Senior Security Engineer – Threat Intelligence, Detection

Jobtailor

Seattle (WA)

On-site

USD 110,000 - 160,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Threat Intelligence & Detection Engineer to design and maintain high-fidelity detection rules in CrowdStrike NG-SIEM. You will own the full detection lifecycle, map threat actor behaviors to telemetry sources, and collaborate across SOC, IAM, and platform teams.

Experience with AI-assisted tooling and cloud telemetry is a plus. The role requires 4+ years in related fields, strong writing, and hands-on EDR/THREAT hunting capabilities.

Qualifications

  • Requires 4+ years in detection engineering, threat intel, SOC/IR, threat hunting, or security automation
  • Proficient in detection logic writing on at least one enterprise SIEM/XDR; CrowdStrike NG-SIEM preferred
  • Familiarity with MITRE ATT&CK technique/sub-technique levels
  • Able to map adversary behaviors to telemetry sources and detection logic
  • Hands-on with EDR analysis, behavioral anomaly detection, and post-exploitation investigation
  • Experience with hypothesis-driven threat hunting and end-to-end hunt documentation
  • Python/PowerShell scripting for automation and tooling
  • Experience in incident response for malware, identity-based, or insider threats
  • Strong written communication with clear detection rationale and intel products
  • Experience with cloud telemetry (Azure/AWS) and cloud-native detection
  • GIAC GCIA/GCIH/GCTI/GDAT or equivalent preferred

Responsibilities

  • Design, develop, and maintain detection logic across SIEM/XDR platforms
  • Operationalize the full detection lifecycle from threat modeling to deployment
  • Align detections to MITRE ATT&CK and threat model priorities
  • Translate intelligence findings into durable detection logic
  • Collaborate with CSIRT, SOC, IAM, and platform teams
  • Develop automation for deployment, triage, and enrichment
  • Lead threat hunts and document outcomes for library feedback
  • Mentor junior team members and contribute to purple team exercises
  • Provide technical escalation during complex incidents
  • Develop runbooks and analyst guidance
  • Integrate detection with CI/CD and threat intel feeds

Skills

Detection Engineering
Threat Intelligence
Threat Hunting
Python Scripting
PowerShell
MITRE ATT&CK Knowledge
Incident Response
Documentation

Education

Bachelor's degree in Computer Science/Information Security
Equivalent professional experience

Tools

CrowdStrike NG-SIEM (LogScale/CQL)
SIEM/EDR/SOAR
Git & CI/CD
Threat Intelligence Platforms

