Senior Logging & Detection Engineer
Clio
full-remoteseniorpermanentsecuritybackend Full remote 73 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Security AnalyticsDetection EngineeringSIEMSOARMITRE ATT&CKKQL (Kusto)Splunk SPLElasticsearchUEBALog Analytics
About the role
Role overview
Join Clio as a Senior Logging & Detection Engineer. You’ll lead the technical direction of Clio’s Security and Logging Engineering teams, with a focus on building scalable detection logic, optimizing log analytics performance, and translating threat intelligence into effective detections.
Key missions
- Design and implement advanced detection rules and queries across logging platforms.
- Act as the primary liaison with the threat intelligence team, creating and owning a framework to convert intelligence into scalable detections.
- Drive performance optimization and resource utilization for petabyte-scale log datasets, including index design and data tiering.
Responsibilities
- Own the full lifecycle of detection rules, alerts, and automated response workflows within SIEM/SOAR environments.
- Lead/participate in threat hunting using log data to identify sophisticated threats and anomalous behavior.
- Provide expert incident response support with technical forensics and analysis during major security incidents.
- Integrate and optimize security tooling such as SIEM platforms and SOAR/security orchestration systems.
Requirements
- Deep background in security analytics and senior-level detection engineering with platform-level log analysis.
- Strong log analysis experience across large-scale data sources, including multi-cloud logs (AWS, Azure, GCP), network flows, and security tool outputs.
- Expertise in detection engineering: owning the end-to-end rule/alert/automation lifecycle in SIEM/SOAR.
- Advanced dashboarding and visualization skills (e.g., Kibana, Grafana, Tableau) for security metrics and executive reporting.
- Strong performance optimization skills (query tuning, index design, data partitioning, resource-efficient analytics).
- Advanced query language proficiency in at least two of: Elasticsearch/Lucene, SQL, KQL (Kusto), SPL (Splunk).
- Senior scripting/automation ability with Python/Go/PowerShell for custom tooling, API work, and detection automation.
- Experience building and scaling enterprise-grade security monitoring/detection.
- Ability to build detection content mapped to MITRE ATT&CK, including coverage gap analysis.
- Experience leading threat hunting and improving craft (including interest in AI).
Nice-to-haves (from the posting)
- Experience with advanced analytics/ML/statistical modeling for security (e.g., UEBA or predictive threat modeling).
- Industry-recognized security certifications (e.g., GCTI, GCFA, GNFA, CISSP).
- Multi-platform security architecture across major clouds (CloudTrail, Azure Activity Logs, GCP Audit Logs).
- Track record of open-source contributions to detection/SIEM content.
- Data science / advanced math background (e.g., anomaly detection, clustering, predictive analytics).
- Cloud-native security analytics and serverless detection architectures (e.g., Security Hub, Defender for Cloud).
Location / eligibility
- Full remote.
- Open to candidates across Canada excluding Quebec.
About Clio
Clio is a rapidly growing legal technology company. In this role, you’ll work within Clio’s Security organization, specifically the Logging Engineering and Security teams, to build large-scale security detection and monitoring capabilities.
Scraped 5/12/2026