Threat Detection Engineer - Splunk, UEBA & RBA

Piper Companies

United States

Remote

USD 130,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
401(k)
PTO

Job summary

Piper Companies is seeking a Detection & Threat Engineer to join a leading cybersecurity-focused organization in the United States. The role focuses on building advanced threat detections, enhancing security monitoring, and increasing threat visibility across enterprise environments.

You will write SPL queries from scratch and apply RBA and UEBA techniques to detect evolving threats. You will partner with Threat Hunting, Incident Response, and SOC teams to implement MITRE ATT&CK-aligned use

Qualifications

  • 4+ years of experience in detection/engineering or security operations.
  • Advanced SPL query development from scratch in Splunk.
  • Experience with Risk-Based Alerting (RBA) and UEBA in enterprise security.
  • Experience developing detection logic and use cases within Splunk Enterprise Security.
  • Familiarity with threat actor TTPs and MITRE ATT&CK framework.
  • Experience supporting SOC, Incident Response, or Threat Hunting functions.

Responsibilities

  • Develop and maintain advanced detection content in Splunk Enterprise Security and related security platforms.
  • Write complex SPL queries from scratch to identify threats, suspicious behaviors, and emerging attack techniques.
  • Design, implement, and optimize Risk-Based Alerting (RBA) methodologies to improve detection fidelity and reduce alert fatigue.
  • Leverage UEBA capabilities to identify anomalous user and entity behavior across enterprise environments.
  • Partner with Threat Hunting, Incident Response, and Security Operations teams to improve detection coverage and investigation workflows.
  • Analyze attack patterns and adversary techniques to create proactive detection use cases aligned with the MITRE ATT&CK framework.
  • Continuously tune and enhance alerting logic to improve operational efficiency and threat visibility.
  • Support detection engineering initiatives for cloud, endpoint, identity, and network security technologies.

Skills

SPL queries
RBA
UEBA
Threat detection
Threat hunting
Security engineering
Analytical skills
Communication

Tools

Splunk Enterprise Security
MITRE ATT&CK

Job description

Piper Companies is seeking a Detection & Threat Engineer to join a leading cybersecurity-focused organization in the United States. The role focuses on building advanced threat detections, enhancing security monitoring, and increasing threat visibility across enterprise environments.

You will write SPL queries from scratch and apply RBA and UEBA techniques to detect evolving threats. You will partner with Threat Hunting, Incident Response, and SOC teams to implement MITRE ATT&CK-aligned use

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection Engineer - Splunk & UEBA Expert
Threat Detection Engineer - Splunk & UEBA Expert

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+2
Detection & Threat Engineer
Detection & Threat Engineer

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical
Dental
Vision
+2
Detection & Threat Engineer - 175934
Detection & Threat Engineer - 175934

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+2
Incident Response Engineer - Threat Hunting & Splunk
Incident Response Engineer - Threat Hunting & Splunk

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical, dental, vision
401(k)
PTO
Remote Incident Response Engineer - Splunk & Threat Hunting
Remote Incident Response Engineer - Splunk & Threat Hunting

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical, dental, vision benefits
401(k) plan
Paid time off
Remote Threat Investigator | CSIRT & Splunk Expert
Remote Threat Investigator | CSIRT & Splunk Expert

Piper Companies • United States

Remote
USD 120,000 - 180,000
Medical benefits
Dental benefits
Vision benefits
+1
Remote Threat Hunter & Incident Response Specialist
Remote Threat Hunter & Incident Response Specialist

Piper Companies • United States

Remote
USD 120,000 - 180,000
Medical, dental, vision benefits
401(k)
PTO
Remote Threat Hunter - Proactive Security & Splunk Expert
Remote Threat Hunter - Proactive Security & Splunk Expert

Piper Companies • United States

Remote
USD 130,000 - 160,000
Health insurance
Vision insurance
Dental insurance
+2
Threat Intelligence & Detection Engineer — Splunk
Threat Intelligence & Detection Engineer — Splunk

SECU • United States

On-site
USD 120,000 - 180,000
Lead Detection Engineer — Splunk ES & Threat Hunting (Remote)
Lead Detection Engineer — Splunk ES & Threat Hunting (Remote)

K&A Technologies LLC • Washington

Hybrid
USD 165,000 - 190,000