1

Senior Threat Detection Engineer Jobs (NOW HIRING)

Tenex is seeking a highly motivated and skilled Threat Detection Engineer to join our growing Security Operations team. In this critical role, you will be responsible for proactively identifying and ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

WV

$94K - $129K/yr

About the role A Senior Threat Engineer builds and improves systems, logic, and workflows that ... Own complex threat detection and workflow problem spaces from investigation concept through ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

Showing results 21-40

Senior Threat Detection Engineer information

See salary details

$59.5K

$126.6K

$183.5K

How much do senior threat detection engineer jobs pay per year?

As of Aug 22, 2026, the average yearly pay for senior threat detection engineer in the United States is $126,557.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,500.00 and $143,500.00 per year, depending on experience, location, and employer.

What does a senior threat detection engineer do?

A Senior Threat Detection Engineer is responsible for designing, implementing, and maintaining systems that identify and respond to cybersecurity threats within an organization's network. They analyze security alerts, develop detection logic, and work closely with incident response teams to mitigate risks. Their role often includes researching emerging threats, improving detection capabilities, and mentoring junior engineers. By proactively identifying potential security breaches, they help safeguard sensitive information and ensure the organization’s cyber resilience.

How does a senior threat detection engineer typically collaborate with other teams to enhance organizational security?

A Senior Threat Detection Engineer works closely with security operations, incident response, IT, and development teams to identify and mitigate threats. This often involves sharing intelligence, developing detection rules, and coordinating responses to security incidents. Regular collaboration ensures that detection strategies align with evolving threats and organizational priorities, fostering a proactive security posture. Effective communication and teamwork are essential, as these engineers often lead efforts to improve detection capabilities and mentor junior staff.

What are the key skills and qualifications needed to thrive as a senior threat detection engineer, and why are they important?

A Senior Threat Detection Engineer requires deep expertise in cybersecurity, threat analysis, and incident response, often backed by a degree in computer science or a related field and industry certifications like CISSP or GIAC. Proficiency with SIEM platforms (such as Splunk or QRadar), EDR solutions, scripting languages, and threat intelligence tools is crucial. Strong analytical thinking, problem-solving abilities, and effective communication skills distinguish top performers in this role. These competencies ensure accurate threat identification, swift mitigation, and robust organizational security in an ever-evolving threat landscape.

What is the difference between Senior Threat Detection Engineer vs Security Analyst?

AspectSenior Threat Detection EngineerSecurity Analyst
CertificationsGICSP, CISSP, GIAC certificationsCompTIA Security+, GIAC certifications
Work EnvironmentAdvanced threat detection, incident response, security architectureMonitoring, analyzing security alerts, reporting
Industry UsageUsed in cybersecurity teams focusing on threat detection and responseUsed across organizations for security monitoring and analysis

While both roles focus on cybersecurity, the Senior Threat Detection Engineer primarily develops and implements advanced detection strategies and handles complex incident responses. The Security Analyst monitors security alerts and performs initial analysis. The Senior Threat Detection Engineer typically requires more technical expertise and experience in threat hunting, whereas Security Analysts focus on alert management and reporting.

More about Senior Threat Detection Engineer jobs

What cities are hiring for Senior Threat Detection Engineer jobs?

Cities with the most Senior Threat Detection Engineer job openings:

What are the most commonly searched types of Threat Detection Engineer jobs?

The most popular types of Threat Detection Engineer jobs are:

What states have the most Senior Threat Detection Engineer jobs?

States with the most job openings for Senior Threat Detection Engineer jobs include:

Infographic showing various Senior Threat Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $126,557 per year, or $60.8 per hour.

Threat Detection Engineer

Legato Security

Salt Lake City, UT • On-site

Full-time

Medical, Dental, Life, PTO

Posted 16 days ago


Job description

Threat Detection Engineer
Who We Are
Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats.
Position Overview
Legato Security is seeking a motivated junior or mid-level Detection Engineer to assist with detection engineering efforts. As a Detection Engineer, you will assist with rule creation, rule tuning, creating documentation, assisting with on-going infrastructure projects, and assisting with customer requests.
Specific Job Responsibilities
  • Create, improve, review, and tune detection rules in various SIEMs (e.g., Sumo Logic, Google SecOps, Stellar Cyber). This will include log reviews of customer environments to make informed decisions.
  • Assist in creating and maintaining documentation for detection procedures, workflows, and active projects.
  • Collaborate with SOC analysts to improve detection accuracy and reduce false positives
  • Help maintain and update detection use cases based on emerging threats and customer-specific logs.
  • Assist in creating regular reports on detection metrics and effectiveness.
  • Review and respond to internal and customer requests to assist with anything related to detection engineering.
  • Contribute to declarative and imperative programming projects to assist with detection as code.

Qualifications
Required Qualifications:
  • Bachelor's degree in Computer Science, Cybersecurity, related field or equivalent industry experience
  • 3-5 years of experience in detection engineering or a related field (e.g., SOC Analyst, Pen Testing, IT Infrastructure, Network Engineering, or Software Development). Job-specific experience in detection engineering is not required
  • Familiarity with networking principals (e.g. routing, common protocols, firewall functionality, etc.)
  • Basic understanding of Windows operating systems (e.g. versions, common exploits, understanding of registries, exposed protocols, common enumeration commands, etc.)
  • Active Directory Fundamentals (e.g. basic understanding of NTLM and Kerberos, how to use LDAP, understanding of common attacks within Active Directory.)
  • Understanding of Detection as Code and common exploits
  • Strong interest in pursuing a career in detection engineering
  • Ability to quickly learn different tool sets and environments
  • Strong written and verbal communication skills
  • Ability to prioritize multiple competing projects, meet deadlines, and work effectively in a team environment

Preferred Qualifications:
  • Applicants who demonstrate personal learning and curiosity through personal projects will be prioritized. e.g. home labs, personal Github projects, write-ups, blog posts, Hack the Box profile, TryHackMe profile.
  • Relevant certifications such as OSCP (Offsec), OSDA (Offsec), CPTS (HTB), CDSA (HTB), etc.

Perks
• Start-up company in a growth phase with opportunity for advancement based on performance
• Start-up culture with an office in downtown Salt Lake City, UT
• Competitive medical and dental benefits for employee and family members
• Other voluntary benefits such as short-term disability, life insurance, children's orthodontia, with additional voluntary benefits available
• Flexible Paid Time Off policy
• Professional Development opportunities specific to role