The Role GreyNoise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused ...
The Role GreyNoise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused ...
Senior Detection Engineer
OR · Remote
$104K - $143K/yr
Overview Instacarts Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North ...
Senior Detection Engineer
OR · Remote
$104K - $143K/yr
Overview Instacarts Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North ...
Detection Engineer (Remote)
OR · Remote
This role will include both proactive and reactive aspects of detection engineering. The primary responsibility of this role will be to analyze adversary intrusions and take tactical steps to ensure ...
Detection Engineer (Remote)
OR · Remote
This role will include both proactive and reactive aspects of detection engineering. The primary responsibility of this role will be to analyze adversary intrusions and take tactical steps to ensure ...
SIEM Infrastructure and Detection Engineer
Portland, OR · On-site +1
$151K/yr
The SIEM Infrastructure and Detection Engineer supports a federal energy sector cybersecurity program by engineering, maintaining, and optimizing the SIEM infrastructure and security monitoring ...
SIEM Infrastructure and Detection Engineer
Portland, OR · On-site +1
$151K/yr
The SIEM Infrastructure and Detection Engineer supports a federal energy sector cybersecurity program by engineering, maintaining, and optimizing the SIEM infrastructure and security monitoring ...
OR · On-site
$260K - $459K/yr
The Role We are looking for a detection engineer to help mature and expand our detection frameworks, platforms, and portfolio. The focus of our team is to create and continually improve detections ...
OR · On-site
$260K - $459K/yr
The Role We are looking for a detection engineer to help mature and expand our detection frameworks, platforms, and portfolio. The focus of our team is to create and continually improve detections ...
Detection and response is a critical capability for Liftoff. * Security-conscious engineering culture. Liftoff's engineering org is a willing and capable partner on security work. * Hands-on ...
What You Will Do As our Senior Security Engineer - Detection and Response, you will be working alongside an existing team of experienced security engineers and partnering closely with technologists ...
What You Will Do As our Senior Security Engineer - Detection and Response, you will be working alongside an existing team of experienced security engineers and partnering closely with technologists ...
OR · On-site
$114K - $156K/yr
The team works across enterprise security, security operations, and detection security engineering to strengthen Upstart's security posture through scalable controls, effective monitoring and ...
Sr. Engineer- Product Abuse (Remote)
OR · Remote
As a Sr. Engineer, you'll lead threat hunting operations, architect detection and prevention capabilities, and drive security enhancements across our product portfolio. You'll operate at both ...
Sr. Engineer- Product Abuse (Remote)
OR · Remote
As a Sr. Engineer, you'll lead threat hunting operations, architect detection and prevention capabilities, and drive security enhancements across our product portfolio. You'll operate at both ...
OR · On-site
As a Security Engineer focused on Incident Response, you will: * Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
OR · On-site
As a Security Engineer focused on Incident Response, you will: * Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
Own features from "we need to detect X" through production, across extension, backend, and pipeline code * Write content scripts that interact with web pages and background scripts that coordinate ...
Own features from "we need to detect X" through production, across extension, backend, and pipeline code * Write content scripts that interact with web pages and background scripts that coordinate ...
SOC Threat Hunter
Portland, OR · On-site
Partner with SOC analysts, Splunk engineers, security engineers, and threat intelligence analysts to improve detection fidelity and coverage * Support development of repeatable hunt playbooks ...
SOC Threat Hunter
Portland, OR · On-site
Partner with SOC analysts, Splunk engineers, security engineers, and threat intelligence analysts to improve detection fidelity and coverage * Support development of repeatable hunt playbooks ...
OR · On-site
This role focuses on engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services. It includes building and ...
Cyber Security Manager: Incident Detection and Response
OR · On-site +1
$110K - $149K/yr
Lead, mentor, and develop a blended IDR team (IR, SOC operations, threat detection, and security tooling engineers) * Lead cyber incident investigations across the environment and oversee root cause ...
Cyber Security Manager: Incident Detection and Response
OR · On-site +1
$110K - $149K/yr
Lead, mentor, and develop a blended IDR team (IR, SOC operations, threat detection, and security tooling engineers) * Lead cyber incident investigations across the environment and oversee root cause ...
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field of perimeter intrusion detection systems (PIDS), design and integration. We are seeking a Systems Engineer to support design ...
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field of perimeter intrusion detection systems (PIDS), design and integration. We are seeking a Systems Engineer to support design ...
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field ofperimeterintrusion detection systems (PIDS),designand integration.We are seeking a Systems Engineer to support design ...
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field ofperimeterintrusion detection systems (PIDS),designand integration.We are seeking a Systems Engineer to support design ...
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field ofperimeterintrusion detection systems (PIDS),designand integration.We are seeking a Systems Engineer to support design ...
Quick apply
Systems Engineer
Wilsonville, OR · On-site
As an experienced Systems Engineer, you will be an expert in the field ofperimeterintrusion detection systems (PIDS),designand integration.We are seeking a Systems Engineer to support design ...
Staff Security Engineer (Blue Team)
OR · Remote
Technically lead a team of security engineers and analysts who hunt, detect, and respond to internal and external threats. * Collaborate with customers and partners to strengthen their security ...
