The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage.
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage.
Detection Engineer
Orlando, FL · On-site
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage.
Detection Engineer
Orlando, FL · On-site
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage.
Detection Engineer
Orlando, FL · On-site
Security Detections Engineer The Security Detections Engineer is responsible for designing, building and continuously improving EA's detection and response capabilities across our global environment.
Detection Engineer
Orlando, FL · On-site
Security Detections Engineer The Security Detections Engineer is responsible for designing, building and continuously improving EA's detection and response capabilities across our global environment.
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused ...
Threat Detection Engineer
Sarasota, FL · On-site
Tenex is seeking a highly motivated and skilled Threat Detection Engineer to join our growing Security Operations team. In this critical role, you will be responsible for proactively identifying and ...
Threat Detection Engineer
Sarasota, FL · On-site
Tenex is seeking a highly motivated and skilled Threat Detection Engineer to join our growing Security Operations team. In this critical role, you will be responsible for proactively identifying and ...
Standardize and maintain detection rule naming conventions and labeling across the SOC environment * Review, customize, and manage security playbooks pulled from integrated code repositories ...
Standardize and maintain detection rule naming conventions and labeling across the SOC environment * Review, customize, and manage security playbooks pulled from integrated code repositories ...
Standardize and maintain detection rule naming conventions and labeling across the SOC environment * Review, customize, and manage security playbooks pulled from integrated code repositories ...
Standardize and maintain detection rule naming conventions and labeling across the SOC environment * Review, customize, and manage security playbooks pulled from integrated code repositories ...
Security Engineer I
Plantation, FL · On-site
In this role you will be responsible for collaborating in a team environment on detection engineering, incident response, SIEM and SOAR development along with a strong emphasis on scripting (Python ...
Security Engineer I
Plantation, FL · On-site
In this role you will be responsible for collaborating in a team environment on detection engineering, incident response, SIEM and SOAR development along with a strong emphasis on scripting (Python ...
In this role you will be responsible for collaborating in a team environment on detection engineering, incident response, SIEM and SOAR development along with a strong emphasis on scripting (Python ...
In this role you will be responsible for collaborating in a team environment on detection engineering, incident response, SIEM and SOAR development along with a strong emphasis on scripting (Python ...
Cyber Threat Hunter
Coral Springs, FL · On-site
You will partner closely with detection engineering, security operations, and incident response teams in a cloud environment, with a primary focus on proactive detection development and signal ...
Cyber Threat Hunter
Coral Springs, FL · On-site
You will partner closely with detection engineering, security operations, and incident response teams in a cloud environment, with a primary focus on proactive detection development and signal ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to develop ...
SITEC - Network Defense Engineer - MacDill AFB
Tampa, FL · On-site
$80K - $128K/yr
The Network Defense Engineer is responsible for designing the organization's network threat detection and countermeasure capabilities. This role focuses on engineering sophisticated telemetry ...
SITEC - Network Defense Engineer - MacDill AFB
Tampa, FL · On-site
$80K - $128K/yr
The Network Defense Engineer is responsible for designing the organization's network threat detection and countermeasure capabilities. This role focuses on engineering sophisticated telemetry ...
As the Senior Threat Detection & Response Engineer, you will work as the overall responsible person for the design and development of countermeasures capabilities. This is an opportunity to ...
As the Senior Threat Detection & Response Engineer, you will work as the overall responsible person for the design and development of countermeasures capabilities. This is an opportunity to ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Detection Engineer information
See Florida salary details
$8.8K - $21.9K
0% of jobs
$21.9K - $35.1K
0% of jobs
$35.1K - $48.2K
0% of jobs
$48.2K - $61.3K
0% of jobs
$61.3K - $74.5K
0% of jobs
$74.5K - $87.6K
0% of jobs
$87.6K - $100.8K
22% of jobs
$111.4K is the 25th percentile. Wages below this are outliers.
$100.8K - $113.9K
4% of jobs
The median wage is $125.4K / yr.
$113.9K - $127.1K
28% of jobs
$135.6K is the 75th percentile. Wages above this are outliers.
$127.1K - $140.2K
33% of jobs
$140.2K - $153.3K
13% of jobs
$8.8K
$124.6K
$153.3K
How much do detection engineer jobs pay per year?
What does a detection engineer do?
A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.
What kind of projects or tasks does a detection engineer typically work on?
As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.
What are the key skills and qualifications needed to thrive as a detection engineer?
To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

ThreatLocker rating
7.0
Based on 6 frontline employees who took The Breakroom Quiz
194th of 241 rated software companies
Job description
COMPANY OVERVIEW
ThreatLocker is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker platform with Application Allowlisting, Ringfencing, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.
JOB OVERVIEW
ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK Framework.
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage. Working closely with Threat Analysts and Security Researchers, this individual will develop high-quality detection logic that identifies evolving attacker techniques while minimizing false positives.
As a Detection Engineer, you are responsible for, but not limited to:
- Develop, test, and maintain detection content for ThreatLocker's Endpoint Detection and Identity Threat Detection platforms.
- Create and maintain custom Sigma, YARA, and Snort detection rules.
- Map detections to the MITRE ATT&CK Framework and continuously improve coverage.
- Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
- Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation activity.
- Collaborate with Threat Analysts and Security Researchers to identify and remediate detection gaps.
- Validate detection logic through threat hunting, malware analysis, and adversary emulation.
- Tune detection content to improve accuracy while reducing false positives.
- Document detection methodologies and technical findings for internal teams.
- Stay current on emerging threats, attack techniques, and industry best practices.
- The role will be based in Orlando, FL and is an in-office position.
REQUIRED QUALIFICATIONS
- 3+ years of experience in Information Security.
- 2+ years of experience working with Endpoint Detection and Response (EDR) or Identity Threat Detection and Response (ITDR) technologies within an enterprise environment.
- Experience developing detection content is strongly preferred.
- Strong understanding of the MITRE ATT&CK Framework and its application within enterprise security.
- Experience creating custom Sigma, YARA, and Snort detection rules.
- Strong knowledge of Windows operating systems and Windows forensic artifacts.
- Experience with Windows persistence mechanisms, privilege escalation, defense evasion, and parent-child process relationships.
- Familiarity with malware analysis, threat hunting, and vulnerability research.
- Familiarity with adversary emulation and post-exploitation frameworks.
- Strong analytical, troubleshooting, and critical thinking skills.
- Excellent written and verbal communication skills with the ability to explain technical concepts to non-technical stakeholders.
- Ability to work independently while collaborating effectively within a team environment.
- Relevant certifications such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.
WORKING CONDITIONS
The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.
- Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
- While performing duties of this job, would occasionally require standing, walking, sitting, reaching with hands and arms, climbing or balancing, stooping or kneeling, talking and hearing, and using fingers and hands to feel objects and tools.
- Must occasionally lift and/or move up to 25 pounds.
- Specific vision abilities required include close vision, distance vision, depth perception, and the ability to adjust focus.
A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.
ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.
What ThreatLocker employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About ThreatLocker
Sourced by ZipRecruiter
Industry
Network security
Company size
201 - 500 Employees
Headquarters location
Maitland, FL, US
Year founded
2015