Staff Security Engineer – Detection Engineering

CyberJobs.Com

Mountain View (CA)

Hybrid

USD 156,000 - 255,000

Full time

31 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

LinkedIn is seeking a Staff Security Engineer in Detection Engineering to define and drive detection strategy across endpoint, identity, cloud, and SaaS environments. You will architect and operate high-signal detections using modern detections‑as‑code practices, telemetry modeling, and data‑driven metrics, including precision, recall, and latency.

You’ll collaborate with Red/Purple Teams to validate efficacy, mentor engineers, and shape engineering standards while delivering scalable, secure

Qualifications

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
  • 5+ years in security engineering, detection engineering, or incident response
  • 2+ years technical leadership
  • Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP)
  • Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)
  • Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.
  • Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.
  • Experience designing schemas and data models (e.g., ASIM/OSSEM-like) and telemetry pipelines.
  • Experience with SIGMA rule authoring and translation; adversary emulation/purple-team experience.

Responsibilities

  • Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn
  • Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple-team validation.
  • Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.
  • Lead adversary emulation exercises to validate detection coverage; develop synthetic signal and test harnesses.
  • Proactive threat hunting to discover unknown attacker activity; design hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) to orchestrate triage, enrichment, containment, and case workflow.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and collaborate with TI to turn reports into testable hypotheses.
  • Build and maintain a SIGMA-based detection content library; translate SIGMA to KQL/SQL where applicable.
  • Own telemetry quality: schemas, enrichment, normalization, and data reliability SLIs/SLOs.
  • Establish and monitor detection quality metrics (signal-to-noise ratio, precision/recall, false-positive rate, alert latency, lift); drive continuous tuning.
  • Lead incident retros to add resilient post-incident detections and suppress noisy patterns.
  • Mentor engineers; establish standards, code reviews, and guidance for detection engineering best practices.
  • Participate in on‑call for critical detection pipelines and high‑severity investigations.

Skills

Security engineering
Technical leadership
KQL/SQL
Python scripting

Education

BA/BS in CyberSecurity or related field

Tools

SIGMA
CI/CD
ASIM/OSSEM-like schemas

Job description

LinkedIn is seeking a Staff Security Engineer in Detection Engineering to define and drive detection strategy across endpoint, identity, cloud, and SaaS environments. You will architect and operate high-signal detections using modern detections‑as‑code practices, telemetry modeling, and data‑driven metrics, including precision, recall, and latency.

You’ll collaborate with Red/Purple Teams to validate efficacy, mentor engineers, and shape engineering standards while delivering scalable, secure

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Detection Engineering Lead - Remote/Hybrid
Staff Detection Engineering Lead - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 156,000 - 255,000
Senior Detection Engineer — Remote/Hybrid
Senior Detection Engineer — Remote/Hybrid

LinkedIn • United States

Hybrid
USD 129,000 - 212,000
Staff Cloud Security & Detection Engineer
Staff Cloud Security & Detection Engineer

Aurora • San Francisco (CA)

Hybrid
USD 189,000 - 303,000
Hybrid work model
Staff Security Engineer – Detection Engineering
Staff Security Engineer – Detection Engineering

Colossus Technologies Group • United States

On-site
USD 170,000 - 210,000
Detection Engineer — Security Ops (Onsite, Redmond)
Detection Engineer — Security Ops (Onsite, Redmond)

SPACE EXPLORATION TECHNOLOGIES CORP • Redmond (WA)

On-site
USD 130,000 - 180,000
Stock or equity
Medical, vision, and dental
401(k)
+2
Staff Security Engineer: Detection & Response Leader
Staff Security Engineer: Detection & Response Leader

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000
Public Sector Security Engineer: Detections & IR
Public Sector Security Engineer: Detections & IR

Scale AI • Washington

On-site
USD 218,000 - 342,000
Equity
Health benefits
Retirement benefits
+2
Staff Security Engineer – Detection & Response Lead
Staff Security Engineer – Detection & Response Lead

IBM • Boston (KY)

On-site
USD 150,000 - 210,000
Staff Cloud Detection & Response Security Engineer
Staff Cloud Detection & Response Security Engineer

Australian Competition and Consumer Commission • Pittsburgh

Hybrid
USD 171,000 - 273,000
Senior Security Detection Engineer
Senior Security Detection Engineer

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 184,000 - 297,000