Staff Security Engineer (Blue Team)
OR · Remote
Technically lead a team of security engineers and analysts who hunt, detect, and respond to internal and external threats. * Collaborate with customers and partners to strengthen their security ...
The Threat Detection and Response team (TDR) at Airbnb is focused on automating security detection ... We are seeking an Engineering Manager to lead our Investigations & Incident Response team within a ...
The Threat Detection and Response team (TDR) at Airbnb is focused on automating security detection ... We are seeking an Engineering Manager to lead our Investigations & Incident Response team within a ...
Detection Engineer information
See Oregon salary details
$11K - $27.4K
0% of jobs
$27.4K - $43.9K
0% of jobs
$43.9K - $60.3K
0% of jobs
$60.3K - $76.8K
0% of jobs
$76.8K - $93.3K
0% of jobs
$93.3K - $109.7K
0% of jobs
$109.7K - $126.2K
22% of jobs
$139.5K is the 25th percentile. Wages below this are outliers.
$126.2K - $142.6K
4% of jobs
The median wage is $157K / yr.
$142.6K - $159.1K
28% of jobs
$169.8K is the 75th percentile. Wages above this are outliers.
$159.1K - $175.5K
33% of jobs
$175.5K - $192K
13% of jobs
$11K
$156K
$192K
How much do detection engineer jobs pay per year?
What does a Detection Engineer do?
A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.
What kind of projects or tasks does a Detection Engineer typically work on?
As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.
What are the key skills and qualifications needed to thrive in the Detection Engineer position, and why are they important?
To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

Job description
GreyNoise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused on operational execution: building, validating, and maintaining detections at scale.
Responsibilities:Detection and Traffic Tagging Operations- Write and tune Intrusion Detection System rules grounded in observed network behavior.
- Maintain and improve tag coverage and quality: adding new tags, fixing broken ones, and de-duplicating overlaps.
- Maintain benign actor classifications and known-scanner lists so non-malicious traffic is accurately labeled.
- Resolve accumulated detection issues that degrade data quality for users and customers.
- Use internal CLI tooling to lint, test, and deploy detection rules and tags at scale.
- Read and analyze packet captures (pcaps) and related network artifacts during routine validation and debugging.
- Validate detections against real traffic and own the trade-offs between false positives and false negatives for individual rules.
- Triage a steady stream of inbound detection requests, CVEs, and internal coverage questions. The team processes dozens of new items weekly.
- Ensure detections are wired correctly end-to-end: from raw data through rule logic to tag output.
- Flag edge cases, collisions, and unexpected behavior in tags or rules for deeper follow-up.
- Work closely with researchers to keep them focused on longer-horizon projects.
- Communicate clearly about what you are working on, blockers, and trade-offs when priorities shift.
- Help sales, support, and customer success get faster, clearer answers on detection coverage questions.
- The backlog of smaller yet important detection work stops growing and quietly gets handled.
- Tag and detection coverage feels predictable and systematic rather than ad hoc.
- Internal teams get faster, clearer answers on coverage questions.
- The rest of the research team has noticeably more uninterrupted time for complex work and bigger bets.
- You develop reliable instincts for which detection issues matter most and can prioritize without constant direction.
We are flexible on the level. This could be filled by someone in early to mid-career or by a senior practitioner willing to own operational detection work as a primary focus, with a possible path toward deeper research responsibilities over time.
Early-Career or Mid-Level- Comfortable with networking fundamentals and common protocols.
- Can read pcaps today, or is eager to get to "pcaps in your sleep" quickly.
- Understands basic security concepts: CVEs, exploit vs. vulnerability, false positives vs. false negatives.
- Thrives on clear queues of work and shipping lots of small, concrete things.
- Wants broad exposure to real-world internet traffic and detection engineering.
- Strong background in detection engineering, DFIR, SOC operations, or network security.
- Sees operational detection work as the foundation for credible research, not a stepping stone past it. Expect to own this for 6 to 9+ months before the role naturally expands.
- Can turn vague problems into scoped, repeatable workflows.
- Understands that high-leverage impact often comes from unglamorous, highly reliable execution.
- Demonstrated ability to read and analyze packet captures (pcaps).
- Experience writing or maintaining Suricata rules or similar network detection signatures.
- Comfort with high context-switching: moving between tags, rules, pcaps, and internal requests throughout the day.
- Strong attention to detail; small mistakes in tags or rules have outsized downstream effects.
- Clear, concise written communication, especially when something is broken, ambiguous, or blocked.
- Experience with IDS/IPS platforms, Suricata, Zeek, Sigma, Nuclei, or Snort.
- Prior exposure to large-scale internet telemetry, threat intelligence feeds, or SOC operations.
- Honesty
- Put your best understanding of the truth first in all that you do.
- Decency
- Treat yourself and others with respect.
- Opinions
- Frame opinions using data or experience; they are still opinions.
- Computers
- Computers are cool, but that doesn't mean you won't hate them.
About GreyNoise Intelligence
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Washington, DC, US
Year founded
2017