Job Location
CINCINNATI GENERAL OFFICESJob Description
At P&G, we believe that diverse experiences help build strong leaders. Mobility is a key component of many management careers, providing opportunities to grow through different assignments, locations, and business challenges. Candidates should be prepared to consider relocation opportunities throughout their career as business needs and development opportunities arise.
The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI — using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.
You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands-on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.
Key Success Metrics
Your success would be based on operational and project deliverables, which would be reviewed on a quarterly basis. Your manager would provide full-support though continuous mentoring and coaching
- Detection rules you write catch real threats and generate minimal noise
- You measurably improve alert fidelity (TP rate) and reduce SOC case volume
- You operate independently within the detection-as-code workflow (branch → validate → deploy)
- You leverage AI tooling to work faster — not as a research project, but as a daily force multiplier
- Quarterly deliverables reviewed with your manager through continuous mentoring and coaching
Job Responsibilities:
Detection Engineering:- Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk
- Write detection logic across the SIEM and data lake platforms
- Manage detection content as code — Git-based workflows, PR reviews, CI/CD deployment pipelines
- Investigate and suppress false positives systematically using lookup-based architectures
- Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI→TH→DE pipeline)
- Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns
- Leverage AI agents and LLM-assisted workflows to accelerate detection rule development, validation, and coverage analysis
- Use and contribute to MCP (Model Context Protocol) tooling that enables AI-assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps)
- Operate agentic pipelines that triage large rule libraries against live telemetry at scale
- Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets
- Stay current on frontier AI threats (agentic attacks, LLM-assisted exploitation, AI-generated phishing) and translate them into detection opportunities
- Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements
- Collaborate with data engineers on telemetry availability, data quality, and log source onboarding
- Contribute to detection coverage reporting and MITRE ATT&CK posture measurement
- Document detection logic, tuning rationale, and suppression decisions
Job Qualifications
Technical Competencies and Experience:
Required:
- Bachelor’s degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience in detection engineering, security operations, or threat detection roles
- Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real-time alerts)
- Strong understanding of MITRE ATT&CK framework and its application to detection coverage
- Proficiency in Python for automation, scripting, and tooling
- Experience with git-based workflows (branching, PRs, CI/CD) for managing security content
- Familiarity with security log sources: EDR, identity, cloud, network, proxy
- Strong analytical skills and ability to distinguish true threats from noise in large datasets
Preferred:
- Certifications CISSP, CCSP, OSCP, GIAC Certified Detection Analyst (GCDA), GCIA, Relevant certifications in cloud & ML/AIExperience with multiple query languages are helpful but not required
- Experience with detection-as-code practices and YAML-based rule formats (Sigma, custom schemas)
- Working knowledge of AI/LLM capabilities and their security implications — both as detection targets and as engineering tools
- Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows
- Familiarity with SOAR platforms and their integration with detection pipelines
- Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments
Compensation for roles at P&G varies depending on a wide array of non-discriminatory factors including but not limited to the specific office location, role, degree/credentials, relevant skill set, and level of relevant experience. At P&G compensation decisions are dependent on the facts and circumstances of each case. Total rewards at P&G include salary + bonus (if applicable) + benefits. Your recruiter may be able to share more about our total rewards offerings and the specific salary range for the relevant location(s) during the hiring process.
We are committed to providing equal opportunities in employment. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Immigration Sponsorship is not available for this role. For more information regarding who is eligible for hire at P&G along with other work authorization FAQ’s, please click HERE.
Procter & Gamble participates in E-Verify.
Qualified individuals will not be disadvantaged based on being unemployed.
P&G is dedicated to meeting the needs of applicants requesting an accommodation/adjustment due to a disability in order to complete the online application process. If you have a disability that affects your ability to complete our online application process, please visit our Disability Accommodation Page.
Job Schedule
Full timeJob Number
R000155624Job Segmentation
Experienced ProfessionalsStarting Pay / Salary Range
$110,000.00 - $165,300.00 / yearSkills Required
- Bachelor's degree in Information Systems, Information Technology, Computer Science, Engineering, or another technical or IT field, and/or at least 5 years of relevant experience in detection engineering, security operations, or threat detection
- Experience writing and tuning SIEM detection rules or analytics, including correlation rules, scheduled queries, or real-time alerts
- Strong understanding of the MITRE ATT&CK framework and its application to detection coverage
- Proficiency in Python for automation, scripting, and tooling
- Experience with Git-based workflows, including branching, pull requests, and CI/CD, for managing security content
- Familiarity with EDR, identity, cloud, network, and proxy security log sources
- Strong analytical skills and ability to distinguish true threats from noise in large datasets
- CISSP, CCSP, OSCP, GCDA, GCIA, or relevant cloud or ML/AI certifications
- Experience with multiple query languages
- Experience with detection-as-code practices and YAML-based rule formats such as Sigma or custom schemas
- Working knowledge of AI/LLM capabilities and security implications
- Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows
- Familiarity with SOAR platforms and their integration with detection pipelines
- Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments
Procter & Gamble Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Procter & Gamble and has not been reviewed or approved by Procter & Gamble.
-
Fair & Transparent Compensation — Compensation is considered competitive and benchmarked against top industry peers, supported by formal pay‑equity audits and stated transparent principles. Feedback suggests pay is a strong draw, with raises described as attainable and benefits starting from day one of training.
-
Healthcare Strength — Health coverage is broad and immediate, including medical, dental, vision, life and disability insurance, with mental‑health and telemedicine offerings expanded recently. This breadth and day‑one access contribute to a perception of reliable, comprehensive care.
-
Parental & Family Support — Parental leave is inclusive under a global framework for all parents, with added recovery time for birth mothers. Adoption, fertility, childcare support and eldercare services further strengthen family support.
Procter & Gamble Insights
What We Do
Procter & Gamble Company is an American multi-national consumer goods corporation. P&G was founded over 180 years ago as a soap and candle company. Today, we’re the world’s largest consumer goods company and home to iconic, trusted brands, including Always®, Charmin®, Braun®, Fairy®, Febreze®, Gillette®, Head & Shoulders®, Oral B®, Pantene®, Pampers®, Tide®, and Vicks®. The design, development, growth and success of these products—and many more—is thanks to the innovative and insightful minds of our people. From Day 1, you’ll help make everyday life easier for our 5 billion consumers through billion dollar brands. With our large global footprint, there are many opportunities to work with P&G in multiple locations. We offer opportunities in approximately 70 countries and continually aim to attract, reward and advance the finest people in the world. As a "build from within" organization, we see 95% of our people start at an entry level and progress through the organization. Here, we want you to get your career off to a fast start. That's why we don't have any rotational development programs or gradual ramping-up periods: you’ll be able—and encouraged—to dive right in from day 1. Join us and help make life better through meaningful work that makes an impact from Day 1.
.png)






