Senior Detection Engineer (Next-Gen Threat Hunter)

West Unified Communications Services (formerly known as InterCall Asia Pacific)

Longmont (CO)

Hybrid

USD 140,000 - 175,000

Full time

42 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
Life and disability coverage
Paid time off
401(k) plan
Parental leave

Job summary

Intrado in Longmont, CO is hiring a Senior Detection Engineer (Next-Gen Threat Hunter) to design high-fidelity detections for multi-cloud and on‑prem environments. You will build behavioral models, deploy tripwires, and mentor SOC/IR teams while iterating from field feedback.

This hybrid role requires strong coding in Python/Go, experience in cloud security, and a track record of threat hunting using identity- and behavior-based techniques.

Qualifications

  • 5+ years of progressive experience in cybersecurity, including detection engineering, security operations, incident response, threat hunting, security engineering, or related discipline.
  • Background in technical/network security, systems and/or cloud computing, with traditional SOC analyst work experience.
  • 3+ years of automation scripting (Python, Go, BASH, Helm, PowerShell) to manipulate APIs and data structures.
  • Experience securing AWS and Azure control planes, IAM auditing, storage access (S3, Azure Blobs), and cloud log management.
  • Kubernetes engineering experience including securing cluster control planes and Kube-audit logs.
  • Identity- and behavior-based threat hunting using LotL techniques rather than static signatures.
  • Hands-on experience engineering automation playbooks and Cortex XSIAM orchestrations.

Responsibilities

  • Design high-fidelity detection pipelines for rapid automated attack-chain detection.
  • Develop behavioral analytics and anomaly detection beyond static indicators.
  • Monitor and protect AWS and Azure infrastructure by tracking API calls and identity movements.
  • Unify threat visibility across external attackers and insider threats by mastering identity perimeter.
  • Write production-grade Python and automation workflows to instantiate detections.
  • Align detection logic with MITRE ATT&CK and cloud/container/identity techniques.
  • Deploy tripwires, honey-tokens, and deception to detect lateral movement.
  • Analyze API telemetry from applications, Kubernetes, and cloud services for malicious activity.
  • Lead analytics and incident response as SME; mentor SOC and IR staff.

Skills

Cybersecurity
Detection engineering
SOAR automation
Python scripting
Cloud security
Kubernetes
Incident response
Threat hunting

Tools

Python
Go
BASH
PowerShell
Helm

Job description

  • Longmont, Colorado
  • Engineering & Technology
  • Hybrid
  • 4633
Senior Detection Engineer (Next-Gen Threat Hunter)
About Us

Intrado is dedicated to saving lives and protecting communities, helping them prepare for, respond to, and recover from critical events. Our cutting-edge company strives to become the most trusted, data-centric emergency services partner by uniting fragmented communications into actionable intelligence for first responders. At Intrado, all of our work truly matters.

Responsibilities/Qualifications

The modern threat actor moves in seconds or minutes, not days. We are shifting to a detections capability focused on where our data is located (SaaS platforms, automation pipelines, user-controlled data storage) and the knowledge that the future of our perimeter is identity based. As a Detection Engineer, you will not just operate security tools—you will design a high-fidelity system that makes our multi-cloud and on-prem environment inherently hostile to adversaries. This position will be its own customer, building and operating detections, growing from feedback in the field, and iterating. This position will spend (for rough example) 70% on engineering detections for automated attack chains and performing response and triage, with 15% on more traditional log reviews or IOCs, and 15% on strategy and modeling the adversary.

