Source description
About the role
Charlotte, NC — Hybrid
W2 Only Mid-Level —
5 to 7 Years
Banking / Financial Services MITRE ATT&CK
Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.
? Critical Requirements
Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience
Role Objectives
Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness
Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services
Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies
Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond
Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives
Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities
Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content
Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency
Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements
Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks
Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience
Qualifications & Skills
-
Cloud & On-Prem Log Analysis SIEM / UEBA / EDR / SOAR Detection-as-Code Pipelines MITRE ATT&CK Framework Query Languages & Data Analysis Threat Intelligence Translation Automation & Scripting Windows & Linux OS Behavioral Analytics Security Telemetry & Correlation Data Lake & Ingestion Pipelines Response Playbook Development
-
? Additional Experience a Plus
-
Incident response
-
Threat intelligence operations
-
Vulnerability management
-
Security engineering
-
Cloud security
-
#LI-EW1
More at Sharp Decisions