about 13 hours ago
Tel Aviv-Yafo, IsraelMid Level / Senior / Staff+
Responsibilities
- Develop detection coverage strategies across endpoint, identity, cloud, and infrastructure.
- Create a Detection-as-Code pipeline for version control, testing, and deployment of detection logic.
- Architect connections between detections and automated response workflows.
- Establish technical standards for detection design, testing, and documentation.
- Measure and improve detection quality through fidelity metrics and validation loops.
- Design high-fidelity behavioral detections for SIEM and EDR platforms.
- Translate threat intelligence into scalable, evasion-resistant detections.
- Validate detections through threat simulations and continuous testing.
- Collaborate with SOC analysts to enhance detection feedback loops.
- Define and communicate detection engineering metrics to security leadership.
Requirements
- Minimum 3 years in detection engineering or security operations with demonstrated depth.
- Experience leading detection engineering work as a senior technical contributor.
- Strong understanding of attacker tradecraft and adversary behavior.
- Hands-on experience with enterprise SIEM and EDR platforms like Splunk or CrowdStrike.
- Strong query development skills in SPL, KQL, Sigma, or similar.
- Solid engineering practices including Git, CI/CD, and code review.
- Experience using MITRE ATT&CK for designing and measuring detection coverage.
- Ability to make and defend technical decisions and establish standards.
Benefits
- Competitive compensation.
- Career growth and learning opportunities.
- Flexibility and ownership.
- Collaborative and innovative culture.
- Opportunity to work on impactful AI projects.
- International environment with talented teams.