1

Senior Detection Engineer Jobs (NOW HIRING)

Sr. Detection Engineer

Chicago, IL ยท On-site

$107K - $147K/yr

The Senior Detection Engineer is a hands-on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role ...

About the Role The senior detection engineer is part of the larger detection engineering team that creates, tunes, maintains, and improves the detection lifecycle. This hands-on role is at the ...

Senior Detection Engineer #3279

San Antonio, TX ยท On-site

$94K - $129K/yr

Senior Detection Engineer Contract Length: 12+ months Location: Austin or San Antonio, Texas (Hybrid) Behind every clean dashboard and every quiet shift is an engineer who built the system that made ...

Senior Detection Engineer

Ashburn, VA ยท On-site

$106K - $146K/yr

Detection Engineering: Design, build, and optimize advanced security detections within the Splunk platform. You will move beyond basic alerts to create high-fidelity, risk-based alerting (RBA) models ...

Sr. Detection Engineer

Scottsdale, AZ ยท On-site

$132 - $165/hr

Overall Purpose The Detection Engineer is part of a highโ€‘performance team, responsible for creating detections, investigating and evaluating threats and malware for a variety of digital devices ...

Senior Detection Engineer

Manhattan, NY ยท On-site

$120 - $180/hr

Own the detection engineering program end to end: threat modeling, detection design, deployment, tuning, and retirement, with coverage mapped to MITRE ATT&CK and gaps documented rather than assumed ...

$168 - $311/hr

## Senior Security Engineer, Detection EngineeringApplylocations: US, CA, Remote: US, TX, Remote: US, NY, Remotetime type: Full timeposted on: Posted Todayjob requisition id: JR2022836NVIDIA Security is ...

Detection Engineer The Opportunity: Are you ready to take an active role in cyber defense for a ... senior leaders and varied audiences, performing technical risk assessments, interpreting ...

next page

Showing results 1-20

Senior Detection Engineer information

See salary details

$59.5K

$126.6K

$183.5K

How much do senior detection engineer jobs pay per year?

As of Aug 25, 2026, the average yearly pay for senior detection engineer in the United States is $126,557.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,500.00 and $143,500.00 per year, depending on experience, location, and employer.

What is a senior detection engineer?

A Senior Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining systems that detect threats and malicious activities within an organization's network. They create and refine detection rules, analyze security alerts, and work closely with incident response teams to mitigate risks. Senior Detection Engineers also lead efforts to improve detection capabilities by researching new attack techniques and developing advanced monitoring solutions. Their expertise helps organizations proactively defend against evolving cyber threats.

What are some common challenges a senior detection engineer faces when developing and tuning detection rules?

A Senior Detection Engineer often encounters challenges such as balancing detection accuracy with false positive rates, staying ahead of evolving threat landscapes, and ensuring detection rules adapt to new attack techniques. They must also collaborate closely with other security teams to understand operational impacts and validate the effectiveness of their rules in real-world scenarios. Regular communication, continuous learning, and iterative testing are crucial to overcoming these challenges and maintaining a robust security posture.

What are the key skills and qualifications needed to thrive as a senior detection engineer, and why are they important?

To excel as a Senior Detection Engineer, you need advanced knowledge of cybersecurity principles, threat detection methodologies, and experience with incident response, often supported by a degree in computer science or related certifications like CISSP or GIAC. Proficiency in SIEM platforms (such as Splunk or Sentinel), scripting languages (like Python), and EDR/XDR tools is typically required. Strong analytical thinking, problem-solving skills, and effective communication help you collaborate with teams and respond to evolving threats. These capabilities are crucial for proactively identifying and mitigating security risks to protect organizational assets.

What is the difference between Senior Detection Engineer vs Security Analyst?

AspectSenior Detection EngineerSecurity Analyst
Required CredentialsBachelor's in CS, Cybersecurity, or related; certifications like CISSP, GIACBachelor's in CS, Cybersecurity, or related; certifications like CompTIA Security+
Work EnvironmentDevelops detection tools, analyzes security data, creates detection rulesMonitors security alerts, investigates incidents, reports findings
Employer & Industry UsageTech companies, financial institutions, cybersecurity firmsIT departments, government agencies, large enterprises

While both roles focus on security, Senior Detection Engineers primarily develop and refine detection systems, whereas Security Analysts monitor and respond to security incidents. The Senior Detection Engineer role is more technical and development-oriented, while Security Analysts focus on incident response and analysis.

