1

Incident Detection Engineer Jobs (NOW HIRING)

Senior Detection Engineer

$107K - $146K/yr

Detection Engineering: Lead the end-to-end detection lifecycle, including requirement gathering ... Incident Escalation: Act as a Tier 3 technical subject matter expert during high severity security ...

New

You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ... We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed ...

Senior Detection Engineer #3279

San Antonio, TX · On-site

$94K - $129K/yr

Senior Detection Engineer Contract Length: 12+ months Location: Austin or San Antonio, Texas ... Partner with incident responders, providing network-level evidence and context * Document ...

... Detection Engineer contributes to ONEOK's commitment to safe, efficient, 24/7 operations by ... Incident Investigations * Troubleshoots and resolves abnormal operating conditions related to leak ...

Role Scope * Lead detection engineering for Fluidstack's IT surface, including cross-domain ... You do threat research that drives new detections, and you close the loop with incident response ...

Showing results 41-60

Incident Detection Engineer information

See salary details

$31K

$53.5K

$61K

How much do incident detection engineer jobs pay per year?

As of Sep 14, 2026, the average yearly pay for incident detection engineer in the United States is $53,456.00, according to ZipRecruiter salary data. Most workers in this role earn between $59,000.00 and $59,500.00 per year, depending on experience, location, and employer.

What are popular job titles related to Incident Detection Engineer jobs?

For Incident Detection Engineer jobs, the most frequently searched job titles are:

Infographic showing various Incident Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $53,456 per year, or $25.7 per hour.

Senior Threat Hunter / Detection Engineer

Remote

Neshent Technologies
11 - 50 employees

$117K - $160K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Roles & Responsibilities
  • Conduct hypothesis-driven threat hunts across endpoints, identities, networks, and security data sources.
  • Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for threat investigation, hunting, and automated response.
  • Develop advanced Kusto Query Language (KQL) queries for threat hunting and detection.
  • Use Splunk Enterprise Security and SPL to perform complex security investigations, correlation, and threat hunting.
  • Develop and tune high-fidelity detection rules while minimizing false positives.
  • Apply the MITRE ATT&CK framework to threat hunting, detection engineering, and adversary analysis.
  • Translate threat intelligence and attack research into actionable detection and hunting use cases.
  • Investigate security incidents using endpoint forensics, malware analysis, and security analytics.
  • Support containment, eradication, and recovery activities for complex incidents.
  • Develop and maintain incident response playbooks, procedures, and technical documentation.
  • Preserve forensic evidence and follow appropriate evidence-handling and chain-of-custody practices.
  • Analyze Windows systems, processes, authentication activity, network traffic, and common attack vectors.
  • Develop scripts and automation using PowerShell, Python, or similar technologies.
  • Collaborate with incident response, detection engineering, IT operations, and other security teams.
  • Provide technical training, mentoring, and knowledge transfer to security teams.
  • Develop training materials and explain complex security concepts to audiences with varying technical skill levels.
  • Identify opportunities to improve security tools, processes, detections, and threat-hunting capabilities.
  • Support security tool implementations, migrations, and optimization initiatives.
Required Skills
  • 5–7+ years of cybersecurity experience with a focus on threat hunting, detection engineering, and/or incident response.
  • At least 2 years of hands-on enterprise experience with Microsoft Defender for Endpoint (MDE).
  • Strong experience with Microsoft 365 Defender/XDR and MDE investigation capabilities.
  • Advanced KQL skills for threat hunting and detection development.
  • Expert-level experience with Splunk Enterprise Security and strong SPL skills.
  • Experience with Splunk UBA or similar behavioral analytics platforms.
  • Strong knowledge of MITRE ATT&CK, adversary TTPs, and threat intelligence.
  • Demonstrated experience conducting threat hunts that resulted in actionable security improvements.
  • Hands-on experience with incident response, endpoint forensics, and malware analysis.
  • Strong understanding of Windows internals, Active Directory, Azure AD, Kerberos, and NTLM.
  • Knowledge of network protocols, traffic analysis, and common attack techniques.
  • Experience with scripting or automation using PowerShell, Python, or similar languages.
  • Strong analytical, problem-solving, documentation, and communication skills.
  • Ability to work independently and collaborate effectively with distributed, cross-functional teams.
Preferred Skills
  • Experience supporting or leading security tool migrations or implementations.
  • Experience with Splunk UBA, SIEM architecture, data onboarding, and platform optimization.
  • Knowledge of NIST and SANS incident response frameworks.
  • Experience developing incident response playbooks and security procedures.
  • Experience with detection engineering and reducing false positives.
  • Strong technical training, mentoring, and knowledge-transfer experience.
  • Ability to translate threat research into practical defensive controls and security improvements.
  • Experience working in a fully remote and distributed team environment.