Senior SOC Detection Engineer — Build Global Detections

Embedded Shishya

United States

Remote

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports benefits
Mental Health Program
Free English lessons (online)
Local language courses
Paid time off
Maternity leave support
Referral program rewards
Upskilling and conferences

Job summary

SOFTSWISS is seeking a Senior SOC Detection Engineer to own the full lifecycle of detections across Windows, Linux, and Kubernetes environments. You will research attack techniques, define logging requirements, and build, test, deploy, and continuously improve detection content in Splunk.

You will translate investigations into detections, optimize telemetry, reduce false positives, and collaborate with SOC, IR, Threat Intelligence, and Engineering teams to strengthen overall security posture.

Qualifications

  • Hands-on SOC/detection engineering experience.
  • Deep knowledge of MITRE ATT&CK and detection methods.
  • Proficiency in Splunk SPL or similar SIEM.
  • Experience building detections, queries, dashboards, and reports.
  • Automation scripting in Python/PowerShell/Bash.
  • Experience with Git, APIs, and CI/CD basics.
  • Understanding of Windows and Linux security monitoring.

Responsibilities

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.
  • Translate incident investigations, threat hunting, and attack research into detections.
  • Analyze false positives/negatives and detection gaps.
  • Improve detection coverage and map detections to MITRE ATT&CK techniques.
  • Develop SPL queries, dashboards, reports, and risk-based detections.
  • Define logging, parsing, normalization, enrichment, and data quality requirements.
  • Develop monitoring and health checks for detection rules and data sources.
  • Contribute to automated detection testing, synthetic events, and CI/CD workflows.
  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.
  • Collaborate with SOC, IR, Threat Intelligence, Infrastructure, and Engineering teams.
  • Document detection logic, data sources, dependencies, limitations, and expected behavior.

Skills

Threat hunting
Incident response
Detection engineering
Python
PowerShell
Bash
Git
CI/CD basics
Windows security monitoring

Tools

Splunk SPL
Kubernetes
Docker
Sysmon
Active Directory
Git
CI/CD tooling

Job description

SOFTSWISS is seeking a Senior SOC Detection Engineer to own the full lifecycle of detections across Windows, Linux, and Kubernetes environments. You will research attack techniques, define logging requirements, and build, test, deploy, and continuously improve detection content in Splunk.

You will translate investigations into detections, optimize telemetry, reduce false positives, and collaborate with SOC, IR, Threat Intelligence, and Engineering teams to strengthen overall security posture.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Detection Engineer - Build Threat Detection
Senior SOC Detection Engineer - Build Threat Detection

Softswiss • United States

Remote
USD 140,000 - 190,000
Private health insurance
Sports benefits
Free English lessons (online)
+5
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
SOC Security Engineer: Detection & Response
SOC Security Engineer: Detection & Response

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Hybrid Splunk & SOC Engineer — Detection & Automation
Hybrid Splunk & SOC Engineer — Detection & Automation

Zachary Piper Solutions • Northern (KY)

On-site
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
SIEM & Detection Engineer — Build Real-Time Threat Detections
SIEM & Detection Engineer — Build Real-Time Threat Detections

Mantis Security Corporation • Reston (VA)

On-site
USD 110,000 - 160,000
Senior SOC Lead – Detection & Response
Senior SOC Lead – Detection & Response

Legends Global • Frisco (TX)

Hybrid
USD 120,000 - 150,000
Medical insurance
Dental and Vision insurance
Life and Disability insurance
+2
Staff SOC Engineer — Telemetry & Detection Platforms
Staff SOC Engineer — Telemetry & Detection Platforms

RGA • Missouri

Hybrid
USD 127,000 - 189,000
Annual bonus plan
Health benefits
Retirement benefits
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000