Detection Engineer

Posted Yesterday
Be an Early Applicant
Chicago, IL, USA
Hybrid
100K-140K Annually
Entry level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Tempus is a technology company leading the adoption of AI to advance precision medicine and patient care.
The Role
Build and maintain reliable log ingestion pipelines to deliver security events to a SIEM. Implement batching, sizing, failure handling, tests, and CI standards. Integrate systems via APIs, assist detection engineering with parser/field fixes, manage detection-as-code in git, and contribute to agentic SOC workflows and SOAR automations with human-in-the-loop validation.
Summary Generated by Built In

Passionate about precision medicine and advancing the healthcare industry?

Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.

**About our teams:** With a mission to use data and AI to power precision medicine and improve patient care, our teams blend deep healthcare expertise with modern product development practices. Tempus products are owned and developed by small, autonomous teams made up of software engineers, designers, scientists, and product managers. These teams set goals, build the software, deploy the code, and contribute to a growing platform that is transforming healthcare.

**Detection Engineer:** The Security Operations Center is building the data foundation for threat detection—reliable pipelines that land security events in our SIEM platform. This is a software engineering role inside security: you will build in Python, integrate APIs, and test your work, with mentorship on SIEM usage, detection logic, and alert quality. Over time, you will help us grow **agentic SOC workflows** (AI-assisted triage, enrichment, and detection support) with human-in-the-loop guardrails—adding automation only when the data and evidence justify it, not on a hype-driven timeline.

Responsibilities:

  • Build and maintain log ingestion pipelines that collect security events from internal and third-party sources and deliver them to our SIEM platform.

  • Normalize and forward events using existing patterns for batching, sizing, and failure handling.

  • Build tests and fix bugs using mocked APIs and team CI standards (lint, format, coverage).

  • Operate pipelines reliably—monitor failures, tune ingestion windows and rate limits, and document configuration.

  • Support detection engineering with guidance—validate that new data is queryable in the SIEM; assist with simple parser or field fixes; learn how detections map to adversary behavior.

  • Help manage and improve our detection-as-code pipeline—versioned detection content in git, automated checks in CI, and review before changes reach production.

  • Participate in code review.

Agentic SOC (incremental; human-in-the-loop):

  • Build with agentic coding tools (e.g. Claude Code, Cursor) as part of daily development—direct, review, and test what you ship; do not rely on typing every line from scratch.

  • Contribute incrementally to agentic workflows—enrichment scripts, structured handoffs into SOAR automations, and evaluation of AI-assisted summaries or drafts in non-production or human-reviewed paths before any autonomous response.

  • Validate changes on historical data before production trust—rules, parsers, and automation earn approval through evidence, simulation or shadow mode, and defined rollback paths.

  • Assist in building and maintaining SOAR automations (enrichment, triage steps, and documentation—with review before production changes).

Requirements:

  • Comfortable building Python—APIs and JSON, basic error handling, and tests in a managed project (Poetry or similar).

  • Ability to integrate systems via APIs—OAuth or API keys, retries, and handling partial failures.

  • Testing discipline—unit tests, readable failures, and fixing regressions you introduce before merge.

  • Git and collaborative development—small, reviewable changes with clear descriptions of risk and rollout.

  • Temperament for long-horizon work—you can focus on incremental pipeline quality while understanding it enables agentic SOC capabilities over time, not instead of them.

  • Strong problem-solving skills and curiosity about security operations; willingness to learn detection concepts with mentorship.

Bonus points for:

  • Experience with scheduled jobs or Docker.

  • Hands-on SIEM exposure from coursework, CTFs, labs, or internships (e.g. Splunk, Google SecOps, Microsoft Sentinel).

  • Can navigate cloud primitives on GCP, Azure, or AWS (S3/GCS/Blob, Key Vault/Secret Manager/Secrets Manager, IAM roles and service principals).

  • Experience with infrastructure as code (e.g. Terraform).

  • Strong understanding of IAM principles in GCP (least privilege, service accounts, workload identity, and role bindings).

#LI-Hybrid#LI-BL1

Chicago Base salary: $100,000-$140,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. 

