Detection Engineer (Contract)

Remote • Posted 10 hours ago • Updated 10 hours ago
Contract Independent
12 Months
No Travel Required
Remote
$80 - $100/hr
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • KQL
  • Sigma
  • Sentinel Analytics Rules
  • Elastic Detection Rules
  • MITRE ATT&CK Framework
  • Git
  • source control
  • CI/CD pipelines
  • Detection-as-Code methodologies
  • Python
  • PowerShell
  • Windows Event Logs
  • Sysmon
  • Microsoft Entra ID Sign-In
  • Endpoint telemetry
  • Network telemetry
  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform
  • Microsoft Windows
  • Splunk
  • Analytics
  • Artificial Intelligence
  • YAML
  • SPL
  • SIEM
  • Incident Management
  • Dashboard
  • English
  • Windows PowerShell
  • Threat Analysis
  • Performance Metrics
  • Security Operations
  • System On A Chip
  • Testing
  • Snort
  • Workflow
  • Version Control
  • Auditing
  • Cloud Computing
  • Cloud Security
  • Collaboration
  • Communication
  • Continuous Delivery
  • Continuous Integration
  • Design Of Experiments
  • Documentation
  • Emulation
  • Good Clinical Practice
  • Network
  • Normalization

Summary

Detection Engineer (Contract)

Location: United States (Remote)
Employment Type: Contract (Full-Time, 40 hours/week)
Duration: Long-term, supporting multiple client projects
Compensation: $80–$100/hour (DOE). 

About the Role

We are seeking an experienced Detection Engineer to design, develop, and maintain advanced security detections that enable Security Operations Centers (SOC) to identify and respond to modern cyber threats. This is a long-term contract opportunity supporting multiple enterprise security initiatives, where you will work across SIEM, endpoint, cloud, identity, and network technologies to improve detection coverage and reduce organizational risk.

This role is ideal for someone passionate about threat detection engineering, adversary behaviors, and continuously improving security operations through automation and detection-as-code practices.

Responsibilities

  • Design, develop, and maintain detection rules, analytics, alerts, dashboards, and threat hunting queries across SIEM, endpoint, identity, cloud, and network platforms.
  • Author and optimize detections using KQL, Sigma, YAML-based detection rules, and other query languages.
  • Own the full detection lifecycle, including design, peer review, testing, deployment, versioning, tuning, maintenance, and retirement.
  • Implement Detection-as-Code practices using source control, peer reviews, and CI/CD pipelines.
  • Translate threat intelligence, incident response findings, and adversary TTPs into effective and resilient detection logic.
  • Map detections to the MITRE ATT&CK Framework and identify gaps in detection coverage.
  • Continuously tune detections to improve fidelity while reducing false positives.
  • Validate detections through adversary emulation, attack simulations, and threat hunting exercises.
  • Monitor detection health and performance metrics, including alert volume, precision, and coverage.
  • Partner with engineering teams to onboard new log sources, improve telemetry quality, and address data gaps.
  • Develop analyst documentation, including triage guidance, expected false positives, and escalation procedures.
  • Collaborate closely with SOC analysts, incident responders, threat hunters, red teams, and platform engineers.
  • Utilize approved AI tools to accelerate documentation, testing, and automation while maintaining human review of all production content.

Required Qualifications

  • 3+ years of experience in Detection Engineering, Security Operations, Threat Hunting, or Incident Response.
  • Strong experience building and tuning detections within enterprise SIEM platforms.
  • Experience authoring detection content using KQL, Sigma, Sentinel Analytics Rules, Elastic Detection Rules, or other YAML-based detection frameworks.
  • Experience operationalizing threat intelligence into actionable detection content.
  • Strong understanding of the MITRE ATT&CK Framework and adversary tradecraft.
  • Experience with Git, source control, CI/CD pipelines, and Detection-as-Code methodologies.
  • Proficiency with Python or PowerShell for automation and testing.
  • Hands-on experience analyzing:
    • Windows Event Logs
    • Sysmon
    • Microsoft Entra ID Sign-In & Audit Logs
    • Endpoint telemetry
    • Network telemetry
    • Cloud control-plane logs (Azure, AWS, or Google Cloud Platform)
  • Strong understanding of detection evasion techniques and behavioral detection strategies.
  • Excellent troubleshooting, documentation, and communication skills.

Preferred Qualifications

  • Experience with Splunk SPL or additional SIEM query languages.
  • Experience with YARA, Snort, Suricata, or Zeek.
  • Experience with adversary emulation or Breach & Attack Simulation (BAS) tools.
  • Familiarity with normalization schemas such as ASIM, OCSF, or ECS.
  • Experience integrating detections with SOAR platforms and automated response workflows.
  • Experience leveraging AI to improve security operations.
  • Relevant certifications in SIEM, cloud security, incident response, or threat intelligence.

Position Details

  • Location: Must be authorized to work in the United States.
  • Language Requirement: English required.
  • Schedule: Full-time contract (40 hours/week).
  • Duration: Long-term engagement supporting multiple concurrent security projects.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10124178
  • Position Id: 9062741
  • Posted 10 hours ago
Contact the job poster
Spencer Bruns

Spencer Bruns

Recruiter @ Maureen Data Systems Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or New York, New York

Today

Full-time

USD 224,000.00 - 275,000.00 per year

Remote or Irvine, California

Today

Full-time

USD 124,000.00 - 229,400.00 per year

Remote

Today

Full-time

USD 171,000.00 - 180,500.00 per year

Remote

Today

Full-time

USD 164,000.00 - 226,000.00 per year

Search all similar jobs