Job Description
JOB SUMMARY
\n
\n
The Detection & Platform Engineering team owns the technology backbone of the Security Operations Center (SOC). The team is responsible for building, operating, and continuously improving the platforms, automation, and detection capabilities that enable effective threat detection and response.
\n
\n
Our charter spans four key areas:
\n
\n
SIEM & SOAR Platform Management — Engineering, administration, optimization, and reliability of the SIEM and SOAR platforms supporting SOC operations.
\n
AI SOC — Deploying and scaling AI-driven investigation, triage, and analyst-assistance capabilities across the SOC.
\n
SOAR & Security Automation — Building playbooks, integrations, APIs, and automated workflows that reduce analyst toil and improve response efficiency.
\n
Detection Deployment — Developing, testing, validating, and deploying high-fidelity detections through a Detection-as-Code (DaC) pipeline.
\n
\n
Role Summary
\n
\n
We are seeking an experienced Detection & Platform Engineer with hands-on SOC and security engineering experience and a strong software-engineering mindset.
\n
\n
This is not a pure SOC analyst role. The ideal contractor will be comfortable building engineering solutions that improve the scalability and effectiveness of security operations. You will develop and maintain Detection-as-Code pipelines, automate SOC workflows, create and tune security detections, integrate security platforms through APIs, and leverage AI to improve investigation and detection-engineering productivity.
\n
\n
Key Responsibilities
\n
\n
Detection-as-Code Engineering
\n
\n
Design, build, and maintain Detection-as-Code (DaC) pipelines.
\n
Develop, test, validate, version, and deploy security detections through automated CI/CD workflows.
\n
Implement detection development standards, testing frameworks, code review processes, and deployment controls.
\n
Develop and tune high-fidelity detections across:
\n
Endpoint/EDR telemetry
\n
Cloud environments
\n
Network telemetry
\n
Email security telemetry
\n
DLP telemetry
\n
Reduce false positives while improving detection coverage and alert fidelity.
\n
Maintain detection logic, documentation, metadata, ownership, and lifecycle management.
\n
Collaborate with threat detection and SOC teams to translate threat intelligence and analyst requirements into production detections.
\n
\n
SIEM & SOAR Engineering
\n
\n
Support administration, engineering, optimization, and reliability of the SIEM/SOAR platform stack.
\n
Develop and maintain SIEM queries, correlation rules, dashboards, alerts, and detection content.
\n
Build SOAR playbooks to automate investigation, enrichment, containment, and response workflows.
\n
Develop API integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, threat intelligence, and other security platforms.
\n
Troubleshoot platform integrations, data ingestion, automation failures, and detection deployment issues.
\n
\n
Security Automation
\n
\n
Identify repetitive SOC processes and develop automation to reduce manual analyst effort.
\n
Build reusable Python/scripts, APIs, workflows, and automation components.
\n
Integrate security tools and services using REST APIs and webhooks.
\n
Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
\n
Improve operational efficiency, response times, and consistency through automation.
\n
\n
AI SOC Engineering
\n
\n
Support deployment and scaling of AI-driven investigation and triage capabilities.
\n
Identify opportunities to apply AI/LLMs to alert investigation, enrichment, summarization, detection development, and analyst workflows.
\n
Integrate AI capabilities with existing SOC platforms and automation workflows.
\n
Help establish appropriate validation, governance, and controls around AI-generated security outcomes.
\n
\n
Platform Engineering & Operations
\n
\n
Monitor and optimize the performance, reliability, scalability, and availability of SOC security platforms.
\n
Troubleshoot production issues and participate in incident resolution.
\n
Support platform upgrades, integrations, configuration changes, and operational improvements.
\n
Create technical documentation, runbooks, architecture documentation, and operational procedures.
\n
Work closely with SOC analysts, threat hunters, detection engineers, threat intelligence teams, infrastructure engineers, and security leadership.
\n
\n
Required Qualifications
\n
\n
5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or a related field.
\n
Hands-on experience building and maintaining Detection-as-Code or automated detection deployment pipelines.
\n
Strong understanding of SIEM and SOAR platforms and SOC operational workflows.
\n
Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
\n
Experience with CI/CD, Git, version control, automated testing, and deployment pipelines.
\n
Strong scripting/programming experience with Python or a similar language.
\n
Experience developing SOAR playbooks, security automation, API integrations, and workflows.
\n
Strong understanding of security events, logs, telemetry, alerting, detection logic, and incident-response processes.
\n
Experience working with REST APIs and integrating multiple security platforms.
\n
Strong troubleshooting and problem-solving skills.
\n
Ability to work independently in a fast-paced engineering environment.
\n
\n
Preferred Qualifications
\n
\n
Experience with Sigma, YARA, or other detection/content-as-code frameworks.
\n
Experience with major SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar.
\n
Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar.
\n
Experience with EDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar.
\n
Experience with cloud security telemetry across AWS, Azure, or GCP.
\n
Experience with GitHub/GitLab/Azure DevOps and CI/CD tooling.
\n
Experience with threat intelligence platforms and automated enrichment.
\n
Experience with LLMs, GenAI, AI agents, or AI-assisted SOC operations.
\n
Familiarity with MITRE ATT&CK and threat detection engineering methodologies.
\n
Experience in large enterprise SOC environments.
\n
\n
Technical Skills
\n
\n
Detection Engineering: Detection-as-Code, Sigma, YARA, detection logic, correlation rules, threat detection, MITRE ATT&CK
\n
\n
SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent
\n
\n
SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent
\n
\n
Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR platforms
\n
\n
Automation & Development: Python, REST APIs, JSON, webhooks, scripting
\n
\n
DevOps: Git, GitHub/GitLab, CI/CD, automated testing, infrastructure/deployment pipelines
\n
\n
Cloud: AWS, Azure, and/or GCP security telemetry
\n
\n
AI: Generative AI, LLMs, AI-assisted investigation, AI agents, automated triage
\n
\n
Security Frameworks: MITRE ATT&CK, threat detection lifecycle, incident response
\n
\n
Soft Skills
\n
\n
Strong engineering and automation mindset.
\n
Ability to translate SOC requirements into scalable technical solutions.
\n
Strong communication and documentation skills.
\n
Comfortable collaborating with security analysts and engineering teams.
\n
Ability to troubleshoot complex production environments.
\n
Strong ownership and ability to work independently.
\n
Detail-oriented approach to detection quality and operational reliability.
\n
\n
Top 3 Required Skills
\n
\n
Detection-as-Code + CI/CD Detection Engineering
\n
SIEM/SOAR Engineering + Security Automation
\n
Python/API Integrations + SOC Detection Engineering
\n
\n
Ideal Candidate Profile
\n
\n
The ideal candidate is a Security Detection/Automation Engineer rather than a traditional SOC Analyst—someone who can write code, build CI/CD pipelines, develop and tune detections, engineer SOAR workflows, integrate security platforms through APIs, and improve SOC operations through automation and AI.
