Job Closed

This listing is no longer active.

AlphaSense logo
AlphaSense

The market intelligence and search platform trusted by over 3,500 leading organizations

Staff Detection and Response Engineer

EngineerEngineerFull TimeRemoteLeadTeam 1,001-5,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

India

Posted

99 days ago

Salary

0

Seniority

Lead

Job Description

Staff Detection and Response Engineer

AlphaSense

• Design, implement, and maintain advanced detection rules and correlation logic across SIEM , EDR, and Cloud platforms (AWS, GCP) • Lead detection strategy and architecture aligned with the Detection Quality frameworks • Write high-fidelity detection rules using languages like SIGMA and YARA-L • Conduct deep log source analysis, perform threat modeling, adversary emulation, and maintain MITRE ATT&CK mapping coverage • Conduct detection gap analysis to identify coverage opportunities across the kill chain • Create and maintain detection playbooks, runbooks, and comprehensive documentation • Perform detection quality assessments and continuous improvement initiatives • Develop complex automated response playbooks for multi-stage incidents spanning multiple security tools • Integrate security tools via APIs (SIEM, EDR, MDM, CASB, ITSM, threat intelligence platforms) • Create automated enrichment pipelines incorporating threat intelligence, asset context, and user behavior analytics • Develop automated containment actions (account disable, host isolation, firewall rule updates) • Measure and report automation ROI, tracking metrics like time saved and incident handling efficiency • Handle Incident Response processes and procedures as needed • Co-lead the organization's threat hunting program with the SOC Manager, defining strategy, methodology, and campaign planning • Execute proactive threat hunting campaigns by conducting hunt queries across SIEM and EDR platforms • Analyze large datasets to identify anomalous behavior patterns including user behavior, process execution, network traffic, and cloud activity • Develop hunting automation and tooling using custom Python scripts, Jupyter Notebooks, Osquery, and Velociraptor • Collaborate with threat intelligence sources to incorporate latest TTPs into hunting campaigns

Job Requirements

  • 7+ years in security operations with 3+ years in detection engineering, including deep expertise in creating high-fidelity rules (SIGMA, YARA-L, KQL, SPL).
  • Proven track record of building detection strategies across SIEM, EDR, and Cloud platforms, grounded in the MITRE ATT&CK framework.
  • Expert knowledge of SOAR platforms (e.g., Tines, Splunk SOAR, Cortex XSOAR), architecture, and complex playbook development.
  • Proven experience designing and implementing SOAR platform architecture from concept to production.
  • Advanced scripting and automation development skills in Python (required) for API integrations and security tool orchestration.
  • Strong background in threat hunting methodology, hypothesis development, and campaign execution, with experience leading or co-leading hunting programs.
  • Proficiency with data analysis, anomaly detection, and hands-on experience with hunting tools like Jupyter Notebooks, Osquery, and Velociraptor.
  • Deep understanding of attack techniques, lateral movement, persistence mechanisms, and post-exploitation TTPs across Windows, Linux, and macOS.
  • Familiarity with security frameworks including MITRE ATT&CK, PICERL, NIST CSF, and Detection Maturity Models, and incident response best practices.
  • Proven ability to lead technical initiatives, mentor team members, and communicate complex technical concepts to diverse audiences.

Benefits

  • High-Impact Leadership Role: Own critical security capabilities (detection, automation, hunting) with direct organizational impact
  • Greenfield Opportunities: Architect and build SOAR platform from the ground up and lead major SIEM migration efforts
  • Technical Depth: Solve complex problems at scale with Modern security stack
  • Scale & Complexity: Protect a critical platform serving enterprise customers with sophisticated threats
  • Autonomy & Influence: Shape security architecture decisions, tool evaluations, and team direction
  • Growing Team: Join a growing team with clear structure, specialized roles, and growth trajectory
  • Balance & Variety: Split time between strategic architecture (detection, SOAR) and hands-on execution (hunting, investigation)
  • Innovation Culture: Implement detection-as-code, automation-as-code, and data-driven security practices

