Sr. Detection Engineer

Cedar Cares, Inc

Chicago (IL)

Hybrid

USD 131,000 - 169,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work environment
Health, dental and vision benefits
401(k) match
Annual incentive compensation

Job summary

Cboe Global Markets is seeking a Senior Detection Engineer to join the Security Operations team. You will author, test, and maintain production detection logic across SIEM, EDR, identity, cloud, and network telemetry, building reusable test content and tooling to validate coverage.

You will collaborate with Threat Hunting, Incident Response and Security Engineering to ensure detections stay effective and quantitatively validated, with a focus on reducing false positives.

Qualifications

  • 5+ years of hands-on security engineering experience with detections.
  • Proficient in at least one detection language (KQL, Sigma, YARA-L).
  • Knowledge of Windows/AD, Entra ID, cloud platforms, SaaS, containers.
  • Able to read unfamiliar exploit/malware code and identify observable artifacts.
  • Fluent in at least one tooling language: Python, Go, C#, PowerShell or Bash.
  • Familiar with telemetry logs and where data is unreliable.
  • Experience building/test infrastructure using virtualization/containers/CI/CD.
  • Strong FP discipline and deterrence of false positives.
  • Clear technical writing for engineers and analysts.

Responsibilities

  • Write, tune, and maintain production detection logic across SIEM, EDR, identity, and cloud platforms.
  • Validate each detection by executing the technique it targets.
  • Build internal tooling to simulate adversary behavior for repeatable testing.
  • Create reusable validation packages and automated regression tests.
  • Operate sandbox and detonation infrastructure for safe technique development.
  • Assess new proof-of-concept exploit code for telemetry and risk.
  • Provide threat hunting validation content and seed artifacts.
  • Automate repeatable work: scheduled executions, telemetry collection, and reporting.
  • Apply AI tooling to shorten cycle time in triage and enrichment.
  • Perform security testing of internal apps/APIs and translate findings.
  • Support Incident Response with concrete attacker insights and detections.
  • Document work for independent operation by others.

Skills

5+ years of security engineering
Detection query language
Windows & AD familiarity
Python / Go / C# / PowerShell
Telemetry & log analysis
Test infrastructure & CI/CD
Writing clear technical docs
Ethical standards & authorization
MITRE ATT&CK awareness

Education

Bachelor's degree or equivalent

Job description

Job Description

At Cboe, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting‑edge trading, clearing and investment solutions to market participants around the world. We’re building inclusive ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. Our Associate Resource Groups champion diversity, equity and inclusion, giving associates a safe space to network, share ideas and create opportunities. Sound like the place for you? Join us!

Role Overview

The Security Operations team is hiring a Senior Detection Engineer. The Senior Detection Engineer is a hands‑on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role authors the rules, then executes the techniques those rules are meant to catch, building the tooling, sandboxes, and reusable test content required to demonstrate coverage rather than assume it. A detection is not finished when it is written. It is finished when someone has run the attack against it, confirmed it fired, confirmed it stayed quiet on benign activity, and left behind a test case that will re‑confirm both after the next platform change. The work spans endpoint, identity, cloud, SaaS, network, and application telemetry. The role requires fluency in attacker tradecraft at a mechanical level: how a technique actually executes, what artifacts it produces, and which of those artifacts are reliable enough to build durable detection logic on. This position partners closely with Threat Hunting, Incident Response, and Security Engineering to ensure detection coverage is measured continuously rather than assumed. To set expectations clearly, this is a detection authoring and validation role, not a data pipeline role. Log source onboarding, parser development, and ingestion engineering are owned elsewhere. You will need to understand our telemetry well enough to know what is and is not detectable with it, and you will be expected to raise gaps when the data cannot support a detection, but building the pipes is not the job.

Responsibilities
  • Writing, tuning, and maintaining production detection logic across SIEM, EDR, identity, and cloud platforms, with explicit attention to fidelity and false positive cost
  • Validating every detection by executing the technique it targets, so that no rule reaches production unproven
  • Building and maintaining internal tooling that simulates adversary behavior on demand, making detection testing repeatable rather than manual
  • Building reusable validation packages and automated regression testing so coverage is re‑verified continuously and after every agent, platform, or configuration change
  • Building and operating sandbox and detonation infrastructure, including disposable, instrumented environments for exploit triage, malware analysis, and safe technique development
  • Evaluating newly published proof‑of‑concept exploit code to determine whether it functions, what telemetry it generates, and whether Cboe is exposed, then converting the answer into detection or hunting content
  • Producing threat hunting validation content, including seeded artifacts, known‑truth datasets, and repeatable test cases that establish whether a hypothesis is testable with the data we hold
  • Automating the repeatable work: scheduled technique execution, telemetry collection, coverage reporting, and detection performance measurement
  • Applying AI and LLM tooling where it measurably shortens cycle time, including agentic workflows for triage and enrichment, automated analysis of exploit and malware code, detection and test‑case drafting, and hunt hypothesis generation
  • Conducting security testing of internally built web applications and APIs, and translating findings into detection requirements as well as remediation guidance
  • Supporting Incident Response during complex investigations with concrete attacker tradecraft insight, and closing the loop by building detections for what the investigation surfaces
  • Documenting and handing off work so that tooling, environments, and test content can be operated by others independently
Qualifications
  • 5+ years of hands‑on security engineering experience with substantial detection authoring content, and the ability to speak concretely about detections you built, how you validated them, and how they performed in production
  • Strong command of at least one detection query language (KQL, Sigma, YARA‑L, or equivalent) and the judgment to recognize when logic is too brittle or too broad to ship
  • Practical knowledge of attacker techniques across Windows and Active Directory, Entra ID, cloud platforms (AWS, Azure), SaaS, and containerized workloads, at the level of execution mechanics rather than technique names
  • The ability to read unfamiliar exploit or malware code and identify the observable artifacts worth detecting on
  • Real fluency in at least one language used to write tooling (Python, Go, C#, PowerShell, bash, or equivalent)
  • Working knowledge of the telemetry itself, including Windows event logs, EDR process and network events, cloud audit logs, and identity sign‑in data, and where each is unreliable, incomplete, or trivially evaded
  • Comfort building and tearing down test infrastructure using virtualization, containers, infrastructure‑as‑code, and CI/CD
  • A disciplined approach to false positives, alert quality, and the operational burden that detections place on analysts
  • Clear technical writing aimed at engineers, including detection documentation and analyst‑facing response guidance
  • High ethical standards and demonstrated discipline around authorization, scope, blast radius, and handling of sensitive data
  • Bachelor’s degree or equivalent practical experience
You’ll really stand out with
  • Public detection content, tooling, or research that we can review
  • Hands‑on experience with atomic testing frameworks or continuous control validation at scale
  • Use of MITRE ATT&CK as a coverage and gap‑analysis instrument rather than a reporting label
  • Concrete AI engineering experience, such as agentic workflows, tool and MCP integration, or testing LLM‑application abuse cases including prompt injection
  • Reverse engineering, Windows internals, or EDR telemetry and evasion research
  • Experience operating in regulated or large enterprise environments, especially financial services
  • A track record of mentoring engineers or building internal training material
  • Curiosity, adaptability, and a continuous improvement mindset
Benefits and Perks

