Detection Engineer - REMOTE

Posted 9 Hours Ago
Be an Early Applicant
Hiring Remotely in Houston, TX, USA
In-Office or Remote
Mid level
Information Technology • Security • Software • Cybersecurity
The Role
Build, deploy, and maintain detections across SIEMs, EDRs, and cloud; author detection-as-code (YAML/Sigma/YARA-L/SPL/KQL/XQL); automate rule deployment via APIs; collaborate with Threat Intel/IR; analyze telemetry (Windows logs, Sysmon, network, cloud); perform adversary simulation and validation; document detection logic and improve detection pipelines.
Summary Generated by Built In

Description

Binary Defense is seeking  an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You’ll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.
 

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.

Responsibilities

· Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).

· Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.

· Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs.

· Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.

· Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.

· Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.

· Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.

· Support documentation of detection logic, coverage rationale, and response guidance.

· Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Requirements

  

· 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response.

· Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.

· Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.

· Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.

· Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.

· Ability to quickly learn new security technologies and adapt detection strategies accordingly.

· Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.

Preferred

· Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).

· Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).

· Exposure to multi-tenant or MDR environments and scaling detections across customer environments.

· Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.

· Experience in IR consulting and working across diverse EDR/SIEM stacks.

About Binary Defense

Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.

For more information, visit our website, check out our blog, or follow us on LinkedIn.

Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!

Skills Required

  • 2-5+ years hands-on experience in detection engineering, threat hunting, or incident response.
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automation.
  • Experience writing, tuning, and validating detection logic in at least one: Sigma, YARA-L, Splunk SPL, KQL, XQL.
  • Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK and mapping detections to adversary techniques and detection choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies.
  • Comfortable working in a fast-paced, threat-driven environment with rapid iteration.
  • Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction).
  • Experience contributing to a detection-as-code pipeline (Git-based workflows, rule validation, CI/CD).
  • Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
  • Familiarity with Sigma to YARA-L translation or detection rule normalization and enrichment workflows.
  • Experience in IR consulting and working across diverse EDR/SIEM stacks.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
192 Employees

What We Do

Binary Defense is a cybersecurity company and managed security services provider specializing in Managed Detection and Response (MDR). The company provides comprehensive security solutions, including SOC-as-a-Service, threat hunting, and counterintelligence, to help organizations monitor, detect, and respond to cyberattacks. By combining human-driven expertise with its AI-powered NightBeacon platform, Binary Defense provides immediate protection and visibility to secure networks and stop advanced threats.

Similar Jobs

CrowdStrike Logo CrowdStrike

Detection Engineer - Machine Learning (Remote, East/Central)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
90K-125K Annually

Quora Logo Quora

Detection & CorpSec Engineer (Remote)

Artificial Intelligence • Consumer Web • Digital Media • Machine Learning • Software
Remote
2 Locations
240 Employees
172K-250K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Manufacturing Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Austin, TX, USA
40000 Employees
118K-201K Annually

Dragos Logo Dragos

SDE - UIUX

Security • Cybersecurity
Remote
United States
295 Employees
165K-165K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account