1

Detection Engineer Jobs in Utah (NOW HIRING)

Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ... Security Engineering & Vulnerability Mastery: You possess deep experience in security operations ...

Security Operations Engineer

Lehi, UT · On-site

$120K - $180K/yr

Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ... Security Engineering & Vulnerability Mastery: You possess deep experience in security operations ...

... detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some coding experience required Fluency in English (native or bilingual level) Strong writing and analytical skills A ...

Security Site Reliability Engineer

Pleasant Grove, UT · On-site

$51.50 - $68.25/hr

Support our Wazuh SIEM - maintain and extend cloud log ingestion (CloudTrail, VPC Flow Logs, GCP Audit Logs) and help tune detection rules after initial setup by a detection engineering contractor

next page

Showing results 1-20

Detection Engineer information

See Utah salary details

$9.9K

$141.1K

$173.7K

How much do detection engineer jobs pay per year?

As of Jun 7, 2026, the average yearly pay for detection engineer in Utah is $141,108.00, according to ZipRecruiter salary data. Most workers in this role earn between $129,019.00 and $155,634.00 per year, depending on experience, location, and employer.

What does a Detection Engineer do?

A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.

What kind of projects or tasks does a Detection Engineer typically work on?

As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.

What are the key skills and qualifications needed to thrive in the Detection Engineer position, and why are they important?

To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

What are the most commonly searched types of Detection Engineer jobs in Utah? The most popular types of Detection Engineer jobs in Utah are:
Infographic showing various Detection Engineer job openings in Utah as of May 2026, with employment types broken down into 76% Full Time, 18% Part Time, and 6% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $141,108 per year, or $67.8 per hour.

Senior Security Engineer, Detection Engineering

Everpure

Lehi, UT

$107K - $147K/yr

Other

PTO

Posted 5 days ago


Job description

THE ROLE

You will partner with the security operations lead and broader security team to develop and mature security use cases that apply across the company's environment and operations. Your mission is to build and refine the detections, policies, and response logic that enable the team to identify real attacks, misuse, intrusions, and data loss events with speed and confidence.

This is not a passive monitoring role. You will be expected to understand how the business operates, how attackers move, where meaningful signals live, and how to translate that knowledge into durable security content and response workflows. Success in this role is measured not by alert volume, but by signal quality, attack reduction, faster containment, and continuous operational improvement.

WHAT YOU'LL DO

  • Design, implement, and maintain high-fidelity detections, correlation rules, alerts, dashboards, and use cases in Splunk and related security platforms.
  • Build detections across multiple data domains, including identity, endpoint, network, cloud infrastructure, SaaS applications, DLP, vulnerability, and asset posture.
  • Correlate signals from diverse tooling and data sources to identify attacker behavior, misuse, anomalous activity, and material security risk.
  • Partner with business units, IT, engineering, and internal security stakeholders to map business processes and workloads to security use cases and required telemetry.
  • Support and participate in incident triage, investigation, containment, and post-incident improvement activities.
  • Develop enrichment and automation workflows using Python, APIs, and security tooling to improve analyst efficiency and response consistency.
  • Improve detection quality by tuning noisy alerts, reducing false positives, and increasing true positive rates.
  • Collaborate on logging strategy, event onboarding, normalization, parsing, correlation, retention, reporting, and platform customization.
  • Apply threat intelligence, attacker tradecraft, and frameworks such as MITRE ATT&CK, CVE/CVSS, and risk context to drive meaningful detections.
  • Create playbooks, runbooks, detection documentation, and operational guidance for responders and analysts.
  • Use lessons learned from incidents, hunts, and threat research to continuously improve content, coverage, and response workflows.
  • Help mature a security operations model that brings together detection, alerting, investigation, and response rather than treating them as isolated functions.
  • We are primarily an in-office environment and therefore, you will be expected to work from the Lehi, UT office in compliance with Everpure's policies, unless you are on PTO, or work travel, or other approved leave.

WHAT YOU BRING

  • 6+ years of experience in cybersecurity, or a related technical field
  • 3+ years of hands-on experience in incident response, detection engineering, security operations, or SIEM engineering
  • Strong hands-on experience with a SIEM platform; direct experience with Splunk is strongly preferred
  • Solid understanding of the incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning
  • Strong understanding of foundational networking, systems, cloud, and security principles
  • Ability to write scripts and automate tasks using Python or a similar language
  • Ability to work with APIs, integrate data sources, and automate enrichment or response actions
  • Strong analytical thinking and the ability to translate ambiguous threats or operational gaps into concrete detection logic
  • Excellent written and verbal communication skills, with the ability to collaborate effectively across technical and non-technical teams
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field

#LI-TH3,  #LI-ONSITE