xelys jobs xelys jobs

Detection Engineer - REMOTE

Totem Market Valuations

full-remoteseniorpermanentsecuritybackend Houston, TX Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Detection EngineeringThreat ModelingMITRE ATT&CKDetection-as-CodePythonREST APIsSigmaYARA-LSIEMEDR

About the role

Role Overview

Detection Engineer for Binary Defense’s Detection Engineering team. You will build, deploy, and maintain threat detections across SIEMs, EDRs, and cloud environments using a detection-as-code approach.

Responsibilities

  • Design and implement detections across SIEM platforms (Splunk, Sentinel, Chronicle) and EDR platforms (CrowdStrike, Cortex XDR, SentinelOne)
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control
  • Use REST APIs to automate rule deployment, validation, and telemetry inspection to reduce GUI dependency
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to build threat-informed detections based on real attack behaviors
  • Perform threat modeling to identify high-value detection opportunities and coverage gaps
  • Analyze telemetry sources (Windows Event Logs, Sysmon, cloud logs, network traffic) to identify use cases and ensure telemetry readiness
  • Participate in adversary simulation and detection validation using Atomic Red Team, Caldera, or custom scripting
  • Document detection logic, coverage rationale, and response guidance
  • Improve detection engineering workflows, tooling, and standards continuously

Requirements

  • 2–5+ years hands-on experience in detection engineering, threat hunting, or incident response
  • Strong Python skills and experience using REST APIs to automate detection workflows with EDR/SIEM platforms
  • Experience writing, tuning, and validating detection logic in at least one of:
    • Sigma, YARA-L, Splunk SPL, KQL, XQL
  • Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud audit logs
  • Familiarity with MITRE ATT&CK and mapping detections to techniques and detection choke points
  • Ability to learn new security technologies quickly and adapt detection strategies
  • Comfortable iterating rapidly in a fast-paced, threat-driven environment

Preferred

  • Experience with Cortex XDR and/or XSIAM (XQL-based detection + REST API interaction)
  • Contribution to a detection-as-code pipeline (Git-based workflows, rule validation, CI/CD)
  • Exposure to multi-tenant or MDR environments and scaling detections across customer environments
  • Familiarity with Sigma-to-YARA-L translation or detection rule normalization/enrichment workflows
  • IR consulting experience across diverse EDR/SIEM stacks

About Totem Market Valuations

Binary Defense is a Managed Detection and Response (MDR) provider trusted by hundreds of organizations. The company combines SOC analysts, threat hunters, detection engineers, and threat researchers to deliver proactive, risk-focused security outcomes. Their teams work around the clock to improve detection coverage, efficacy, and scalability.

Scraped 8/1/2026