xelys jobs xelys jobs

Detection Engineer - REMOTE

Binary Defense

full-remotemidpermanentsecurity Houston, TX 4 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Detection EngineeringPythonREST APIsSigmaYARA-LMITRE ATT&CKSIEMEDRThreat ModelingCI/CD

About the role

Role Overview

Detection Engineer (REMOTE) for Binary Defense’s growing Detection Engineering team. You will build, deploy, and maintain high-quality security detections across SIEM, EDR, and cloud environments, operating in a detection-as-code, automation-driven workflow.

Responsibilities

  • Design and implement detections using detection-as-code across SIEMs (Splunk, Microsoft Sentinel, Chronicle) and EDR platforms (CrowdStrike, Cortex XDR, SentinelOne).
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
  • Use EDR/SIEM REST APIs to automate rule deployment, validation, and telemetry inspection to reduce reliance on GUIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security to create threat-informed detections based on real attacker behaviors.
  • Perform threat modeling to identify high-value detection opportunities and coverage gaps.
  • Analyze telemetry sources (Windows Event Logs, Sysmon, cloud logs, network traffic) and ensure telemetry readiness.
  • Support adversary simulation and detection validation using Atomic Red Team, Caldera, or custom scripting.
  • Document detection logic, coverage rationale, and response guidance.
  • Continuously improve detection engineering workflows, tooling, and standards.

Requirements

  • 2–5+ years hands-on experience in detection engineering, threat hunting, or incident response.
  • Strong proficiency in Python and REST APIs for automating detection workflows with EDR/SIEM platforms.
  • Proven ability to write/tune/validate detection logic in at least one of:
    • Sigma, YARA-L, Splunk SPL, KQL, XQL
  • Experience working with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud audit logs.
  • Familiarity with MITRE ATT&CK and mapping detections to adversary techniques and detection choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies.
  • Comfortable in a fast-paced, threat-driven environment with rapid iteration.

Preferred

  • Experience with Cortex XDR and/or XSIAM (XQL-based detection + REST API interaction).
  • Contributions to a detection-as-code pipeline (e.g., Git-based workflows, CI/CD).
  • Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
  • Familiarity with Sigma → YARA-L translation or detection rule normalization/enrichment workflows.
  • Experience in IR consulting across diverse EDR/SIEM stacks.

About Binary Defense

Binary Defense is a Managed Detection and Response (MDR) provider trusted by hundreds of organizations to protect what matters most. The company delivers proactive, threat-driven security outcomes through SOC analysts, threat hunters, detection engineers, and threat researchers operating around the clock.

Scraped 8/2/2026