Security Engineer

Jobtailor

Arizona

On-site

USD 85,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor is seeking a Detection Engineer to design, test, deploy, and maintain detections across enterprise SIEMs, XDR, and cloud platforms in a US-based role. You will translate threat intel into prioritized use cases and map coverage to adversary behaviors, owning the detection lifecycle end-to-end.

Responsibilities include on-call response, collaboration with security, IT, and cloud teams to onboard telemetry, validate coverage, and improve data quality.

Qualifications

  • College degree or equivalent required.
  • 1 year related experience.
  • Ability to follow technical instructions and guidelines.
  • Ability to document daily activities and system functions.
  • Ability to travel as required by business and on-call availability.
  • Proven hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform.
  • Strong ability to analyze authentication, endpoint, network, email, cloud, and application telemetry and translate findings into durable detection logic.
  • Hands-on experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation.
  • Working knowledge of adversary behavior, detection lifecycle practices, and methods for validating detection coverage.
  • Experience securing Azure and/or AWS environments and Microsoft 365 security capabilities.
  • Experience with PKI and certificate-based authentication basics.

Responsibilities

  • Design, test, deploy, document, and maintain detection content across SIEM, XDR, and cloud platforms.
  • Translate threat intelligence and adversary techniques into prioritized detection use cases.
  • Own the detection lifecycle from intake through retirement.
  • Monitor detection health, data freshness, and alert quality; drive corrective action.
  • Collaborate with cross-functional teams to onboard telemetry and ensure data quality.
  • Perform root-cause analysis and validate remediation; improve detections and playbooks.
  • Configure security controls across Azure, AWS, and Microsoft 365 environments.
  • Participate in on-call rotation and after-hours response as needed.
  • Use scripting and SOAR workflows to enrich alerts and automate response.

Skills

SIEM Detection Creation
Threat Intelligence Translation
Incident Response
PowerShell Scripting
Adversary Behavior Knowledge
Purple Teaming
Cloud Security
Azure Security

Education

Bachelor's degree or equivalent

Tools

SIEM Platforms
XDR Solutions
Azure Virtual Desktop
Microsoft 365
SOAR
Linux Command-Line

Job description

  • Design, test, deploy, document, and maintain detection content across SIEM, XDR, NDR, identity, email, endpoint, network, cloud, and application security platforms
  • Translate threat intelligence, adversary tactics and techniques, incident findings, and business risk into prioritized detection use cases and analytics
  • Map detection coverage to recognized adversary behaviors and maintain traceability among threats, telemetry, analytics, response actions, and control owners
  • Validate and tune detections through structured testing, historical-log review, attack simulation, purple-team exercises, and post-incident analysis
  • Own the detection lifecycle from intake and prioritization through peer review, release, performance review, exception handling, and retirement
  • Monitor detection health, data freshness, rule execution, alert quality, and coverage gaps; drive corrective action
  • Partner with cloud, identity, endpoint, network, infrastructure, and application teams to onboard, normalize, and retain security telemetry
  • Assess log quality, event fidelity, field mapping, parsing, retention, and ingestion health
  • Document data dependencies and recovery procedures and contribute to detection architecture and use-case roadmaps across hybrid and multi-cloud environments
  • Investigate and respond to alerts and incidents through triage, containment, eradication, recovery, validation, and lessons learned
  • Perform root-cause analysis, reconstruct activity, preserve evidence, validate remediation, and improve detections, playbooks, and preventive controls
  • Configure, harden, maintain, and troubleshoot security controls across Azure, Azure Virtual Desktop, AWS, and Microsoft 365
  • Support certificate-based authentication, encryption, and PKI dependencies
  • Participate in on-call rotation and after-hours response as needed
  • Use PowerShell, Python, Bash, APIs, SOAR workflows, and automation to enrich alerts, test controls, improve data quality, orchestrate response, and reduce repetitive work
  • Build reusable queries, scripts, integrations, dashboards, guidance, runbooks, playbooks, SOPs, and knowledge articles
  • Evaluate AI-enabled security capabilities with appropriate human review and control
  • Partner with Security Operations, GRC, IT, Cloud, Networking, Systems, Endpoint, application owners, threat intelligence, vulnerability management, and red/purple teams
Requirements
  • College Degree or equivalent required
  • 1 year related experience
  • Proficient use of applicable technology
  • Ability to follow technical instructions and guidelines
  • Ability to document daily activities and system functions
  • Able to work in team environment
  • Demonstrated ability to communicate verbally and in writing throughout all levels of organization both internally and externally
  • Ability to travel as required by business and on-call availability
  • Able to lift up to 50 lbs
  • Proven hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform
  • Strong ability to analyze authentication, endpoint, network, email, cloud, and application telemetry and translate findings into durable detection logic
  • Hands-on experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation
  • Working knowledge of adversary behavior, common attack techniques, detection lifecycle practices, and methods for validating detection coverage
  • Experience securing Azure and/or AWS environments and operating Microsoft 365 security capabilities
  • Experience supporting or securing Azure Virtual Desktop is required
  • Working knowledge of PKI, certificate-based authentication, encryption, enterprise logging architectures, networking, identity and access, endpoint security, and malware fundamentals
  • Strong PowerShell skills and experience with Linux command-line administration, logs, and services
  • Advanced skill with SIEM query languages, detection-as-code, source control, testing frameworks, SOAR, APIs, and automated response
  • Experience with threat hunting, attack simulation, purple teaming, adversary emulation, breach-and-attack simulation, or measuring detection coverage and quality
  • Experience with AI-assisted security analytics and responsible use of AI in detection and response workflows
  • Relevant certifications such as Security+, GIAC, Microsoft security certifications, ISC2 CC or CISSP, or comparable credentials
  • Experience in a large enterprise SOC, hybrid or multi-cloud environment, or large-scale security transformation
Core Competencies