Key Responsibilities
  • Design Automated Logic:Design and implement high-fidelity detection pipelines that detect automated attack chains within minutes or seconds.
  • Build Behavioral Models: Shift focus from static indicators (like file hashes) to complex behavioral analytics and anomaly detection.
  • Secure Cloud Control Planes: Monitor and protect AWS and Azure infrastructure by tracking API calls, configuration drift, and identity-based movements.
  • Unify Threat Visibility: Dissolve boundaries between external attackers, non-human ID and insider threats by mastering the identity perimeter and focusing on potential credential activities.
  • Develop Security Code: Write production-grade Python and automated workflows in other scripting and automation languages/tools to turn manual threat-hunting hypotheses into instantiated detections code.
  • Map to Matrix Frameworks: Align detection logic with modern matrices like MITRE ATT&CK, focusing heavily on cloud, container, and identity techniques.
  • Construct Tripwires: Deploy deceptive assets, honey-tokens, and behavioral tripwires to detect adversary lateral movement or actions post-compromise.
  • Analyze API Telemetry: Deep-dive into application, Kubernetes, and cloud-service APIs to detect malicious API-shimming, data staging, and account takeovers.
  • Collaborate and Mentor SOC and IR:Lead analytics and incident response as SME to ensure clean response and containment, ingest post-mortem data and continuously harden detection logic against new variants. Mentor analyst and engineering staff in areas of expertise.
  • Optimize SIEM/XDR/XSIAM and Protections Pipelines: Refine data ingestion pipelines and engineer XSOAR playbooks to automatically triage and contain alerts with minimal analyst intervention.
  • Design for the Future/Work in the Present: Our protections/controls matrix are top notch. You will ensure that our stack stays positioned for the always-evolving future, but that we optimize our tools and capabilities as they exist today, getting the most for the dollars invested while planning for what's next.
Candidate Prerequisites
  • Cybersecurity Experience: 5+ years of progressive experience in cybersecurity, including experience in detection engineering, security operations, incident response, threat hunting, security engineering, or a related discipline.
  • Security Operations Expert: You have a background in technical/network security, systems and/or network engineering or cloud computing, and have done traditional SOC analyst work whether single-hatted or as a generalist role.
  • Operational Production Coding: Minimum 3+ years of experience writing clean automations and scripts in Python, Go, BASH, Helm, or PowerShell to manipulate APIs and data structures.
  • Multi-Cloud Architecture Expertise: Proven experience securing AWS and Azure control planes, specifically auditing IAM, storage access (e.g., S3, Azure Blobs), and cloud log management.
  • Container & Orchestration Security: Strong engineering experience with Kubernetes, including securing cluster control planes, monitoring Kube-audit logs, and analyzing container runtime telemetry.
  • Behavioral Threat Hunting: Demonstrated track record of hunting based on identity, behavioral baselines, and Living-off-the-Land (LotL) techniques rather than static signatures.
  • SOAR Automation Expert: Hands-on experience engineering automation playbooks, integrations, and orchestration flows specifically within Cortex XSIAM.
Physical Requirements
  • Position requires long periods of sitting, typing, and participating in phone or video calls.
On-call Requirements
  • Participation in a scheduled on-call rotation is a required responsibility of this position. On-call assignments typically occur once every four to five weeks and involve responding to security incidents, critical alerts, and potential threats that require investigation, triage, or containment outside of normal business hours.
Total Rewards

Want to love where you work? At Intrado, we offer a comprehensive benefits package that includes what you’d expect (medical, dental, vision, life and disability coverage, paid time off, a 401(k) retirement plan, and several that go above and beyond– paid parental leave, access to a robust library of personal and professional training resources, employee discounts, critical illness, hospital indemnity, access to legal support, pet insurance, identity theft protection,an EAP (Employee Assistance Program) that includes free mental health resources/support, and more!

The starting salary is anticipated between $140,000 and $175,000 and will be commensurate with experience.

Intrado is an Equal Opportunity Employer – Veterans/Disabled and Other Protected Categories. Our Company welcomes and encourages applications of individuals with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process. Intrado maintains a Drug Free Workplace.

Key Responsibilities
  • Design Automated Logic:Design and implement high-fidelity detection pipelines that detect automated attack chains within minutes or seconds.
  • Build Behavioral Models: Shift focus from static indicators (like file hashes) to complex behavioral analytics and anomaly detection.
  • Secure Cloud Control Planes: Monitor and protect AWS and Azure infrastructure by tracking API calls, configuration drift, and identity-based movements.
  • Unify Threat Visibility: Dissolve boundaries between external attackers, non-human ID and insider threats by mastering the identity perimeter and focusing on potential credential activities.
  • Develop Security Code: Write production-grade Python and automated workflows in other scripting and automation languages/tools to turn manual threat-hunting hypotheses into instantiated detections code.
  • Map to Matrix Frameworks: Align detection logic with modern matrices like MITRE ATT&CK, focusing heavily on cloud, container, and identity techniques.
  • Construct Tripwires: Deploy deceptive assets, honey-tokens, and behavioral tripwires to detect adversary lateral movement or actions post-compromise.
  • Analyze API Telemetry: Deep-dive into application, Kubernetes, and cloud-service APIs to detect malicious API-shimming, data staging, and account takeovers.
  • Collaborate and Mentor SOC and IR:Lead analytics and incident response as SME to ensure clean response and containment, ingest post-mortem data and continuously harden detection logic against new variants. Mentor analyst and engineering staff in areas of expertise.
  • Optimize SIEM/XDR/XSIAM and Protections Pipelines: Refine data ingestion pipelines and engineer XSOAR playbooks to automatically triage and contain alerts with minimal analyst intervention.
  • Design for the Future/Work in the Present: Our protections/controls matrix are top notch. You will ensure that our stack stays positioned for the always-evolving future, but that we optimize our tools and capabilities as they exist today, getting the most for the dollars invested while planning for what's next.
Candidate Prerequisites
  • Cybersecurity Experience: 5+ years of progressive experience in cybersecurity, including experience in detection engineering, security operations, incident response, threat hunting, security engineering, or a related discipline.
  • Security Operations Expert: You have a background in technical/network security, systems and/or network engineering or cloud computing, and have done traditional SOC analyst work whether single-hatted or as a generalist role.
  • Operational Production Coding: Minimum 3+ years of experience writing clean automations and scripts in Python, Go, BASH, Helm, or PowerShell to manipulate APIs and data structures.
  • Multi-Cloud Architecture Expertise: Proven experience securing AWS and Azure control planes, specifically auditing IAM, storage access (e.g., S3, Azure Blobs), and cloud log management.
  • Container & Orchestration Security: Strong engineering experience with Kubernetes, including securing cluster control planes, monitoring Kube-audit logs, and analyzing container runtime telemetry.
  • Behavioral Threat Hunting: Demonstrated track record of hunting based on identity, behavioral baselines, and Living-off-the-Land (LotL) techniques rather than static signatures.
  • SOAR Automation Expert: Hands-on experience engineering automation playbooks, integrations, and orchestration flows specifically within Cortex XSIAM.
Physical Requirements
  • Position requires long periods of sitting, typing, and participating in phone or video calls.
On-call Requirements
  • Participation in a scheduled on-call rotation is a required responsibility of this position. On-call assignments typically occur once every four to five weeks and involve responding to security incidents, critical alerts, and potential threats that require investigation, triage, or containment outside of normal business hours.
Total Rewards