Related Categories

Related Job Pages

More Engineer Jobs

Coalition logo

Site Reliability Engineer II

Coalition

Coalition is a cybersecurity company dedicated to partnering with clients to help them prevent and mitigate losses. Coalition helps small and medium-sized businesses around the wor

Engineer99 days ago

Role Description We are looking for a Site Reliability Engineer to join our Platform SRE team. In this role, you will build and operate the infrastructure, tools, and "paved roads" that empower our developers to deliver scalable, secure, and reliable software with speed and confidence. - You’ll work across the entire stack—from infrastructure automation and observability to developer enablement and system reliability. - You will be a key collaborator with software engineering and security teams, helping to evolve our Infrastructure as Code (IaC), enhance CI/CD pipelines, and scale our internal developer platform. - We value pragmatism and engineering excellence, primarily using Python, Go, and AWS to reduce toil and build self-service capabilities. Qualifications - 4+ years in SRE, DevOps, Cloud Engineering, or Software Development roles. - Hands-on experience operating and scaling production environments within AWS. - Strong expertise with Terraform for managing complex cloud infrastructure. - Proficiency in Go or Python, with experience building production-grade automation, tooling, or libraries. - Experience with ECS or Kubernetes. - Familiarity with modern deployment tools, specifically GitHub Actions. - Strong written and verbal skills with a knack for evangelizing reliability best practices across the organization. Requirements - Design, build, and scale production environments using AWS and Terraform. - Improve the resilience and operability of our platform through failure-based testing and automated recovery strategies. - Design and implement reusable platform components and self-service tools to streamline the developer experience. - Implement and maintain robust observability practices, including system metrics, distributed tracing, and SLO management. - Participate in technical design discussions, sharing feedback and adapting strategies based on team input and evolving requirements. - Uphold high infrastructure quality and actively contribute to the team's evolving best practices and standards. - Participate in a low-volume on-call rotation. Benefits - 100% medical, dental, and vision coverage - Flexible PTO - Annual home office stipend and WeWork access - Mental & physical health wellness programs like Headspace, Lumino, and more! - Competitive compensation and opportunity for advancement

Canada
C$115K - C$159.8K / year
Job Closed
Humach logo

Forward Deployed Engineer

Humach

We combine the strengths of both humans and machines to deliver exceptional customer experiences.

Engineer99 days ago
OtherRemoteTeam 1,001-5,000H1B No Sponsor

• Build and deploy AI agents using large language models (LLMs) • Implement backend services and APIs to support agent workflows • Develop and refine prompts, tools, and context strategies for agent reliability • Configure and extend agent orchestration (state management, tool calling, memory) • Integrate third-party services and AI platforms (e.g., voice, speech-to-text, messaging) • Deploy and operate services in AWS, including monitoring and basic DevOps workflows • Work on real customer problems with incomplete requirements and iterate toward solutions • Collaborate closely with senior engineers to learn system design and production patterns

Texas
Engineer99 days ago
Full TimeRemoteTeam 10,001+H1B Sponsor

• Analyze the design package provided by the Design Office • Create the industrial dossier in compliance with requirements, integrating bills of materials (BOMs) and the manufacturing process • Prepare the instruction/work sheets associated with the industrial dossier • Ensure configuration management • Perform updates to the quality system tools • Submit tooling requests • Handle non-conformities and, if necessary, create repair dossiers • Participate in continuous improvement meetings

France
Job Closed
Leidos logo

Transmission Line Engineer

Leidos

Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.

Engineer99 days ago
OtherRemoteTeam 10,001+Since 1969H1B Sponsor

• Work as a member of a dynamic team solving challenging problems involved with electric transmission • Serve as an Engineer on electric transmission line design projects for extra high-voltage (EHV) overhead and underground systems • Apply NESC, ASCE, ACI and other applicable standards in engineering and design • Perform engineering analyses, prepare bidding documents, draft plans and specifications, and prepare material procurement and construction documents • Collaborate with a multi-person team and interface with clients, project planning, environmental, permitting, and construction management personnel

Colorado + 1 moreAll locations: Colorado | Minnesota
$59.2K - $106.9K / year