How much do detection engineers make?

Detection engineers typically earn a median salary ranging from $90,000 to $130,000 annually, depending on experience, location, and certifications. Senior detection engineers with specialized skills in cybersecurity tools and threat detection may earn higher salaries, often exceeding $150,000.
More about Senior Detection Engineer jobs

What cities are hiring for Senior Detection Engineer jobs?

Cities with the most Senior Detection Engineer job openings:

What are the most commonly searched types of Detection Engineer jobs?

The most popular types of Detection Engineer jobs are:

What states have the most Senior Detection Engineer jobs?

States with the most job openings for Senior Detection Engineer jobs include:

Infographic showing various Senior Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $126,557 per year, or $60.8 per hour.

Sr. Detection Engineer

Chicago, IL โ€ข On-site

Cboe Global Markets
Finance and Insuranceย โ€ขย 501 - 1,000 employees

$107K - $147K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 6 days ago


Job description

Job Description:

At Cboe, we inspire our people to solve complex challenges together because what we do matters. We providethe financialinfrastructure that powers the global economy.As a leading provider of market infrastructure and tradable products, Cboe deliverscutting-edgetrading, clearing and investment solutions to market participants around the world.

We'rebuilding inclusive ways to support professional and personal developmentwhile strengthening the trustwe'veearned as a global market leader.Our teams are empowered to share ideas, actively pursuethemand bring on a challenge.As champions of internal mobility and access toopportunity, we encourage ourpeopleto "go for it" and equip our managers with the training to coach their teams to the next level.Our Associate Resource Groupschampion diversity,equityand inclusion,givingassociates a safe space to network, share ideas and create opportunities.

Soundliketheplace for you? Join us!

The Security Operations team is hiring a Senior Detection Engineer.

The Senior Detection Engineer is a hands-on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role authors the rules, then executes the techniques those rules are meant to catch, building the tooling, sandboxes, and reusable test contentrequiredtodemonstratecoverage rather than assume it. A detection is not finished when it is written. It is finished when someone has run the attack against it, confirmed it fired, confirmed it stayed quiet on benign activity, and left behind a test case that will re-confirm both after the next platform change.

The work spans endpoint, identity, cloud, SaaS, network, andapplicationtelemetry. The role requires fluency in attacker tradecraft at a mechanical level: how a techniqueactually executes, what artifacts it produces, and which of those artifacts are reliable enough to build durable detection logic on. This position partners closely with Threat Hunting, Incident Response, and Security Engineering to ensure detection coverage is measured continuously rather than assumed.

To set expectations clearly, this is a detection authoring and validation role, not a data pipeline role. Log source onboarding, parser development, and ingestion engineering are owned elsewhere. You will need to understand our telemetry well enough to know what is and is not detectable with it, and you will be expected to raise gaps when the data cannot support a detection, but building the pipes is not the job.

In this roleyou'llbe responsible for:

  • Writing, tuning, and maintaining production detection logic across SIEM, EDR, identity, and cloud platforms, with explicit attention to fidelity and false positive cost

  • Validating every detection by executing the technique it targets, so that no rule reaches production unproven

  • Building andmaintaininginternal tooling that simulates adversary behavior on demand, making detection testing repeatable rather than manual

  • Building reusable validation packages and automated regression testing so coverage is re-verified continuously and after every agent, platform, or configuration change

  • Building and operating sandbox and detonation infrastructure, including disposable, instrumented environments for exploit triage, malware analysis, and safe technique development

  • Evaluating newly published proof-of-concept exploit code todeterminewhether it functions, what telemetry it generates, and whether Cboe is exposed, then converting the answer into detection or hunting content

  • Producing threat hunting validation content, including seeded artifacts, known-truth datasets, and repeatable test cases thatestablishwhether a hypothesis is testable with the data we hold

  • Automating the repeatable work: scheduled technique execution, telemetry collection, coverage reporting, and detection performance measurement

  • Applying AI and LLM tooling where it measurably shortens cycle time, including agentic workflows for triage and enrichment, automated analysis of exploit and malware code, detection and test-case drafting, and hunt hypothesis generation

