Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Principal Consultant - SIEM | Remote, USA
Leawood, KS · Remote
$134K - $184K/yr
Architect and validate SIEM solutions to ensure the customer's risk reduction, visibility, and detection engineering objectives are met. Lead SIEM platform design, deployment, migration, and ...
Principal Consultant - SIEM | Remote, USA
Leawood, KS · Remote
$134K - $184K/yr
Architect and validate SIEM solutions to ensure the customer's risk reduction, visibility, and detection engineering objectives are met. Lead SIEM platform design, deployment, migration, and ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
Experience leading one or more security operations domains (e.g., incident response, detection engineering, threat intelligence, network security). * Experience streamlining processes, automating ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
Experience leading one or more security operations domains (e.g., incident response, detection engineering, threat intelligence, network security). * Experience streamlining processes, automating ...
VP, Agentic Managed Detection & Response (MDR) | Remote, USA
Leawood, KS · On-site +1
$175K - $225K/yr
The Vice President, Agentic Managed Detection & Response (MDR) is a premier executive leader ... Data Engineering & SIEM Modernization: Oversee the strategy for large-scale data ingestion ...
VP, Agentic Managed Detection & Response (MDR) | Remote, USA
Leawood, KS · On-site +1
$175K - $225K/yr
The Vice President, Agentic Managed Detection & Response (MDR) is a premier executive leader ... Data Engineering & SIEM Modernization: Oversee the strategy for large-scale data ingestion ...
VP, Agentic Managed Detection & Response (MDR) | Remote, USA
Leawood, KS · Remote
$175K - $225K/yr
The Vice President, Agentic Managed Detection & Response (MDR) is a premier executive leader ... Data Engineering & SIEM Modernization: Oversee the strategy for large-scale data ingestion ...
VP, Agentic Managed Detection & Response (MDR) | Remote, USA
Leawood, KS · Remote
$175K - $225K/yr
The Vice President, Agentic Managed Detection & Response (MDR) is a premier executive leader ... Data Engineering & SIEM Modernization: Oversee the strategy for large-scale data ingestion ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
New
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
New
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Senior SOC Analyst - Weekends
Topeka, KS · On-site
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Senior SOC Analyst - Weekends
Topeka, KS · On-site
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Senior SOC Analyst - Weekends
Wichita, KS · On-site
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Senior SOC Analyst - Weekends
Wichita, KS · On-site
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Engineer, test, and deploy new detection logic, alerting mechanisms, behavioral analytics, and ATT&CK-aligned use cases. * Identify control gaps and collaborate with platform owners to implement both ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
Documents engineering decisions, detection logic, workflows, and best practices to ensure operational continuity * Assists with the implementation, configuration and operations of various security ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
Documents engineering decisions, detection logic, workflows, and best practices to ensure operational continuity * Assists with the implementation, configuration and operations of various security ...
Senior Communications Security Engineer
Overland Park, KS · On-site
$113K - $155K/yr
... Engineer/Analyst to lead the design, implementation, and continuous improvement of security ... Phishing and malware detection * Email authentication (SPF, DKIM, DMARC) * Safe Links / Safe ...
Senior Communications Security Engineer
Overland Park, KS · On-site
$113K - $155K/yr
... Engineer/Analyst to lead the design, implementation, and continuous improvement of security ... Phishing and malware detection * Email authentication (SPF, DKIM, DMARC) * Safe Links / Safe ...
Cloud Security Engineer
Overland Park, KS · On-site
Detection & Automation * Custom Logic: Write custom YARA-L detection rules to correlate cloud ... Current Google Cloud Associate Cloud Engineer or professional security certifications. * Advanced ...
Cloud Security Engineer
Overland Park, KS · On-site
Detection & Automation * Custom Logic: Write custom YARA-L detection rules to correlate cloud ... Current Google Cloud Associate Cloud Engineer or professional security certifications. * Advanced ...
$61K - $79K/yr
Your work will directly affect the success of product releases, accelerate our defect detection and ... Learn more about our engineering culture here: StackAdapt is a remote-first company; we are open to ...
$61K - $79K/yr
Your work will directly affect the success of product releases, accelerate our defect detection and ... Learn more about our engineering culture here: StackAdapt is a remote-first company; we are open to ...
Cloud Security Engineer
Overland Park, KS · On-site
Detection & Automation * Custom Logic: Write custom YARA-L detection rules to correlate cloud ... Current Google Cloud Associate Cloud Engineer or professional security certifications. * Advanced ...
Quick apply
Cloud Security Engineer
Overland Park, KS · On-site
Detection & Automation * Custom Logic: Write custom YARA-L detection rules to correlate cloud ... Current Google Cloud Associate Cloud Engineer or professional security certifications. * Advanced ...
