Senior Detection Engineer (EDR, Autonomous Defense)

Horizon3

United States

Remote

USD 120,000 - 150,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Growth opportunities
Innovation culture
Remote-friendly
Diversity & inclusion

Job summary

Horizon3 is seeking a Senior Detection Engineer to serve as the blue team voice within the Defensive Agent team. You will define what correctness means for detections and remediation, acting as the ground truth across Product, Engineering, and AI researchers.

This role emphasizes domain expertise over coding, focusing on how tools behave and how detections are tuned and validated. You will translate blue team workflows into concrete, buildable product requirements, set acceptance criteria for

Qualifications

  • 6+ years in detection engineering, security operations, incident response, or threat hunting.
  • Deep understanding of attacker behavior and its surface in telemetry.
  • Hands-on experience tuning EDR platforms in production with policy/exclusions.
  • Fluency in false positive/false negative tradeoffs and detection coverage.

Responsibilities

  • Define acceptance criteria for detection, effectiveness, and tuning features.
  • Validate releases against criteria before customers see them.
  • Partner with Product to translate blue team workflows into prioritized product outcomes.
  • Maintain domain truth across tools and vendor guidance to ensure consistent behavior.

Skills

Detection engineering
Python scripting
SQL querying
Technical writing
Threat hunting
SOC operations
Endpoint security

Tools

EDR platforms tuning
Python
SQL

Job description

  • We’re hiring a Senior Detection Engineer to be the blue team voice inside the Defensive Agent team
  • You’ll sit between Product and Engineering as the person who defines what “correct” means
  • When an attack technique is detected, you decide what remediation that claim requires
  • Your judgment becomes the ground truth
  • This is not a coding role and it is not a product management role
  • Product owns the roadmap, Engineering owns the implementation, and our AI researchers own how the agents reason
  • You own the domain truth all three depend on, and you make it concrete enough to build and measure against
  • If you’ve spent your career being the person in the room who knows how the tools really behave, this is a seat where that knowledge teaches a system instead of firefighting alerts
  • Partner with Product to turn EDR effectiveness and tuning ambitions into concrete, buildable requirements
  • Translate blue team workflows and pain into prioritized product outcomes, and push back when a proposed feature or agent behavior would not hold up in a real SOC
  • Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against them before customers see them
  • Serve as the standing domain reference for Engineering and AI research: available for design reviews, technique questions, and vendor behavior questions
  • Own deep, current knowledge of the major EDR and endpoint platforms at the console, policy, telemetry, and API level
  • Maintain fluency in how detection logic, prevention policy, exclusions, and tuning actually work in each product, including the differences between default and hardened configurations
  • Define the vendor-specific policy semantics, so a recommended change means the same thing across platforms that model it differently
  • Track platform changes, new detection capabilities, and vendor guidance, and keep our coverage model current as vendors ship
  • Define what a correct tuning recommendation looks like and grade agent output against that standard
  • Partner with the Attack team so technique coverage and detection expectations stay grounded in current adversary tradecraft
Benefits
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career advancement opportunities
  • Innovation-Driven Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking
  • Flexible Work Environment: Enjoy the convenience and work-life balance that comes with remote work
  • Inclusive and Diverse Team: We value diversity and promote an inclusive culture where everyone can thrive

6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time spent as a practitioner rather than an advisorSolid understanding of post-compromise attacker behavior and how each surfaces in endpoint and identity telemetryHands-on operational experience administering and tuning EDR platforms in production — writing detections, managing policy and exclusions, and investigating real alertsFluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurementStrong working knowledge of MITRE ATT&CK and detection coverage frameworks, and a clear view of where they help and where they misleadDeep understanding of what a SOC actually does with EDR outputAbility to influence without authority. You will not manage the engineers or own the roadmap, and you will still be expected to move bothEnough scripting ability, ideally Python, to query APIs, inspect telemetry, and prototype an analysisDemonstrated experience shaping a product or platform as a domain expert, whether in a security vendor, an internal tooling team, or a detection engineering functionComfort with SQL and with reasoning over large volumes of event and telemetry dataComfort translating between audiences: engineers, AI researchers, product managers, SOC analysts, and executivesExceptional technical writing. Most of your leverage here comes from written artifacts — requirements, methodology docs, labeling guides, tuning content

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming
Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming

CDW • United States

On-site
USD 140,000 - 210,000
Cybersecurity Engineer
Cybersecurity Engineer

Vortalsoft Inc • New Jersey

On-site
USD 90,000 - 130,000
Cyber Defense Platforms Staff Engineer
Cyber Defense Platforms Staff Engineer

Scorpion Therapeutics • Cambridge (MA)

On-site
USD 170,000 - 230,000
Senior Detection Engineer: EDR & SOC Domain Expert
Senior Detection Engineer: EDR & SOC Domain Expert

Horizon3 • United States

Remote
USD 120,000 - 150,000
Growth opportunities
Innovation culture
Remote-friendly
+1
Sr. Lead Threat Detection Engineer
Sr. Lead Threat Detection Engineer

ADP • Roseland (NJ)

On-site
USD 150,000 - 210,000
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Detection Engineer
Detection Engineer

Foundation Capital • San Francisco (CA)

On-site
USD 150,000 - 200,000
Senior Product Manager (XDR) - Security Solutions
Senior Product Manager (XDR) - Security Solutions

Elastic • United States

On-site
USD 150,000 - 210,000
MEDR Threat Engineer US work hours
MEDR Threat Engineer US work hours

Proficio Inc • United States

On-site
USD 120,000 - 180,000
Meals reimbursement
Gym access
Internet reimbursement
Security Engineer
Security Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 180,000