  • Conducting security testing of internally built web applications and APIs, and translating findings into detection requirements as well as remediation guidance

  • Supporting Incident Response during complex investigations with concrete attacker tradecraft insight, and closing the loop by building detections for what the investigation surfaces

  • Documenting and handing off work so that tooling, environments, and test content can beoperatedby others independently

The ideal candidate has:

  • 5+ years of hands-on security engineering experience with substantial detection authoring content, and the ability to speak concretely about detections you built, how youvalidatedthem, and how they performed in production

  • Strong command of at least one detection query language (KQL, Sigma, YARA-L, or equivalent) and the judgment to recognize when logic is too brittle or too broad to ship

  • Practical knowledge of attacker techniques across Windows and Active Directory, Entra ID, cloud platforms (AWS, Azure), SaaS, and containerized workloads, at the level of execution mechanics rather than technique names

  • The ability to read unfamiliar exploit or malware code andidentifythe observable artifacts worth detecting on

  • Real fluency in at least one language used to write tooling (Python, Go, C#, PowerShell, bash, or equivalent

  • Working knowledge of the telemetry itself, including Windows event logs, EDR process and network events, cloud audit logs, and identity sign-in data, and where each is unreliable, incomplete, or trivially evaded

  • Comfort building and tearing down test infrastructure using virtualization, containers, infrastructure-as-code, and CI/CD

  • A disciplined approach to false positives, alert quality, and the operational burden that detections place on analysts

  • Clear technical writing aimed at engineers, including detection documentation and analyst-facing response guidance

  • High ethical standards anddemonstrateddiscipline around authorization, scope, blast radius, and handling of sensitive data

  • Bachelor's degree or equivalent practical experience

You'llreally stand out with:

  • Public detection content, tooling, or research that we can review

  • Hands-on experience with atomic testing frameworks or continuous control validation at scale

  • Use of MITRE ATT&CK as a coverage and gap-analysis instrument rather than a reporting label

  • Concrete AI engineering experience, such as agentic workflows,tooland MCP integration, or testing LLM-application abuse cases including promptinjection

  • Reverse engineering, Windows internals, or EDR telemetry and evasion research

  • Experienceoperatingin regulated or large enterprise environments, especially financial services

  • A track recordof mentoring engineers or building internal training material

  • Curiosity, adaptability, and a continuous improvement mindset

Benefits and Perks

We value the total wellbeing of our people - including health, financial,personaland social wellness. We believe standard benefits like health insurance and fair pay are givenatany organization. Still, you shouldknowwe offer:

  • Fair and competitive salary and incentive compensation packages with an upside for overachievement

  • Generous paid time off, including vacation, personal days, sickdaysand annual community service days

  • Flexible, hybrid work environment

  • Health, dental and vision benefits, including access to telemedicine and mental health services

  • 2:1 401(k) match, up to 8% matchimmediatelyupon hire

  • Discounted Employee Stock Purchase Plan

  • Tax Savings Accounts for health,dependentand transportation

  • Employee referral bonus program

  • Volunteer opportunities to help you give back to your communities

Some of our associates' favorite benefits andperksinclude:

  • Complimentary lunch,snacksand coffee in any Cboe office

  • Paid Tuitionassistanceand education opportunities

  • Generous charitable giving company match

  • Paid parental leave and fertility benefits

  • On-site gyms and discounts to other fitness centers

More About Cboe

We'rereimagining the future of the workplace by focusing on what matters most, our people.Our journey is an inclusive one.We'reinvesting deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We celebrate the diversity in our communities, inside and out, and welcome new perspectives with equity,inclusionand belonging.

We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion.We'rean engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.

Learn more about life at Cboe onour websiteandLinkedIn.

Equal Employment Opportunity

We'reproud to be an equal opportunity employer - and celebrate our associates' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status

#LI-CP1


This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.

Salary Ranges (applicable for US locations only)

At Cboe, we are committed to providing a competitive, transparent, and marketinformed total rewards program. The anticipated base salary range for this role is $130,900-$169,400, with actual compensation determined by jobrelated factors such as skills, relevant experience, education, internal alignment, and location.

This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs.

Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.


Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.