Demonstrates expertise in detection lifecycle management, including the creation and tuning of detections across SIEM, XDR, and cloud environments. Proficient in security investigations, incident response, and leveraging automation tools to enhance security operations.

Highest-signal resume keywords
  • SIEM Detection Creation and Tuning
  • Azure and AWS Security Management
  • PowerShell Scripting
  • Incident Response and Root-Cause Analysis
  • Threat Intelligence Translation
ATS Optimization Keywords
Hard Skills
  • Detection Logic Development
  • Log Analysis
  • Adversary Behavior Knowledge
  • Detection Lifecycle Practices
  • SIEM Query Languages
  • Automation with SOAR
  • Security Control Configuration
  • Data Quality Improvement
  • Incident Triage and Containment
  • Purple Teaming
Soft Skills
  • Verbal and Written Communication
  • Team Collaboration
  • Technical Instruction Following
  • Documentation Skills
  • Problem-Solving
Certifications & Qualifications
  • Security+
  • GIAC
  • Microsoft Security Certifications
  • ISC2 CC
  • CISSP
Industry Keywords
  • Threat Intelligence
  • Incident Response
  • Cloud Security
  • Enterprise SOC
  • Multi-Cloud Environments
  • Detection Coverage
  • Adversary Emulation
  • Breach-and-Attack Simulation
  • PKI
  • Certificate-Based Authentication
Tools & Technologies
  • SIEM Platforms
  • XDR Solutions
  • Azure Virtual Desktop
  • Microsoft 365
  • APIs
  • Automation Workflows
  • Linux Command-Line
  • Cloud Security Platforms
  • Security Telemetry
  • Encryption Technologies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Detection Engineer – Manager
Detection Engineer – Manager

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Cyber Defense Analyst
Cyber Defense Analyst

Jobtailor • Cambridge (MA)

On-site
USD 150,000 - 190,000
Network Security Engineer
Network Security Engineer

Jobtailor • Town of Florida (NY)

Hybrid
USD 90,000 - 130,000
Senior Cyber Security Architect
Senior Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 90,000 - 120,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Senior Security Engineer – Threat Intelligence, Detection
Senior Security Engineer – Threat Intelligence, Detection

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000