We value the total wellbeing of our people – including health, financial, personal and social wellness. We believe standard benefits like health insurance and fair pay are given at any organization. Still, you should know we offer: Fair and competitive salary and incentive compensation packages with an upside for overachievement Generous paid time off, including vacation, personal days, sick days and annual community service days Flexible, hybrid work environment Health, dental and vision benefits, including access to telemedicine and mental health services 2:1 401(k) match, up to 8% match immediately upon hire Discounted Employee Stock Purchase Plan Tax Savings Accounts for health, dependent and transportation Employee referral bonus program Volunteer opportunities to help you give back to your communities

Some of our associates’ favorite benefits and perks include: Complimentary lunch, snacks and coffee in any Cboe office Paid Tuition assistance and education opportunities Generous charitable giving company match Paid parental leave and fertility benefits On‑site gyms and discounts to other fitness centers

More About Cboe

We’re reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We’re investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We celebrate the diversity in our communities, inside and out, and welcome new perspectives with equity, inclusion and belonging. We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We’re an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes. Learn more about life at Cboe on our website and LinkedIn.

Equal Employment Opportunity

We celebrate the diversity in our communities, inside and out, and welcome new perspectives with equity, inclusion and belonging.

Equal Employment Opportunity We're proud to be an equal opportunity employer - and celebrate our associates' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status

Cboe Global Markets is an Equal Opportunity Employer.

Salary Ranges (applicable for US locations only)

At Cboe, we are committed to providing a competitive, transparent, and market‑informed total rewards program. The anticipated base salary range for this role is $130,900-$169,400, with actual compensation determined by job‑related factors such as skills, relevant experience, education, internal alignment, and location. This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long‑term equity programs. Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.

This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer - Threat Hunting
Senior Engineer - Threat Hunting

Cedar Cares, Inc • Chicago (IL)

On-site
USD 131,000 - 169,000
Salary & incentives
Paid time off
Health benefits
+1
Sr. Vulnerability Analyst
Sr. Vulnerability Analyst

Cedar Cares, Inc • Chicago (IL)

Hybrid
USD 122,000 - 157,000
Hybrid work
Health, dental and vision benefits
401(k) match
+4
Software Engineer
Software Engineer

Cedar Cares, Inc • Chicago (IL)

On-site
USD 108,000 - 139,000
Health insurance
401(k) match
Tuition assistance
+1
Sr. Information Security Engineer (Systems Engineer)
Sr. Information Security Engineer (Systems Engineer)

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 119,000 - 154,000
Health, dental, vision benefits
2:1 401(k) match up to 8%
Employee stock purchase plan
+3
Sr Info Security Engineer
Sr Info Security Engineer

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 92,000 - 154,000
Senior Investigator
Senior Investigator

Cedar Cares, Inc • Chicago (IL)

On-site
USD 98,000 - 127,000
Health benefits
401(k) plan
Paid time off
+1
Sr Investigator
Sr Investigator

Cedar Cares, Inc • Chicago (IL)

Hybrid
USD 98,000 - 127,000
Competitive salary
Hybrid work environment
Health, dental and vision benefits
+2
Principal Software Engineer at Cboe Global Markets
Principal Software Engineer at Cboe Global Markets

Cboe Global Markets • Chicago (IL)

On-site
USD 182,000 - 236,000
Senior Engineer - Machine Learning - Regulatory
Senior Engineer - Machine Learning - Regulatory

Cedar Cares, Inc • Chicago (IL)

On-site
USD 154,000 - 200,000
Health insurance
401(k) match
Paid time off
+2
Principal Software Engineer
Principal Software Engineer

Cedar Cares, Inc • Chicago (IL)

On-site
USD 182,000 - 236,000
Health benefits
Generous PTO
401(k) matching