
Sr. Detection Engineer
Cboe Global Markets4 days ago
Base Salary
$131k - $169k/yr
Responsibilities
- Write, tune, and maintain production detection logic across SIEM, EDR, identity, and cloud platforms.
- Validate detections by executing targeted attack techniques and confirming true positives, benign behavior handling, and repeatability.
- Build adversary-simulation tooling, reusable validation packages, automated regression tests, and continuous coverage reporting.
- Build and operate sandbox and detonation infrastructure for exploit triage, malware analysis, and safe technique development.
- Evaluate proof-of-concept exploit code, identify generated telemetry and organizational exposure, and convert findings into detection or hunting content.
- Produce threat-hunting validation content, including seeded artifacts, known-truth datasets, and repeatable test cases.
- Automate scheduled technique execution, telemetry collection, coverage reporting, and detection performance measurement.
- Apply AI and LLM tooling to triage, enrichment, exploit and malware analysis, detection drafting, and hunt hypothesis generation.
- Conduct security testing of internal web applications and APIs and translate findings into detection requirements and remediation guidance.
- Support complex Incident Response investigations with attacker-tradecraft expertise and create detections based on investigation findings.
- Document and hand off tooling, environments, and test content so others can operate them independently.
Requirements
- 5+ years of hands-on security engineering experience with substantial detection-authoring experience.
- Strong command of at least one detection query language, such as KQL, Sigma, or YARA-L, or an equivalent.
- Practical knowledge of attacker techniques across Windows, Active Directory, Entra ID, AWS, Azure, SaaS, and containerized workloads.
- Ability to read unfamiliar exploit or malware code and identify observable artifacts suitable for detection.
- Fluency in at least one tooling language, such as Python, Go, C#, PowerShell, or Bash, or an equivalent.
- Working knowledge of Windows event logs, EDR process and network events, cloud audit logs, and identity sign-in data, including their limitations.
- Experience building and tearing down test infrastructure using virtualization, containers, infrastructure-as-code, and CI/CD.
- Disciplined approach to false positives, alert quality, and the operational burden placed on analysts.
- Clear technical writing for engineers, including detection documentation and analyst-facing response guidance.
- High ethical standards and discipline regarding authorization, scope, blast radius, and sensitive data.
- Bachelor's degree or equivalent practical experience.
- Preferred qualifications include public detection content or research, atomic testing frameworks, continuous control validation, MITRE ATT&CK coverage analysis, AI engineering, reverse engineering, Windows internals, EDR telemetry and evasion research, regulated-enterprise experience, and mentoring experience.
Benefits
- Flexible, hybrid work environment.
- Health, dental, and vision benefits, including telemedicine and mental health services.
- Generous paid time off, including vacation, personal, sick, and community service days.
- 2:1 401(k) match up to 8%, available immediately upon hire.
- Discounted Employee Stock Purchase Plan and tax savings accounts for health, dependent, and transportation expenses.
- Employee referral bonus program, volunteer opportunities, and charitable giving company match.
- Complimentary lunch, snacks, and coffee in Cboe offices.
- Tuition assistance and education opportunities.
- Paid parental leave, fertility benefits, on-site gyms, and fitness-center discounts.
About Cboe Global Markets
Cboe Global Markets operates exchanges and market infrastructure for options, equities, futures, FX, ETPs, and digital assets used by brokers, banks, and institutional and retail investors. Its revenue comes from transaction and listing fees, market data and index licensing (including VIX and SPX), and related services. Founded in 1973 and headquartered in Chicago, it runs Cboe Options and Cboe Futures exchanges as well as European trading venues.