Skills Required

  • Proficient building in Python (APIs, JSON, basic error handling) and tests in a managed project (Poetry or similar).
  • Ability to integrate systems via APIs (OAuth or API keys), implement retries and handle partial failures.
  • Testing discipline: unit tests, readable failures, and fixing regressions prior to merge.
  • Experience with Git and collaborative development workflows (code review, small reviewable changes).
  • Temperament for long-horizon, incremental pipeline quality work.
  • Strong problem-solving skills and curiosity about security operations; willingness to learn detection concepts with mentorship.
  • Experience with scheduled jobs or Docker.
  • Hands-on SIEM exposure (Splunk, Google SecOps, Microsoft Sentinel).
  • Familiarity with cloud primitives on GCP, Azure, or AWS (S3/GCS/Blob, Key Vault/Secret Manager/Secrets Manager, IAM).
  • Experience with infrastructure as code (Terraform).
  • Strong understanding of IAM principles in GCP (least privilege, service accounts, workload identity).

What the Team is Saying

Rachel
Louis
Anita
Alexis
Hala
Aaron
Alexis
Ash
Emma
Anita
Mile

Tempus AI Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage spans medical, dental, vision, life/AD&D, short‑term disability, mental‑health/EAP, FSAs, and even pet insurance. Feedback suggests this breadth meets core needs for many employees.
  • Wellbeing & Lifestyle Benefits On‑site cafeteria meals, stocked snacks, an on‑site barista, commuter benefits, gym discounts, ERGs, and regular events enhance daily experience, especially at Chicago HQ. Feedback suggests these amenities add tangible value for those working regularly on‑site.
  • Parental & Family Support Parental leave and an onsite Mother’s Room are highlighted, alongside hybrid work in many roles. Feedback suggests these supports help work‑life integration for caregivers.

Tempus AI Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,775 Employees
Year Founded: 2015

What We Do

We bring together one of the world’s largest libraries of multimodal clinical and molecular data with a robust suite of AI tools to help physicians personalize care in real time, connect patients with therapies and clinical trials, and enable partners to accelerate discovery and development of new treatments. With ~8 million de-identified research records and 350+ petabytes of data, Tempus partners with more than half of U.S. oncologists and the majority of the top 20 global pharma companies. Our teams are pioneering work across oncology, neurology, psychiatry, cardiology, and beyond—transforming how care is delivered and therapies are developed. At Tempus, every role contributes to our mission: to help each patient benefit from the experiences of those who came before. For more information, visit tempus.com.

Why Work With Us

We’re looking for people who can change the world. People who question the status quo and refuse to shy away from tough problems. For builders who are never done building, and the learners who are never done learning. Passionate individuals with undying curiosity who want to take on one of the greatest challenges humanity has ever faced—head on.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Tempus AI Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Most of the team follows a hybrid policy, with some roles allowing for a fully remote arrangement and some roles being onsite only.

Typical time on-site: 3 days a week
Company Office Image
HQChicago - Tempus Headquarters & Lab
Company Office Image
RTP - Tempus Lab
Company Office Image
Boston - Tempus Office
Company Office Image
Seattle - Tempus Office
Company Office Image
Lewisburg - Tempus Office
Company Office Image
Madison - Tempus Office
Company Office Image
Milwaukee - Tempus Office
Company Office Image
New York City - Tempus Office
Company Office Image
Atlanta - Tempus Lab
Company Office Image
Bay Area - Tempus Office
Company Office Image
Washington DC - Tempus Office
Learn more

Similar Jobs

Tempus AI Logo Tempus AI

Senior Software Engineer

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Hybrid
Chicago, IL, USA
3775 Employees
150K-190K Annually

Tempus AI Logo Tempus AI

Scientist

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Remote or Hybrid
Illinois, USA
3775 Employees
100K-125K Annually

Tempus AI Logo Tempus AI

Scientist

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Remote or Hybrid
Illinois, USA
3775 Employees
60K-100K Annually

Tempus AI Logo Tempus AI

Associate Director RWE, PharmaR&D

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Hybrid
3 Locations
3775 Employees
155K-210K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account