1

Siem Detection Engineer Jobs (NOW HIRING)

Detection Engineering Lead

$104K - $138K/yr

About the role We're looking for a highly experienced Senior / Principal Detection Engineer to help ... Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and ...

Detection Engineer, Manager Are you passionate about building and pioneering in the technology ... SIEM, which processes over 20 million events per second across hundreds of custom detection rules ...

New

Detection Engineer, Manager Are you passionate about building and pioneering in the technology ... SIEM, which processes over 20 million events per second across hundreds of custom detection rules ...

New

Detection Engineer, Manager Are you passionate about building and pioneering in the technology ... SIEM, which processes over 20 million events per second across hundreds of custom detection rules ...

New

Detection at DoorDash spans more than the corporate estate. You'll build coverage across cloud ... Mastery of SIEM querying (sql, spl, kql) and programming languages (python, go, etc) * Experience ...

Detection Engineer, Manager Are you passionate about building and pioneering in the technology ... SIEM, which processes over 20 million events per second across hundreds of custom detection rules ...

New

SIEM Engineer LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position ... Understanding of threat detection * Familiarity with security protocols * Ability to develop ...

SIEM Engineer LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position ... Understanding of threat detection * Familiarity with security protocols * Ability to develop ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

Splunk SPL knowledge and SIEM experience or additional SIEM background Following Qualifications ... detection engineering, data engineering, incident response, threat hunting, threat intelligence.

SIEM Engineer LOCATION Annapolis Junction, MD 20701 CLEARANCE TS/SCI Full Poly (Please note this ... Understanding of threat detection * Familiarity with security protocols * Ability to develop ...

SIEM Engineer LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position ... Understanding of threat detection * Familiarity with security protocols * Ability to develop ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

Splunk SPL knowledge and SIEM experience or additional SIEM background Following Qualifications ... detection engineering, data engineering, incident response, threat hunting, threat intelligence.

Showing results 41-60

Siem Detection Engineer information

See salary details

$25

$53

$76

How much do siem detection engineer jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for siem detection engineer in the United States is $53.63, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $62.26 per hour, depending on experience, location, and employer.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

More about Siem Detection Engineer jobs

What cities are hiring for Siem Detection Engineer jobs?

Cities with the most Siem Detection Engineer job openings:

What states have the most Siem Detection Engineer jobs?

States with the most job openings for Siem Detection Engineer jobs include:

What are popular job titles related to Siem Detection Engineer jobs?

For Siem Detection Engineer jobs, the most frequently searched job titles are:

Infographic showing various Siem Detection Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 89% Full Time, 7% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $111,552 per year, or $53.6 per hour.

Detection Engineering Lead

Remote

Dropzone AI
Network Security • 1 - 10 employees

$104K - $138K/yr

Full-time

Medical, Retirement, PTO

Re-posted 17 days ago


Job description

About the role

We're looking for a highly experienced Senior / Principal Detection Engineer to help shape the future of AI-driven security operations. This is a senior-to-principal level role for an individual who combines deep detection engineering expertise with a passion for innovation, customer impact, and advancing the state of security operations.
As the Detection Engineering Lead, you will serve as one of Dropzone AI's foremost experts in adversary tradecraft, threat detection, detection efficacy evaluation, and SIEM content. You will work closely with product management and engineering teams to ensure our AI detection engineer can draft new detection contents and improve existing detection rules as well as the best detection engineer on the planet.

This role is part of the R&D team and you will focus on building the best software that replicates your expert intuitions and techniques. This is not a service or consulting role and you will not be performing hands-on detection engineering service to our customers.

What you'll do

Detection Engineering Leadership
  • Reimagine how having unlimited detection engineering capacity could change Detection and Response teams and how future security practitioners interact with an AI detection engineer
  • Prototype, validate, and continuously improve an AI agent that programmatically generates detection content across diverse security environments.
  • Experiment autonomous agentic loops between detection engineering and other D&R functions such as threat intelligence and threat hunting
Product Development
  • Partner with engineering teams to encode expert detection knowledge into our product.
  • Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and SaaS security platforms.
  • Provide guidance on detection methodologies used by mature SOCs.
  • Establish best practices for detection quality, tuning, testing, and lifecycle management.
  • Influence product roadmap decisions based on customer and operational needs.
Threat Research & Innovation
  • Stay current on emerging threats, attacker techniques, and defensive strategies.
  • Conduct original research into detection opportunities and gaps.
  • Develop novel approaches for AI-assisted threat detection.

Requirements

  • 5+ years of experience in detection engineering.
  • Deep expertise with two or more major SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, Chronicle, Sumo Logic, etc.).
  • Strong understanding of endpoint, cloud, identity, network, and SaaS telemetry.
  • Expertise in MITRE ATT&CK, adversary emulation, and detection coverage analysis.
  • Experience building and tuning high-fidelity detections at scale.
  • Strong understanding of modern attacker tradecraft across Windows, Linux, cloud, identity, and SaaS environments.
  • Excellent communication skills with the ability to engage practitioners, executives, and customers.
  • Early-stage startup mindset. You thrive on ambiguity and move with lightspeed execution
  • Being data-driven is part of your DNA.
Preferred
  • Experience leading detection engineering programs at large complex environments.
  • Expertise with EDR platforms such as CrowdStrike, Microsoft Defender, SentinelOne, or Palo Alto Cortex XDR.
  • Experience with cloud security platforms including AWS, Azure, and GCP.
  • Familiarity with AI, machine learning, LLMs, or autonomous security workflows.
  • Experience contributing to open-source detection content (Sigma, YARA, Suricata, Zeek, etc.).
  • Public speaking, research publication, or conference presentation experience.

Work Environment/Travel

We are a 100% remote company where you will work from your home with company-provided equipment to set you up for success. Semi-frequent travel to professional office settings and other events locally and nationally; some overnight travel expected.

Compensation

In the spirit of pay transparency, we are excited to share the base salary range below, exclusive of fringe benefits or potential bonuses. If you are hired at Dropzone your final base salary compensation will be determined based on factors such as geographic location, skills, education, and/or experience. In addition, all compensation packages include significant above market new hire equity grants because we believe in rewarding long term value creation. If you are hired at Dropzone your final base salary compensation will be determined based on factors such as geographic location, skills, education, and/or experience. In addition to those factors, we believe in the importance of pay equity and consider internal equity of our current team members as a part of any final offer. Please keep in mind that hiring at the maximum of the range would not be typical to allow for future and continued salary growth. We also offer a generous benefits package, including company paid health insurance, 401K Plan with employer match, Self-Managed PTO, parental leave, and more.