Want to love where you work? At Intrado, we offer a comprehensive benefits package that includes what you’d expect (medical, dental, vision, life and disability coverage, paid time off, a 401(k) retirement plan, and several that go above and beyond– paid parental leave, access to a robust library of personal and professional training resources, employee discounts, critical illness, hospital indemnity, access to legal support, pet insurance, identity theft protection,an EAP (Employee Assistance Program) that includes free mental health resources/support, and more!

The starting salary is anticipated between $140,000 and $175,000 and will be commensurate with experience.

Intrado is an Equal Opportunity Employer – Veterans/Disabled and Other Protected Categories. Our Company welcomes and encourages applications of individuals with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process. Intrado maintains a Drug Free Workplace.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer (Next-Gen Threat Hunter)
Senior Detection Engineer (Next-Gen Threat Hunter)

Socket.dev • Longmont (CO)

On-site
USD 140,000 - 175,000
Senior Detection Engineer (Next-Gen Threat Hunter)
Senior Detection Engineer (Next-Gen Threat Hunter)

Intrado Life & Safety, Inc. • Longmont (CO)

On-site
USD 140,000 - 175,000
Medical, dental, vision
Paid time off
401(k) retirement plan
+2
Application Administrator
Application Administrator

Intrado Life & Safety, Inc. • Northern (KY)

Hybrid
USD 85,000 - 110,000
Medical, dental, vision
401(k) retirement plan
Paid time off
+2
Director, Enterprise Data Management
Director, Enterprise Data Management

Intrado • United States

On-site
USD 150,000 - 175,000
Sr. Manager, Digital Marketing at Intrado
Sr. Manager, Digital Marketing at Intrado

Feedinkoo • United States

On-site
USD 100,000 - 110,000
Medical, dental, vision insurance
401(k) plan with company match
Tuition reimbursement
+3
Director, Enterprise Data Management
Director, Enterprise Data Management

Intrado Life & Safety, Inc. • United States

On-site
USD 150,000 - 175,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+2
Sr. Telecommunications Engineer
Sr. Telecommunications Engineer

Intrado • Longmont (CO)

On-site
USD 90,000 - 110,000
Comprehensive benefits package
401(k) retirement plan with company match
Tuition reimbursement
+2
Telecommunicator 2
Telecommunicator 2

Intrado • Longmont (CO)

On-site
USD 3,582,000 - 3,788,000
On-site fitness center
On-site café
Predictable shifts
+1
911 Call Taker at Intrado Life & Safety, Inc. Longmont, CO
911 Call Taker at Intrado Life & Safety, Inc. Longmont, CO

Intrado Life & Safety, Inc. • Longmont (CO)

On-site
Medical insurance
Dental insurance
Vision insurance
+5
Telecommunicator 2
Telecommunicator 2

Intrado Life & Safety, Inc. • Longmont (CO)

On-site
USD 37,000 - 38,000
Dedicated desk/workstation
On-site fitness center and cafe
Structured processes and predictable角色