Detection Engineer - REMOTE
Totem Market Valuations
full-remoteseniorpermanentsecuritybackend Houston, TX Yesterday via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Detection EngineeringThreat ModelingMITRE ATT&CKDetection-as-CodePythonREST APIsSigmaYARA-LSIEMEDR
About the role
Role Overview
Detection Engineer for Binary Defense’s Detection Engineering team. You will build, deploy, and maintain threat detections across SIEMs, EDRs, and cloud environments using a detection-as-code approach.
Responsibilities
- Design and implement detections across SIEM platforms (Splunk, Sentinel, Chronicle) and EDR platforms (CrowdStrike, Cortex XDR, SentinelOne)
- Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control
- Use REST APIs to automate rule deployment, validation, and telemetry inspection to reduce GUI dependency
- Collaborate with Threat Intel, Incident Response, and Cloud Security teams to build threat-informed detections based on real attack behaviors
- Perform threat modeling to identify high-value detection opportunities and coverage gaps
- Analyze telemetry sources (Windows Event Logs, Sysmon, cloud logs, network traffic) to identify use cases and ensure telemetry readiness
- Participate in adversary simulation and detection validation using Atomic Red Team, Caldera, or custom scripting
- Document detection logic, coverage rationale, and response guidance
- Improve detection engineering workflows, tooling, and standards continuously
Requirements
- 2–5+ years hands-on experience in detection engineering, threat hunting, or incident response
- Strong Python skills and experience using REST APIs to automate detection workflows with EDR/SIEM platforms
- Experience writing, tuning, and validating detection logic in at least one of:
- Sigma, YARA-L, Splunk SPL, KQL, XQL
- Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud audit logs
- Familiarity with MITRE ATT&CK and mapping detections to techniques and detection choke points
- Ability to learn new security technologies quickly and adapt detection strategies
- Comfortable iterating rapidly in a fast-paced, threat-driven environment
Preferred
- Experience with Cortex XDR and/or XSIAM (XQL-based detection + REST API interaction)
- Contribution to a detection-as-code pipeline (Git-based workflows, rule validation, CI/CD)
- Exposure to multi-tenant or MDR environments and scaling detections across customer environments
- Familiarity with Sigma-to-YARA-L translation or detection rule normalization/enrichment workflows
- IR consulting experience across diverse EDR/SIEM stacks
About Totem Market Valuations
Binary Defense is a Managed Detection and Response (MDR) provider trusted by hundreds of organizations. The company combines SOC analysts, threat hunters, detection engineers, and threat researchers to deliver proactive, risk-focused security outcomes. Their teams work around the clock to improve detection coverage, efficacy, and scalability.
Scraped 8/1/2026