Job description

  • Design, develop, and maintain high-fidelity detection rules in CrowdStrike NG-SIEM (LogScale/CQL) across endpoint, email, identity, network, and cloud domains
  • Operationalize the full detection lifecycle: threat modeling, logic development, empirical testing, deployment, tuning, and retirement
  • Build detection content aligned to MITRE ATT&CK, threat actor TTPs, and internal threat model priorities
  • Translate threat intelligence findings, incident post-mortems, and hunt discoveries into durable detection logic
  • Enforce detection engineering standards including taxonomy, quality criteria, and review processes
  • Collect, analyze, and operationalize tactical and technical threat intelligence from open-source, commercial, and internal sources
  • Produce actionable intelligence products including threat actor profiles, TTP summaries, and IOC packages
  • Monitor threat actor campaigns targeting retail and e-commerce environments
  • Collaborate with CSIRT and SOC to enrich active investigations with adversary context
  • Apply AI-assisted tooling to accelerate intelligence processing, IOC enrichment, and adversary research
  • Design and execute hypothesis-driven threat hunts across endpoint, email, identity, network, and cloud telemetry
  • Document hunt outcomes and feed confirmed patterns back into the detection library
  • Maintain visibility into coverage gaps and drive hunt-to-detect cycles
  • Provide technical escalation support for complex incidents
  • Conduct targeted forensic and log-based analysis during active investigations
  • Develop and maintain investigation runbooks and analyst guidance
  • Translate post-incident lessons learned into detection and hunting improvements
  • Build and maintain automation for detection deployment, alert triage, case enrichment, and threat intelligence processing
  • Develop integrations between SIEM, EDR, email security, SOAR, and threat intelligence platforms
  • Apply Python and PowerShell to operationalize repetitive workflows
  • Leverage AI and machine learning tools to improve detection quality, reduce false positives, and accelerate triage
  • Mentor less experienced team members
  • Partner with SOC, IAM, Platform Engineering, Email Security, and Cloud teams
  • Contribute to purple team exercises, tabletop scenarios, and platform migration readiness
  • Report to the Sr. Manager of Threat Intelligence & Detection Engineering and serve as a lead technical contributor on the TIDE team
Requirements
  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation
  • Demonstrated proficiency writing detection logic in at least one enterprise SIEM or XDR platform; CrowdStrike NG-SIEM (LogScale/CQL) experience strongly preferred
  • Working knowledge of MITRE ATT&CK at the technique and sub-technique level
  • Ability to map adversary behaviors to telemetry sources and detection logic
  • Hands‑on experience with EDR analysis, behavioral anomaly detection, and investigation of post‑exploitation activity
  • Hands‑on experience with hypothesis‑driven threat hunting; ability to document and execute an end‑to‑end hunt
  • Scripting proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling
  • Experience contributing to incident response for malware incidents, identity‑based attacks, or insider threats
  • Strong written communication skills; ability to produce clear, actionable documentation, detection rationale, and intelligence products
  • Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience
  • Familiarity with identity attack patterns including AiTM, MFA fatigue, session hijacking, token replay, and adversarial abuse of SSO and federated identity platforms
  • Experience with enterprise email security platforms and email‑based threat detection including phishing, BEC, and malicious delivery mechanisms
  • Exposure to SOAR platforms and workflow automation (CrowdStrike Fusion or equivalent)
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Recorded Future) and structured intel formats (STIX/TAXII)
  • Knowledge of detection‑as‑code practices, version control (Git), and CI/CD integration for detection deployment
  • Experience with cloud security telemetry (Azure, AWS) and cloud‑native attack detection
  • Demonstrated use of AI tools to accelerate detection development, security operations, or threat research
  • Intermediate or advanced certifications such as GIAC GCIA, GCIH, GCTI, GDAT, or equivalent are preferred
Core Competencies

Expertise in detection engineering and threat intelligence, with a strong focus on developing and operationalizing detection logic in CrowdStrike NG-SIEM. Proficient in threat hunting, incident response, and automation using Python and PowerShell, while leveraging AI tools to enhance detection capabilities.

Highest-signal resume keywords
  • CrowdStrike NG-SIEM (LogScale/CQL)
  • Detection Logic Development
  • Threat Hunting
  • Python Scripting
  • MITRE ATT&CK Knowledge
Hard Skills
  • Detection Engineering
  • Threat Intelligence Analysis
  • EDR Analysis
  • Behavioral Anomaly Detection
  • Hypothesis-Driven Threat Hunting
  • Log Parsing
  • Cloud Security Telemetry
  • Automation
  • Incident Response
  • Detection-as-Code Practices
Soft Skills
  • Strong Written Communication
  • Mentoring
Certifications & Qualifications
  • GIAC GCIA
  • GIAC GCIH
  • GIAC GCTI
  • GIAC GDAT
Industry Keywords
  • Threat Actor TTPs
  • Incident Post-Mortems
  • IOC Packages
  • Identity Attack Patterns
  • Phishing
  • BEC
  • Cloud-Native Attack Detection
Tools & Technologies
  • SIEM
  • EDR
  • SOAR
  • Threat Intelligence Platforms
  • Email Security Platforms
  • AI Tools
  • Git
  • CI/CD Integration
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and platform engineer
Detection and platform engineer

Tixy Services LLC • Town of Texas (WI), Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Staff Threat Hunting, Intelligence Engineer
Staff Threat Hunting, Intelligence Engineer

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • St. Louis (MO)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+4
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • United States

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation & holidays
+5