1

Detection Engineer Jobs in Portland, OR (NOW HIRING)

Senior Security Engineer, IAM

Portland, OR · On-site

$121K - $166K/yr

This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Detection, Response & Threat Context * Lead integration of identity telemetry into the detection ...

New

Design, develop, and optimize detection engineering capabilities, including SIEM correlation rules, behavioral analytics, and custom detections to improve coverage and reduce false positives. * Drive ...

Partner with SOC analysts, Splunk engineers, security engineers, and threat intelligence analysts to improve detection fidelity and coverage * Support development of repeatable hunt playbooks ...

... engineers, and threat intelligence analysts to improve detection fidelity and coverage • Support development of repeatable hunt playbooks, queries, dashboards, and analytic procedures • Research ...

Senior Cybersecurity Analyst

Portland, OR · On-site +1

$94K - $126K/yr

The Senior Cybersecurity Analyst is the primary technical lead for Metro's security operations, detection engineering, and technical control execution, leading hands-on threat detection, incident ...

The Senior Cybersecurity Analyst is the primary technical lead for Metro's security operations, detection engineering, and technical control execution, leading hands-on threat detection, incident ...

As an experienced Systems Engineer, you will be an expert in the field of perimeter intrusion detection systems (PIDS), design and integration. We are seeking a Systems Engineer to support design ...

As an experienced Systems Engineer, you will be an expert in the field of perimeter intrusion detection systems (PIDS), design and integration. We are seeking a Systems Engineer to support design ...

As an experienced Systems Engineer, you will be an expert in the field ofperimeterintrusion detection systems (PIDS),designand integration.We are seeking a Systems Engineer to support design ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

Senior Security Engineer Department: IT Group Employment Type: Full Time Location: Clackamas ... Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ...

Senior Security Engineer

Portland, OR · On-site

$121K - $166K/yr

Design and tune detection logic, alerts, and monitoring for threats and anomalous activity * Lead ... Partner with DevOps, SRE, and engineering teams to integrate security tooling into CI/CD pipelines

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

Summary: The Senior Security Engineer at Pacific Seafood is a key role in our information ... Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ...

Senior Security Engineer

Clackamas, OR

$120K - $165K/yr

Summary: The Senior Security Engineer at Pacific Seafood is a key role in our information ... Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ...

next page

Showing results 1-20

Detection Engineer information

What does a detection engineer do?

A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.

What are the key skills and qualifications needed to thrive as a detection engineer?

To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

What kind of projects or tasks does a detection engineer typically work on?

As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.

What are popular job titles related to Detection Engineer jobs in Portland, OR?

For Detection Engineer jobs in Portland, OR, the most frequently searched job titles are:

What job categories do people searching Detection Engineer jobs in Portland, OR look for?

The top searched job categories for Detection Engineer jobs in Portland, OR are:

What cities near Portland, OR are hiring for Detection Engineer jobs?

Cities near Portland, OR with the most Detection Engineer job openings:

Infographic showing various Detection Engineer job openings in Portland, OR as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Senior Security Engineer, IAM

Relativity

Portland, OR • On-site

$121K - $166K/yr

Other

Medical, Dental, Vision

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Posting Type

Remote

Job Overview

The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise IAM function and anchors identity as the primary control plane in a defense-in-depth program. This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces Relativity's identity attack surface, sets the standards others build against, mentors engineers, and elevates the organization's ability to detect and respond to identity-based threats.

Job Description and Requirements

Role Responsibilites:

Continuous Adaptive Trust & Identity Architecture

  • Design identity architecture spanning workforce, machine, and workload identity, mapping layered controls to relevant frameworks as a core tier of defense-in-depth.

  • Design and advance continuous adaptive trust capabilities (continuous access evaluation (CAE), risk-based and phishing-resistant authentication, and signal-driven session revocation) as the maturation of the enterprise Zero Trust architecture.

  • Engineer and optimize ZTNA, least-privilege micro-segmentation, MFA/FIDO2, and JIT access across access paths.

  • Design and optimize SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.

