Detection Engineer
- Own the full detection lifecycle: threat intelligence intake and hypothesis formation through rule authoring, testing, deployment, and continuous tuning across SIEM, EDR, NDR, and cloud-native platforms.
- Apply detection-as-code principles: detection logic version-controlled in Git, tested in CI/CD pipelines, and deployed through automated workflows using Sigma, YARA, and Terraform.
- Design and build SOAR playbooks and enrichment workflows so high-confidence alert classes are triaged, enriched, and resolved without manual analyst intervention; serve as the human-in-the-loop auditor validating AI-generated investigation narratives.
- Serve as incident commander on rotation for complex security events, and conduct hypothesis-driven threat hunts across endpoint, network, identity, and cloud telemetry.
The platform is a cloud-native digital banking provider serving roughly eight million consumer accounts across ninety financial institutions. Security here sits where banking compliance, cloud-native infrastructure, and real-time threat detection converge, with detection and response capabilities aligned to the regulatory requirements and control frameworks the industry demands.
This is not a traditional SOC analyst seat. AI-driven triage and SOAR handle the bulk of routine alert processing; the work is building the detections those platforms execute, authoring the automation that keeps the SOC operating at machine speed, and hunting for the threats that evade automated pipelines. Detection coverage is mapped to MITRE ATT&CK and maintained as a living matrix. I surface gaps proactively from threat intelligence, red team findings, and incident post-mortems, and track them through the detection backlog.