Detection Engineer information
See Kansas salary details
$9.7K - $24.3K
0% of jobs
$24.3K - $38.9K
0% of jobs
$38.9K - $53.4K
0% of jobs
$53.4K - $68K
0% of jobs
$68K - $82.6K
0% of jobs
$82.6K - $97.1K
0% of jobs
$97.1K - $111.7K
22% of jobs
$123.5K is the 25th percentile. Wages below this are outliers.
$111.7K - $126.3K
4% of jobs
The median wage is $138.9K / yr.
$126.3K - $140.8K
28% of jobs
$150.3K is the 75th percentile. Wages above this are outliers.
$140.8K - $155.4K
33% of jobs
$155.4K - $170K
13% of jobs
$9.7K
$138.1K
$170K
How much do detection engineer jobs pay per year?
What does a Detection Engineer do?
A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.
What kind of projects or tasks does a Detection Engineer typically work on?
As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.
What are the key skills and qualifications needed to thrive in the Detection Engineer position, and why are they important?
To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

Deloitte rating
8.1
Based on 90 frontline employees who took The Breakroom Quiz
58th of 150 rated financial services
Job description
Are you passionate about technology and interested in joining a community of collaborative colleagues who respectfully and courageously seek to challenge the status quo? If so, read on to learn more about an exciting opportunity with Deloitte Technology US (DT - US). We are curious and life-long learners focused on technology and innovation.
Recruiting for this role ends on 7/31/2026.
Work you'll do
The position supports the SOC as an escalation point identifying and addressing potential SIEM content/level I and II engineering security concerns as this role is the first line of operational support. This role is also responsible for supporting Security application patching, content creation as requested from all stake holders, and development of process documentation.
Responsibilities by category:
Administrative
- Maintain ticket management and DevOps activity tracking to ensure accurate work intake, prioritization, and status reporting.
- Monitor and communicate Microsoft product updates; assess and advise on impacts on the environment and customers.
- Build strong stakeholder relationships and provide timely end-user support with clear follow-through and resolution documentation.
- Create and maintain process documentation (runbooks, SOPs, workflows) to support consistent execution and knowledge transfer.
- Maintain and enforce change control and peer review processes to promote quality, security, and auditability.
Threat Detection
- Threat detection development in Microsoft Sentinel and Defender platforms sing KQL.
- Align detection rules to current and emerging threats, leveraging external threat intelligence as appropriate.
- Identify and remediate detection gaps using the MITRE ATT&CK framework, based on business risk and priorities.
- Collaborate with Cybersecurity teams (e.g., Incident Response, Threat Intelligence, Engineering) to ensure cross-team alignment and coverage.
- Develop, tune, and support analytics/detection rules, including performance monitoring and optimization.
- Develop, maintain, and optimize playbooks/notebooks, including operational reliability and performance.
- Develop, maintain, and optimize Logic Apps, including operational reliability and performance.
- Develop, maintain, and optimize workbooks and dashboards to support detection engineering and SOC visibility.
- Support reporting needs tied to threat detection outcomes, metrics, and operational insights.
- Define and document required fields per data source to enable effective detection and investigation.
- Identify and remediate high-cost/expensive detections to improve signal-to-noise ratio and manage platform consumption.
Automation
- Design, build, and support automation solutions that improve efficiency, consistency, and time-to-response across security operations.
SOC Support & Collaboration
- Maintain strong SOC partnerships and provide support for SOC inquiries related to the Azure and Microsoft Defender portals, including troubleshooting and operational guidance.
The successful candidate would possess these skills
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte Technology US (DT - US) helps power Deloitte's success, which serves many of the world's largest, most respected organizations. We develop and deploy cutting-edge internal and go-to-market solutions that help Deloitte operate effectively and lead in the market. Our reputation is built on a tradition of delivering with excellence.
The ~3,000 professionals in DT - US deliver services including:
- Cyber Security
- Technology Support
- Technology & Infrastructure
- Applications
- Relationship Management
- Strategy & Communications
- Project Management
- Financials
Cyber Security
Cyber Security vigilantly protects Deloitte and client data. The team leads a strategic cyber risk program that adapts to a rapidly changing threat landscape, changes in business strategies, risks, and vulnerabilities. Using situational awareness, threat intelligence, and building a security culture across the organization, the team helps to protect the Deloitte brand.
Areas of focus include:
- Risk & Compliance
- Identity & Access Management
- Data Protection
- Cyber Design
- Threat Detection
- Incident Response
- Security Architecture
- Business Partnership
Qualifications
Required:
- Bachelor's degree or equivalent in Computer Science, Computer Engineering, Business Administration.
- Minimum 8 years of various technology experience.
- Minimum 3 years' cyber security experience within SIEM Administration.
- Hands-on experience with Microsoft Sentinel, including building and tuning analytics rules, hunting queries, workbooks, automation, and managing the SIEM data model and workspace.
- Strong KQL proficiency for threat hunting, detection logic, investigation, and telemetry analysis.
