
Lead Cybersecurity Detection Engineer
Cox Enterprises, Inc.1 day ago
Atlanta, GA, USAStaff+
Base Salary
$123k - $204k/yr
Responsibilities
- Lead the detection engineering strategy, roadmap, and objectives.
- Design, build, deploy, and maintain advanced enterprise and customer-focused cybersecurity detection capabilities.
- Architect agentic AI and multi-agent systems for threat detection, investigation, threat hunting, and response.
- Develop custom detection rules, automated remediation playbooks, alerts, and SIEM/SOAR use cases.
- Manage SIEM and data lake data management and log ingestion infrastructure.
- Monitor, tune, validate, optimize, and sunset detections based on effectiveness and coverage.
- Use MITRE and ATLAS frameworks to identify detection gaps and improve coverage.
- Conduct attack simulation testing and purple teaming exercises.
- Collaborate with Incident Response and Threat Intelligence teams to accelerate threat identification and containment.
- Build operational guidelines, diagrams, documentation, and governance processes for detection and response.
- Partner with Cybersecurity, Engineering, Product, and other stakeholders to deliver customer-focused detection solutions.
- Provide hands-on technical leadership and mentorship to other engineers.
- Provide off-hour support for security administration, detection, and response activities.
Requirements
- Bachelor’s degree in Computer Science or a related discipline and 6+ years of industry-related professional experience.
- At least 3 years of experience in a cyber defense role.
- Multi-cloud security experience across AWS, Azure, and GCP.
- Experience with AI/ML frameworks and prompt engineering for security applications.
- Expert-level knowledge of detection engineering, the attack kill chain, and the diamond model.
- Strong experience in information security, network security, security monitoring, and incident response.
- Strong experience developing SIEM/SOAR detection and automation use cases.
- Experience with threat intelligence, firewalls, SASE, IPS, endpoint security, DLP, SIEM/SOAR, and data lakes.
- Preferred certifications include OSCP, GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA.
- Preferred experience includes DevOps, engineering, network administration, or system administration.
- Preferred experience developing customer-focused detection and response systems.
- Strong verbal and written communication skills and the ability to communicate with technical and non-technical stakeholders.
Benefits
- Hybrid work arrangement with the ability to work remotely part of the week.
- Flexible paid vacation, seven paid holidays, and up to 160 hours of paid wellness time annually.
- Additional paid leave may include bereavement, voting, jury duty, volunteer, military, and parental leave.
- Eligible benefits may include medical, dental, vision, 401(k), sick leave, parental leave, flexible vacation, wellness days, and/or PTO.
- No travel is required, and the work shift is daytime.
- Employment requires clearing a pre-employment drug test; marijuana is not currently included in the test for this position.
Tech Stack
Categories
About Cox Enterprises, Inc.
Cox Enterprises is a privately held, Atlanta-based company operating businesses in broadband and automotive services. Through Cox Communications, it provides internet, voice, and video to residential and business customers; through Cox Automotive, it runs marketplaces and dealer software including Autotrader, Kelley Blue Book, and Manheim. Founded in 1898, the family-owned company also invests in sustainable technologies and other growth ventures.