Senior Threat Detection Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $108k - $169k / year

⏰ Full Time

🟠 Senior

👷🏻‍♀️ Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cribl

Cribl

501 - 1000 employees

Founded 2017

☁️ SaaS

SaaS • Cloud

Cribl is a company providing a cloud-based service, allowing users to manage and analyze their data through a web application. The service includes features for user accounts and integration with Google for authentication.

📋 Description

• Design, build, test, and tune detections as code (KQL) through a GitOps workflow • Map detections to MITRE ATT&CK, identify coverage gaps, and prioritize investments based on the threat model • Review community and vendor rule releases such as Sigma and decide what to adopt, adapt, or skip • Reduce alert noise by tuning and retiring ineffective rules while tracking detection quality metrics • Plan and conduct hypothesis-driven threat hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry • Use adversary emulation to generate test events for detections • Convert hunt findings into durable detections, documentation, and backlog items • Participate in the incident response rotation during the initial 6–12 months • Triage, scope, contain, and investigate security incidents from first alert to closure • Run retrospectives and turn lessons into detections, playbook updates, and visibility fixes • Write and maintain incident response runbooks • Help own security log flow health, including onboarding sources, parsing, normalization, and monitoring data quality • Build and maintain Cribl Stream data pipelines to route, enrich, and reduce telemetry before SIEM ingestion • Maintain CI/CD and automation for the detection program, including GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and pull request review • Design processes, standards, and tools that help the team work effectively • Mentor teammates through code review, pairing, and documentation • Collaborate with IT, Infrastructure, Engineering, and GRC to improve visibility and detection coverage • Report to the Sr. Director, Security Engineering and Operations under the CISO

🎯 Requirements

• 5+ years in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response • Experience writing and maintaining detections as code in a modern SIEM • Strong Python skills and comfort with Git-based workflows, code review, and CI/CD • Strong KQL skills for writing detection queries • Working knowledge of MITRE ATT&CK and coverage analysis • Experience investigating incidents in cloud environments (AWS, GCP, and/or Azure), SaaS, and identity providers • Hands-on experience with log pipelines, including data ingestion, parsing, and troubleshooting • Ability to distinguish real signals from noise and determine when to escalate • Clear technical and non-technical writing skills for incident summaries, runbooks, and detection documentation • Routine use of AI in engineering work, with concrete examples of its impact on building, testing, or investigations • Bonus: experience with Cribl Stream or other telemetry pipeline tools • Bonus: experience with Sigma rules, adversary emulation (Atomic Red Team, Caldera, or similar), or purple teaming • Bonus: experience building agentic or AI-assisted workflows for security operations • Bonus: certifications such as GCIH, GCDA, or equivalent experience • Stand-by, on-call, or off-hours availability

🏖️ Benefits

• Health insurance • Dental insurance • Vision insurance • Short-term disability insurance • Life insurance • Paid holidays • Paid time off • Fertility treatment benefit • 401(k) • Equity • Cribl Corporate Bonus Program

Apply Now

Similar Jobs

🔥 20 minutes ago

Unisys

10,000+ employees

💼 Consulting

📦 Logistics

🤖 Artificial Intelligence

Senior Windows and VMware engineer modernizing enterprise cloud and hybrid-cloud infrastructure for Unisys. Leading migrations, virtualization, automation, and resiliency initiatives.

🔥 53 minutes ago

LMI

1001 - 5000

📦 Logistics

🏥 Healthcare

🎖️ Defense

Senior Requirements Engineer supporting DHS CBP mission systems through technology evaluation, requirements analysis, trade studies, and engineering documentation.

🔥 54 minutes ago

DMI (Digital Management, LLC)

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

COTS Systems Engineer maintaining secure enterprise applications across Windows, RHEL, virtualized, and AWS environments. Supporting DMI’s government and commercial clients through upgrades, troubleshooting, and security compliance.

🔥 1 hour ago

Dataminr

501 - 1000

🤖 Artificial Intelligence

🔐 Security

📱 Media

Forward Deployed Engineer deploying Palantir Foundry solutions and real-time intelligence for Dataminr’s defense and security customers. Building mission-critical data pipelines, applications, and integrations across secure environments.

🔥 2 hours ago

Sargent & Lundy

1001 - 5000

🏗️ Construction

🎖️ Defense

⚡ Energy

Lead piping stress engineer delivering nuclear piping analysis, design reviews, and technical leadership. Supporting Sargent & Lundy's clean-energy engineering and modernization projects.