Staff Detection Engineer, Security Engineering Lead

LinkedIn

Kansas

Remote

USD 156,000 - 255,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

LinkedIn is seeking a Staff Security Engineer in Detection Engineering to define and drive detection strategy across endpoint, identity, cloud, and SaaS environments. You will architect, build, and operate high-signal detections using detections-as-code, telemetry modeling, and data-driven efficacy measures.

This role emphasizes hands-on engineering leadership and scalable security automation. You will partner with Red and Purple Teams, validate effectiveness through adversary emulation, and

Qualifications

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
  • 5+ years in security engineering, detection engineering, or incident response
  • 2+ years technical leadership.
  • Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP).
  • Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)
  • Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.
  • Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.

Responsibilities

  • Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn.
  • Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple-team validation.
  • Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.
  • Lead adversary emulation exercises to validate detection coverage; develop synthetic signal and test harnesses.
  • Proactive threat hunting to discover unknown attacker activity; design hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) to orchestrate triage, enrichment, containment, and case workflow.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and collaborate with TI to turn reports into testable hypotheses.
  • Build and maintain a SIGMA-based detection content library; translate SIGMA to KQL/SQL where applicable.
  • Own telemetry quality: schemas, enrichment, normalization, and data reliability SLIs/SLOs.
  • Establish and monitor detection quality metrics (signal-to-noise ratio, precision/recall, false-positive rate, alert latency, lift); drive continuous tuning.
  • Lead incident retros to add resilient post-incident detections and suppress noisy patterns.
  • Mentor engineers; establish standards, code reviews, and guidance for detection engineering best practices.
  • Participate in on-call for critical detection pipelines and high-severity investigations.

Skills

Security engineering
Detection engineering
Technical leadership
KQL/SQL
Python

Education

BA/BS in CyberSecurity

Tools

SIGMA
SIEM
EDR

Job description

LinkedIn is seeking a Staff Security Engineer in Detection Engineering to define and drive detection strategy across endpoint, identity, cloud, and SaaS environments. You will architect, build, and operate high-signal detections using detections-as-code, telemetry modeling, and data-driven efficacy measures.

This role emphasizes hands-on engineering leadership and scalable security automation. You will partner with Red and Purple Teams, validate effectiveness through adversary emulation, and

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Detection Engineering Lead - Remote/Hybrid
Staff Detection Engineering Lead - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 156,000 - 255,000
Senior Detection Engineer: SIEM/XDR & Cloud Security
Senior Detection Engineer: SIEM/XDR & Cloud Security

LinkedIn • United States

Remote
USD 129,000 - 210,000
Health and wellness programs
Staff Security Engineer, Data Science & Detection
Staff Security Engineer, Data Science & Detection

Nscale • Seattle (WA)

On-site
USD 190,000 - 230,000
Competitive compensation package (base
Equity
Flexible work policies
Staff Security Data Engineer: Detection & Trust
Staff Security Data Engineer: Detection & Trust

Nscale • United States

Remote
USD 190,000 - 230,000
Base salary + bonus + equity
Dynamic progression plan
Flexible workplace
Senior Detection & Response Engineer — Build Next-Gen Security
Senior Detection & Response Engineer — Build Next-Gen Security

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Senior Threat Detection Lead - SOAR & SIEM Expert
Senior Threat Detection Lead - SOAR & SIEM Expert

ADP • Roseland (NJ)

On-site
USD 150,000 - 210,000
Staff Threat Detection & SecOps Engineer
Staff Threat Detection & SecOps Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Lead Detection Engineer—AI-Driven Security
Lead Detection Engineer—AI-Driven Security

Cisco • United States

Hybrid
USD 151,000 - 191,000
401(k) with matching
Paid parental leave
Disability coverage
+1
Senior Detection Engineer — Threat & Incident Response
Senior Detection Engineer — Threat & Incident Response

CoreWeave • Sunnyvale (CA)

On-site
USD 165,000 - 242,000
Medical, dental, and vision insurance
Company-paid Life Insurance
401(k) with employer match
+3
Staff Cloud Detection & Response Security Engineer
Staff Cloud Detection & Response Security Engineer

Australian Competition and Consumer Commission • Pittsburgh

Hybrid
USD 171,000 - 273,000