Remote Detection Engineer: Build & Automate Detections

Binary-Defense

Houston (TX)

Remote

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage
401k match
Remote-friendly work environment
Training opportunities

Job summary

Binary Defense is seeking an experienced Detection Engineer to join our Detection Engineering team in a hands-on role. You will build, deploy, and maintain detections across SIEMs, EDRs, and cloud environments, with a focus on automation and scale.

You will work in a detection-as-code model, using Python and REST APIs to remove GUI dependencies, map detections to MITRE ATT&CK techniques, and collaborate with Threat Intel, IR, and Cloud Security to improve coverage and effectiveness.

Qualifications

  • 2–5+ years in detection engineering, threat hunting, or incident response.
  • Proficient in Python and REST APIs for automating workflows.
  • Experience writing and tuning Sigma, YARA-L, Splunk SPL, KQL or XQL.
  • Experience with telemetry sources: Windows event logs, Sysmon, cloud logs.
  • Familiar with MITRE ATT&CK mapping.
  • Willingness to learn new security tech and work in a fast-paced environment.
  • Ability to work cross-functionally with Threat Intel, Incident Response, and Cloud Security.

Responsibilities

  • Design and implement detections across SIEM and EDR.
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L.
  • Automate rule deployment, validation, and telemetry inspection via APIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams.
  • Contribute to threat modeling to identify coverage gaps.
  • Analyze telemetry sources to identify detection use cases.
  • Participate in adversary simulation and detection validation efforts.
  • Document detection logic and guidance.
  • Improve detection engineering workflows, tooling, and standards.

Skills

Python
REST APIs
Sigma
YARA-L
Splunk SPL
KQL
XQL
MITRE ATT&CK
Threat Modeling
Detection as Code
CI/CD
Git
Telemetry Analysis
Windows Event Logs
Sysmon

Tools

Cortex XDR
XSIAM

Job description

Binary Defense is seeking an experienced Detection Engineer to join our Detection Engineering team in a hands-on role. You will build, deploy, and maintain detections across SIEMs, EDRs, and cloud environments, with a focus on automation and scale.

You will work in a detection-as-code model, using Python and REST APIs to remove GUI dependencies, map detections to MITRE ATT&CK techniques, and collaborate with Threat Intel, IR, and Cloud Security to improve coverage and effectiveness.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer, Cloud Security & IR
Detection Engineer, Cloud Security & IR

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Remote SIEM Detection Engineer: Build Detection Excellence
Remote SIEM Detection Engineer: Build Detection Excellence

Mosaec • Northern (KY)

Hybrid
USD 112,000 - 162,000
Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)
Detection and Response Engineer
Detection and Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
Senior Security Automation & Detection Engineer
Senior Security Automation & Detection Engineer

Solidigm Inc. • Rancho Cordova (CA)

On-site
USD 140,000 - 190,000
Detection & Response Engineer - AI-Driven Security
Detection & Response Engineer - AI-Driven Security

Triwill Group • New York (NY)

On-site
USD 120,000 - 180,000
Director of Detection Engineering & Automation Excellence
Director of Detection Engineering & Automation Excellence

TransUnion • Chicago (IL)

Hybrid
USD 168,000 - 282,000
Medical, dental, vision coverage
HSA/FSA options
Life & AD&D insurance
+8
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Detection & Response Engineer — AI-Driven Security
Detection & Response Engineer — AI-Driven Security

Neura Market • New York (NY)

On-site
USD 140,000 - 210,000
Detection & Response Engineer — AI-Driven Security
Detection & Response Engineer — AI-Driven Security

Doist • New York (NY)

On-site
USD 140,000 - 190,000