Senior Detection Engineer (AI-ML Focus)

Relha LLC

Cincinnati (OH)

On-site

USD 120,000 - 150,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Procter & Gamble is seeking a Senior Detection Engineer to design, build, and tune detection rules across enterprise SIEM platforms. You will work at the intersection of detection engineering and AI, using agentic tooling to accelerate threat detection development and coverage analysis.

You will collaborate with Threat Intelligence and Threat Hunting teams, manage content as code, and continuously improve alert fidelity while reducing noise.

Qualifications

  • Bachelor’s degree in Information Systems, IT, CS, Engineering, or related field; 5+ years in detection/security roles

Responsibilities

  • Design, build, test, and tune SIEM detection rules aligned to MITRE ATT&CK
  • Write detection logic across SIEM and data lake platforms
  • Manage detection content as code with Git workflows, PRs, and CI/CD pipelines
  • Investigate and suppress false positives using lookup-based architectures
  • Collaborate with Threat Hunting and Threat Intelligence teams
  • Monitor threats and rapidly develop detections for new TTPs
  • Leverage AI agents and LLM-assisted workflows to accelerate development and validation

Skills

Python
Detection engineering
MITRE ATT&CK
AI/LLM tooling
SIEM rules tuning

Education

Bachelor's degree (IT/CS/Engineering)

Tools

Git-based workflows
CI/CD pipelines

Job description

At P&G, we believe that diverse experiences help build strong leaders. Mobility is a key component of many management careers, providing opportunities to grow through different assignments, locations, and business challenges. Candidates should be prepared to consider relocation opportunities throughout their career as business needs and development opportunities arise.

The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI — using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.

You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands-on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.

Key Success Metrics

Your success would be based on operational and project deliverables, which would be reviewed on a quarterly basis. Your manager would provide full-support though continuous mentoring and coaching

Detection rules you write catch real threats and generate minimal noise
You measurably improve alert fidelity (TP rate) and reduce SOC case volume

You operate independently within the detection-as-code workflow (branch → validate → deploy)

You leverage AI tooling to work faster — not as a research project, but as a daily force multiplier

Quarterly deliverables reviewed with your manager through continuous mentoring and coaching

Job Responsibilities:
Detection Engineering:

Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk

Write detection logic across the SIEM and data lake platforms

Manage detection content as code — Git-based workflows, PR reviews, CI/CD deployment pipelines

Investigate and suppress false positives systematically using lookup-based architectures

Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI→TH→DE pipeline)

Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns

Leverage AI agents and LLM-assisted workflows to accelerate detection rule development, validation, and coverage analysis

Use and contribute to MCP (Model Context Protocol) tooling that enables AI-assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps)

Operate agentic pipelines that triage large rule libraries against live telemetry at scale

Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets

Stay current on frontier AI threats (agentic attacks, LLM-assisted exploitation, AI-generated phishing) and translate them into detection opportunities

Collaboration & Operations:

Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements

Collaborate with data engineers on telemetry availability, data quality, and log source onboarding

Contribute to detection coverage reporting and MITRE ATT&CK posture measurement
Document detection logic, tuning rationale, and suppression decisions
Job Qualifications
Technical Competencies and Experience:
Required:

Bachelor’s degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience in detection engineering, security operations, or threat detection roles

Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real-time alerts)

Strong understanding of MITRE ATT&CK framework and its application to detection coverage

Proficiency in Python for automation, scripting, and tooling

Experience with git-based workflows (branching, PRs, CI/CD) for managing security content

Familiarity with security log sources: EDR, identity, cloud, network, proxy

Strong analytical skills and ability to distinguish true threats from noise in large datasets

Preferred:

Certifications CISSP, CCSP, OSCP, GIAC Certified Detection Analyst (GCDA), GCIA, Relevant certifications in cloud & ML/AIExperience with multiple query languages are helpful but not required

Experience with detection-as-code practices and YAML-based rule formats (Sigma, custom schemas)

Working knowledge of AI/LLM capabilities and their security implications — both as detection targets and as engineering tools

Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows

Familiarity with SOAR platforms and their integration with detection pipelines

Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments

Compensation for roles at P&G varies depending on a wide array of non-discriminatory factors including but not limited to the specific office location, role, degree/credentials, relevant skill set, and level of relevant experience. At P&G compensation decisions are dependent on the facts and circumstances of each case. Total rewards at P&G include salary + bonus (if applicable) + benefits. Your recruiter may be able to share more about our total rewards offerings and the specific salary range for the relevant location(s) during the hiring process.

We are committed to providing equal opportunities in employment. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Immigration Sponsorship is not available for this role. For more information regarding who is eligible for hire at P&G along with other work authorization FAQ’s, please click HERE.

Procter & Gamble participates in E-Verify.

Qualified individuals will not be disadvantaged based on being unemployed.

P&G is dedicated to meeting the needs of applicants requesting an accommodation/adjustment due to a disability in order to complete the online application process. If you have a disability that affects your ability to complete our online application process, please visit our Disability Accommodation Page.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Site Cyber Security Leader
Site Cyber Security Leader

Procter & Gamble • Dayton (OH)

On-site
USD 85,000 - 122,000
Ownership from Day 1
Mentorship & Training
Work-life balance
Sr. Data Scientist - AI/ML
Sr. Data Scientist - AI/ML

Procter & Gamble • Cincinnati (OH)

Hybrid
USD 110,000 - 165,000
Senior AI-Driven Detection Engineer for SIEM
Senior AI-Driven Detection Engineer for SIEM

Relha LLC • Cincinnati (OH)

On-site
USD 120,000 - 150,000
Senior Data Scientist
Senior Data Scientist

PPG Industries • United States

Hybrid
USD 130,000 - 210,000
Hybrid work schedule
Flexible Fridays
Data Engineer - North America Fabric Care
Data Engineer - North America Fabric Care

Procter & Gamble • Cincinnati (OH)

Hybrid
USD 85,000 - 122,000
Digital Security Leader
Digital Security Leader

Procter & Gamble • Georgia

On-site
USD 85,000 - 122,000
Site Cyber Security Leader
Site Cyber Security Leader

Procter & Gamble • Union (OH)

On-site
USD 85,000 - 123,000
Ownership from Day 1
Continuous mentorship
Work-life balance
Administrative Assistant, Surface Care Team
Administrative Assistant, Surface Care Team

Procter & Gamble • Saint Bernard (OH)

On-site
USD 69,000 - 96,000
Sr. Embedded Detection Analyst
Sr. Embedded Detection Analyst

Abnormalsecurity • United States

On-site
USD 100,000 - 120,000
Community Manager & Brand Fans Club Leader
Community Manager & Brand Fans Club Leader

Procter & Gamble • Cincinnati (OH)

On-site
USD 85,000 - 122,200