xelys jobs xelys jobs

Senior Logging & Detection Engineer

Clio

full-remoteseniorpermanentsecuritybackend Full remote 73 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Security AnalyticsDetection EngineeringSIEMSOARMITRE ATT&CKKQL (Kusto)Splunk SPLElasticsearchUEBALog Analytics

About the role

Role overview

Join Clio as a Senior Logging & Detection Engineer. You’ll lead the technical direction of Clio’s Security and Logging Engineering teams, with a focus on building scalable detection logic, optimizing log analytics performance, and translating threat intelligence into effective detections.

Key missions

  • Design and implement advanced detection rules and queries across logging platforms.
  • Act as the primary liaison with the threat intelligence team, creating and owning a framework to convert intelligence into scalable detections.
  • Drive performance optimization and resource utilization for petabyte-scale log datasets, including index design and data tiering.

Responsibilities

  • Own the full lifecycle of detection rules, alerts, and automated response workflows within SIEM/SOAR environments.
  • Lead/participate in threat hunting using log data to identify sophisticated threats and anomalous behavior.
  • Provide expert incident response support with technical forensics and analysis during major security incidents.
  • Integrate and optimize security tooling such as SIEM platforms and SOAR/security orchestration systems.

Requirements

  • Deep background in security analytics and senior-level detection engineering with platform-level log analysis.
  • Strong log analysis experience across large-scale data sources, including multi-cloud logs (AWS, Azure, GCP), network flows, and security tool outputs.
  • Expertise in detection engineering: owning the end-to-end rule/alert/automation lifecycle in SIEM/SOAR.
  • Advanced dashboarding and visualization skills (e.g., Kibana, Grafana, Tableau) for security metrics and executive reporting.
  • Strong performance optimization skills (query tuning, index design, data partitioning, resource-efficient analytics).
  • Advanced query language proficiency in at least two of: Elasticsearch/Lucene, SQL, KQL (Kusto), SPL (Splunk).
  • Senior scripting/automation ability with Python/Go/PowerShell for custom tooling, API work, and detection automation.
  • Experience building and scaling enterprise-grade security monitoring/detection.
  • Ability to build detection content mapped to MITRE ATT&CK, including coverage gap analysis.
  • Experience leading threat hunting and improving craft (including interest in AI).

Nice-to-haves (from the posting)

  • Experience with advanced analytics/ML/statistical modeling for security (e.g., UEBA or predictive threat modeling).
  • Industry-recognized security certifications (e.g., GCTI, GCFA, GNFA, CISSP).
  • Multi-platform security architecture across major clouds (CloudTrail, Azure Activity Logs, GCP Audit Logs).
  • Track record of open-source contributions to detection/SIEM content.
  • Data science / advanced math background (e.g., anomaly detection, clustering, predictive analytics).
  • Cloud-native security analytics and serverless detection architectures (e.g., Security Hub, Defender for Cloud).

Location / eligibility

  • Full remote.
  • Open to candidates across Canada excluding Quebec.

About Clio

Clio is a rapidly growing legal technology company. In this role, you’ll work within Clio’s Security organization, specifically the Logging Engineering and Security teams, to build large-scale security detection and monitoring capabilities.

Scraped 5/12/2026