Senior SOC Detection Engineer - Build Threat Detection

Softswiss

United States

Remote

USD 140,000 - 190,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports benefits
Free English lessons (online)
Local language courses
Paid time off
Maternity leave support
Referral program rewards
Upskilling, internal workshops, and...

Job summary

SOFTSWISS is seeking a Senior SOC Detection Engineer to join the Security Operations team. You will own the full lifecycle of detections in Splunk, from researching attack techniques to deploying and tuning content that reduces false positives and improves threat visibility.

You will work across Windows, Linux, and Kubernetes environments, collaborating with SOC, IR, Threat Intelligence, and Infra teams to elevate detection coverage and incident response readiness.

Qualifications

  • Hands-on SOC experience in detection engineering, threat hunting, or IR.
  • Strong knowledge of MITRE ATT&CK techniques and detection methods.
  • Proficiency in Splunk SPL and building detections, dashboards, and reports.
  • Experience tuning detections, handling exceptions, and allowlists.
  • Ability to define logging and telemetry requirements.
  • Scripting in Python, PowerShell, or Bash for automation.

Responsibilities

  • Own the lifecycle of detections from research to deployment in Splunk.
  • Translate investigations into effective detections and rules.
  • Analyze false positives/negatives and close detection gaps.
  • Map detections to MITRE ATT&CK techniques and improve telemetry.
  • Develop SPL queries, dashboards, and risk-based detections.
  • Collaborate with SOC, IR, Threat Intel, and Engineering teams.
  • Document logic, data sources, and dependencies; support CI/CD workflows.

Skills

SOC Detection
Threat Hunting
Incident Response
Splunk SPL
Python
PowerShell
Bash
Git
CI/CD
MITRE ATT&CK

Tools

Splunk Enterprise Security
Kubernetes

Job description

SOFTSWISS is seeking a Senior SOC Detection Engineer to join the Security Operations team. You will own the full lifecycle of detections in Splunk, from researching attack techniques to deploying and tuning content that reduces false positives and improves threat visibility.

You will work across Windows, Linux, and Kubernetes environments, collaborating with SOC, IR, Threat Intelligence, and Infra teams to elevate detection coverage and incident response readiness.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Detection Engineer — Build Global Detections
Senior SOC Detection Engineer — Build Global Detections

Embedded Shishya • United States

Remote
USD 120,000 - 180,000
Private health insurance
Sports benefits
Mental Health Program
+6
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Hybrid Splunk & SOC Engineer — Detection & Automation
Hybrid Splunk & SOC Engineer — Detection & Automation

Zachary Piper Solutions • Northern (KY)

On-site
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Lead Cybersecurity Engineer – Splunk & Threat Hunting
Lead Cybersecurity Engineer – Splunk & Threat Hunting

SSV Technologies Inc. • Richmond (VA)

On-site
USD 120,000 - 180,000
SIEM & Detection Engineer — Build Real-Time Threat Detections
SIEM & Detection Engineer — Build Real-Time Threat Detections

Mantis Security Corporation • Reston (VA)

On-site
USD 110,000 - 160,000
SOC Security Engineer: Detection & Response
SOC Security Engineer: Detection & Response

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior SOC Analyst - Threat Detection & Response (Hybrid)
Senior SOC Analyst - Threat Detection & Response (Hybrid)

FlexTrade • Village of Great Neck (NY)

Hybrid
USD 120,000 - 180,000
Hybrid work schedule
Professional development budget
Comprehensive benefits
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000