  • Define and tune hardening standards using CIS Benchmarks/DISA STIGs with automated compliance validation.

Identity Lifecycle, Governance & PAM

  • Design and optimize identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.

  • Engineer identity governance and administration (IGA) capabilities: access reviews, certification campaigns, and segregation-of-duties enforcement.

  • Lead implementation and optimization of privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.

  • Design governance for non-human identities (service accounts, workloads, secrets) with automated drift detection and policy-as-code enforcement.

Detection, Response & Threat Context

  • Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect credential abuse, privilege escalation, and lateral movement, reducing MTTD and MTTR.

  • Develop identity-focused IR playbooks covering account takeover, credential compromise, federation abuse, and session hijacking.

  • Apply threat intelligence context to prioritize identity exposure remediation and lead identity-focused purple team engagements.

AI DevSecOps & Collaboration

  • Design identity controls embedded in AI-augmented CI/CD pipelines (secret scanning, IaC identity policy, workload identity) with AI-generated fix recommendations surfaced in PR workflows.

  • Define and track identity KPIs: privileged access coverage, certification completion, authentication anomaly rates, and entitlement drift.

  • Partner with GRC on identity controls aligned to SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA, and support audits, certifications, e-discovery, and forensic integrity requirements.

  • Provide technical guidance and mentorship to Advanced and Engineer-level identity engineers.

Minimum qualifications:

  • Bachelor's in Computer Science, Information Security, or equivalent experience.

  • 8+ years of hands-on experience in enterprise IAM or security engineering, with deep specialization in identity, authentication, and access domains, or a Master's degree in Cybersecurity or a relevant field with 6+ years of experience.

  • Expert, hands-on experience architecting and operating identity platforms across IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), and PAM (CyberArk, BeyondTrust), with advanced knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos).

  • Demonstrated experience leading identity threat detection, complex access investigations, and detection-engineering efforts, including designing automation for access enforcement and observability.

  • Working command of industry-standard security benchmarks and frameworks (MITRE, NIST 800-63, Zero Trust) and the ability to translate them into technical controls.

  • Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to containerized services, CLI-based commands, and identity-specific use cases (API-driven provisioning, policy-as-code).

  • Proven ability to mentor engineers and communicate technical strategy and findings clearly to engineering peers, leadership, and non-technical stakeholders.

Preferred qualifications:

  • Experience securing SaaS, cloud-native, or globally distributed regulated environments.

  • Cloud IAM experience across AWS, Azure, or GCP, and securing non-human/workload identities at scale.

  • Experience with AI-augmented security and governance for AI-assisted and agentic identity workflows (UEBA, ML-based access-risk scoring, agentic identity).

  • Experience embedding identity and access controls (secrets management, workload identity, policy-as-code) into CI/CD pipelines and infrastructure-as-code environments.

  • Familiarity with legal technology, e-discovery, litigation holds, and digital forensics chain-of-custody requirements.

  • Experience leading compliance and audit engagements (SOX, SOC 2, ISO 27001, FedRAMP, HIPAA, GDPR, CCPA) from an identity and access control perspective.

  • Certifications such as CISSP, CISM, GCIH, GCFA, CCSP, AWS Security Specialty, SC-300, or AZ-500.

Relativity is a diverse workplace with different skills and life experiences-and we love and celebrate those differences. We believe that employees are happiest when they're empowered to be their full, authentic selves, regardless how you identify.

Benefit Highlights:

Comprehensive health, dental, and vision plans

Parental leave for primary and secondary caregivers

Flexible work arrangements

Two, week-long company breaks per year

Additional time off

Long-term incentive program

Training investment program

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Relativity is committed to competitive, fair, and equitable compensation practices.

This position is eligible for total compensation which includes a competitive base salary, an annual performance bonus, and long-term incentives.

The expected salary range for this role is between following values:

$130000 and $195000

The final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position.

Required Skills:

Access Management, Application Security, Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Information, Security Information and Event Management (SIEM), Security Operations, Vulnerability Management