Preferred:
- MS Sentinel SC-200 badge
- SOAR and automation experience, especially with Azure Logic Apps, playbooks, and integrations with ITSM or third-party APIs.
- Cloud Fundamental Certificates.
- Ability to communicate network security issues to peers and lower management.
- Hands-on experience with Linux, working knowledge of multiple Cloud environments, Azure O365, and SOC processes.
- An understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity and possible abnormal activities, such as worms, Trojans, viruses, etc.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $97,600 to $200,600.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
EA_ExpHire
RITM10703562
Qualifications:Are you passionate about technology and interested in joining a community of collaborative colleagues who respectfully and courageously seek to challenge the status quo? If so, read on to learn more about an exciting opportunity with Deloitte Technology US (DT - US). We are curious and life-long learners focused on technology and innovation.
Recruiting for this role ends on 7/31/2026.
Work you'll do
The position supports the SOC as an escalation point identifying and addressing potential SIEM content/level I and II engineering security concerns as this role is the first line of operational support. This role is also responsible for supporting Security application patching, content creation as requested from all stake holders, and development of process documentation.
Responsibilities by category:
Administrative
- Maintain ticket management and DevOps activity tracking to ensure accurate work intake, prioritization, and status reporting.
- Monitor and communicate Microsoft product updates; assess and advise on impacts on the environment and customers.
- Build strong stakeholder relationships and provide timely end-user support with clear follow-through and resolution documentation.
- Create and maintain process documentation (runbooks, SOPs, workflows) to support consistent execution and knowledge transfer.
- Maintain and enforce change control and peer review processes to promote quality, security, and auditability.
Threat Detection
- Threat detection development in Microsoft Sentinel and Defender platforms sing KQL.
- Align detection rules to current and emerging threats, leveraging external threat intelligence as appropriate.
- Identify and remediate detection gaps using the MITRE ATT&CK framework, based on business risk and priorities.
- Collaborate with Cybersecurity teams (e.g., Incident Response, Threat Intelligence, Engineering) to ensure cross-team alignment and coverage.
- Develop, tune, and support analytics/detection rules, including performance monitoring and optimization.
- Develop, maintain, and optimize playbooks/notebooks, including operational reliability and performance.
- Develop, maintain, and optimize Logic Apps, including operational reliability and performance.
- Develop, maintain, and optimize workbooks and dashboards to support detection engineering and SOC visibility.
- Support reporting needs tied to threat detection outcomes, metrics, and operational insights.
- Define and document required fields per data source to enable effective detection and investigation.
- Identify and remediate high-cost/expensive detections to improve signal-to-noise ratio and manage platform consumption.
Automation
- Design, build, and support automation solutions that improve efficiency, consistency, and time-to-response across security operations.
SOC Support & Collaboration
- Maintain strong SOC partnerships and provide support for SOC inquiries related to the Azure and Microsoft Defender portals, including troubleshooting and operational guidance.
The successful candidate would possess these skills
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte Technology US (DT - US) helps power Deloitte's success, which serves many of the world's largest, most respected organizations. We develop and deploy cutting-edge internal and go-to-market solutions that help Deloitte operate effectively and lead in the market. Our reputation is built on a tradition of delivering with excellence.
The ~3,000 professionals in DT - US deliver services including:
- Cyber Security
- Technology Support
- Technology & Infrastructure
- Applications
- Relationship Management
- Strategy & Communications
- Project Management
- Financials
Cyber Security
Cyber Security vigilantly protects Deloitte and client data. The team leads a strategic cyber risk program that adapts to a rapidly changing threat landscape, changes in business strategies, risks, and vulnerabilities. Using situational awareness, threat intelligence, and building a security culture across the organization, the team helps to protect the Deloitte brand.
Areas of focus include:
- Risk & Compliance
- Identity & Access Management
- Data Protection
- Cyber Design
- Threat Detection
- Incident Response
- Security Architecture
- Business Partnership
Qualifications
Required:
- Bachelor's degree or equivalent in Computer Science, Computer Engineering, Business Administration.
- Minimum 8 years of various technology experience.
- Minimum 3 years' cyber security experience within SIEM Administration.
- Hands-on experience with Microsoft Sentinel, including building and tuning analytics rules, hunting queries, workbooks, automation, and managing the SIEM data model and workspace.
- Strong KQL proficiency for threat hunting, detection logic, investigation, and telemetry analysis.
Preferred:
- MS Sentinel SC-200 badge
- SOAR and automation experience, especially with Azure Logic Apps, playbooks, and integrations with ITSM or third-party APIs.
- Cloud Fundamental Certificates.
- Ability to communicate network security issues to peers and lower management.
- Hands-on experience with Linux, working knowledge of multiple Cloud environments, Azure O365, and SOC processes.
- An understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity and possible abnormal activities, such as worms, Trojans, viruses, etc.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $97,600 to $200,600.
You may also be eligible to participate in a discretionary annual incentive...