1

Siem Detection Engineer Jobs (NOW HIRING)

Our team operates detection engineering as code, and we are looking for someone who thrives in a ... Responsibilities · Design and implement detections using a detection-as-code approach across SIEM ...

Utilize tools such as SIEM, EDR, and custom-built solutions to enhance detection accuracy and ... Reverse-engineer malware, analyze malicious artifacts, and provide actionable guidance to mitigate ...

Detection Engineering Lead

$104K - $138K/yr

About the role We're looking for a highly experienced Senior / Principal Detection Engineer to help ... Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and ...

Detection Engineering Lead

$104K - $138K/yr

About the role We're looking for a highly experienced Senior / Principal Detection Engineer to help ... Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and ...

Showing results 21-40

Siem Detection Engineer information

See salary details

$25

$53

$76

How much do siem detection engineer jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for siem detection engineer in the United States is $53.63, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $62.26 per hour, depending on experience, location, and employer.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

More about Siem Detection Engineer jobs

What cities are hiring for Siem Detection Engineer jobs?

Cities with the most Siem Detection Engineer job openings:

What states have the most Siem Detection Engineer jobs?

States with the most job openings for Siem Detection Engineer jobs include:

What job categories do people searching Siem Detection Engineer jobs look for?

The top searched job categories for Siem Detection Engineer jobs are:

Infographic showing various Siem Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $111,552 per year, or $53.6 per hour.

Detection Engineer - REMOTE

Binary Defense

Houston, TX • On-site

Full-time

Medical, Dental, Vision, Retirement

Posted 24 days ago


Job description

Description:


Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You’ll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.


Responsibilities


· Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).

· Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.

· Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs.

· Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.

· Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.

· Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.

· Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.

· Support documentation of detection logic, coverage rationale, and response guidance.

· Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Requirements:

· 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response.

· Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.

· Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.

· Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.

· Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.

· Ability to quickly learn new security technologies and adapt detection strategies accordingly.

· Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.


Preferred


· Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).

· Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).

· Exposure to multi-tenant or MDR environments and scaling detections across customer environments.

· Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.

· Experience in IR consulting and working across diverse EDR/SIEM stacks.


About Binary Defense


Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.


For more information, visit our website, check out our blog, or follow us on LinkedIn.


Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!