Padmi

Cyber Security Engineer – Threat Detection

HybridPosted 1 month ago
CybersecurityMid-level
Apply at Sharp Decisions

Opens the source posting on sharpdecisions.com

Source description

About the role

View original

Charlotte, NC — Hybrid

W2 Only Mid-Level —

5 to 7 Years

Banking / Financial Services MITRE ATT&CK

Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.

? Critical Requirements

Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience

Role Objectives

Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness

Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services

Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies

Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond

Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives

Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities

Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content

Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency

Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements

Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks

Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience

Qualifications & Skills

  • Cloud & On-Prem Log Analysis SIEM / UEBA / EDR / SOAR Detection-as-Code Pipelines MITRE ATT&CK Framework Query Languages & Data Analysis Threat Intelligence Translation Automation & Scripting Windows & Linux OS Behavioral Analytics Security Telemetry & Correlation Data Lake & Ingestion Pipelines Response Playbook Development

  • ? Additional Experience a Plus

  • Incident response

  • Threat intelligence operations

  • Vulnerability management

  • Security engineering

  • Cloud security

  • #LI-EW1

One address, no account. We’ll tell you when matching roles go live.

More at Sharp Decisions

Related open roles

View all roles