Charlotte, NC - Hybrid
W2 Only Mid-Level -
5 to 7 Years
Banking / Financial Services MITRE ATT&CK
Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.
? Critical Requirements
- Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience
Role Objectives
- Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness
- Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services
- Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies
- Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond
- Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives
- Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities
- Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content
- Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency
- Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements
- Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks
- Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience
Qualifications & Skills
Cloud & On-Prem Log Analysis
SIEM / UEBA / EDR / SOAR
Detection-as-Code Pipelines
MITRE ATT&CK Framework
Query Languages & Data Analysis
Threat Intelligence Translation
Automation & Scripting
Windows & Linux OS
Behavioral Analytics
Security Telemetry & Correlation
Data Lake & Ingestion Pipelines
Response Playbook Development
? Additional Experience a Plus
- Incident response
- Threat intelligence operations
- Vulnerability management
- Security engineering
- Cloud security
#LI-EW1