Detection Engineer - REMOTE
Binary Defense
full-remotemidpermanentsecurity Houston, TX 4 days ago via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Detection EngineeringPythonREST APIsSigmaYARA-LMITRE ATT&CKSIEMEDRThreat ModelingCI/CD
About the role
Role Overview
Detection Engineer (REMOTE) for Binary Defense’s growing Detection Engineering team. You will build, deploy, and maintain high-quality security detections across SIEM, EDR, and cloud environments, operating in a detection-as-code, automation-driven workflow.
Responsibilities
- Design and implement detections using detection-as-code across SIEMs (Splunk, Microsoft Sentinel, Chronicle) and EDR platforms (CrowdStrike, Cortex XDR, SentinelOne).
- Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
- Use EDR/SIEM REST APIs to automate rule deployment, validation, and telemetry inspection to reduce reliance on GUIs.
- Collaborate with Threat Intel, Incident Response, and Cloud Security to create threat-informed detections based on real attacker behaviors.
- Perform threat modeling to identify high-value detection opportunities and coverage gaps.
- Analyze telemetry sources (Windows Event Logs, Sysmon, cloud logs, network traffic) and ensure telemetry readiness.
- Support adversary simulation and detection validation using Atomic Red Team, Caldera, or custom scripting.
- Document detection logic, coverage rationale, and response guidance.
- Continuously improve detection engineering workflows, tooling, and standards.
Requirements
- 2–5+ years hands-on experience in detection engineering, threat hunting, or incident response.
- Strong proficiency in Python and REST APIs for automating detection workflows with EDR/SIEM platforms.
- Proven ability to write/tune/validate detection logic in at least one of:
- Sigma, YARA-L, Splunk SPL, KQL, XQL
- Experience working with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud audit logs.
- Familiarity with MITRE ATT&CK and mapping detections to adversary techniques and detection choke points.
- Ability to quickly learn new security technologies and adapt detection strategies.
- Comfortable in a fast-paced, threat-driven environment with rapid iteration.
Preferred
- Experience with Cortex XDR and/or XSIAM (XQL-based detection + REST API interaction).
- Contributions to a detection-as-code pipeline (e.g., Git-based workflows, CI/CD).
- Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
- Familiarity with Sigma → YARA-L translation or detection rule normalization/enrichment workflows.
- Experience in IR consulting across diverse EDR/SIEM stacks.
About Binary Defense
Binary Defense is a Managed Detection and Response (MDR) provider trusted by hundreds of organizations to protect what matters most. The company delivers proactive, threat-driven security outcomes through SOC analysts, threat hunters, detection engineers, and threat researchers operating around the clock.
Scraped 8/2/2026