Senior Detection Engineer - SIEM/XDR & Cloud Security

CyberJobs.Com

Sunnyvale (CA)

On-site

USD 129,000 - 212,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

LinkedIn is seeking a senior security engineer to design, build, and operate high‑signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code, telemetry modeling, and data‑driven efficacy to improve coverage, validated through purple-team exercises and real incidents.

The role emphasizes hands‑on engineering, technical leadership, and cross‑functional collaboration, with flexible remote/hybrid work options and a focus on protecting a global

Qualifications

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
  • 3+ years in security, detection engineering or incident response.
  • Experience building detection content and analytics for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP).
  • Experience programming for detections/automation (e.g., Python) and query languages (e.g., KQL/SQL/SPL).
  • Experience with detections-as-code (tests, CI/CD, canary/rollback) at scale.
  • Experience with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics.

Responsibilities

  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry; measure precision/recall, latency, lift, and signal-to-noise ratio.
  • Build detections-as-code with version control, CI/CD, unit/integration tests, staged canary rollouts, and safe rollback.
  • Author and maintain SIGMA rules; translate SIGMA to KQL/SQL as needed.
  • Integrate multi-cloud telemetry: Azure (Activity/Diagnostics), AWS (CloudTrail, GuardDuty), GCP (Cloud Audit Logs, SCC).
  • Operationalize Microsoft Defender XDR and Sentinel signals; leverage Entra ID controls (Conditional Access, sign-in risk).
  • Proactive threat hunting; create hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow; integrate with ticketing/chat ops.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and turn reports into testable hypotheses.
  • Own telemetry quality for assigned pipelines: schemas/normalization (e.g., ASIM/OCSF-like), enrichment, data contracts, reliability SLIs/SLOs.
  • Participate in incident retros; add post-incident detections and suppress noisy patterns.
  • Participate in on-call for critical detection pipelines and high-severity investigations.

Skills

Information Security
Detection Engineering
Detection as code
KQL

Education

BA/BS in CyberSecurity, Information Security, CS or related

Tools

SIGMA
KQL
Python
CI/CD
GitHub Actions

Job description

LinkedIn is seeking a senior security engineer to design, build, and operate high‑signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code, telemetry modeling, and data‑driven efficacy to improve coverage, validated through purple-team exercises and real incidents.

The role emphasizes hands‑on engineering, technical leadership, and cross‑functional collaboration, with flexible remote/hybrid work options and a focus on protecting a global

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer — Remote/Hybrid
Senior Detection Engineer — Remote/Hybrid

LinkedIn • United States

Hybrid
USD 129,000 - 212,000
Staff Security Engineer – Detection Engineering
Staff Security Engineer – Detection Engineering

CyberJobs.Com • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Detection Engineer: SIEM/XDR & Cloud Security
Detection Engineer: SIEM/XDR & Cloud Security

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
Staff Detection Engineering Lead - Remote/Hybrid
Staff Detection Engineering Lead - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 156,000 - 255,000
Senior Cloud Security Engineer: SIEM & IR (Remote)
Senior Cloud Security Engineer: SIEM & IR (Remote)

SmarterDx, Inc. • United States

Remote
USD 190,000 - 220,000
Medical, Dental & Vision
Remote-First Team
Unlimited PTO & 10 Holidays
+3
Senior Detection Architect - EDR & SIEM
Senior Detection Architect - EDR & SIEM

Verizon Communications • Ashburn (VA)

On-site
USD 101,000 - 194,000
Senior Detection Engineer - EDR & SIEM Leader (Hybrid)
Senior Detection Engineer - EDR & SIEM Leader (Hybrid)

Verizon • Southlake (TX)

Hybrid
USD 101,000 - 194,000
Remote Senior Detection Engineer — SIEM & Telemetry
Remote Senior Detection Engineer — SIEM & Telemetry

Visa Hunt • Cameron Park (CA), Chicago (IL)

Hybrid
USD 120,000 - 180,000
Medical, Dental & Vision
Employer Paid Life Insurance
Disability Insurance
+3
Senior Detection & Response Engineer — SIEM & Threat Hunt
Senior Detection & Response Engineer — SIEM & Threat Hunt

Cedarparktexasedc • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Detection Engineer — Build Trusted Detections
Senior Detection Engineer — Build Trusted Detections

Socket.dev • Town of Texas (WI)

Hybrid
USD 168,000 - 311,000