Platform Engineer
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Title:
Cyber Security Engineer – Threat Detection
6 months contract
Charlotte, NC 28202
Hybrid role
Experience level: 5 - 7 years
Role Description
Seeking a Cyber Security Engineer – Threat Detection to join a high-performing Security Operations team responsible for advancing the Bank’s security monitoring, detection engineering, and cyber defense capabilities. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to help proactively identify, investigate, and respond to threats before they impact SMBC. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute detection engineering activities with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.
Role Objectives
- Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.
- Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services.
- Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies.
- Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond.
- Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives.
- Map detections and coverage to relevant frameworks, including MITRE ATT&CK, to support measurable improvements in monitoring and response capabilities.
- Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content.
- Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency.
- Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements.
- Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
- Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen SMBC’s cyber resilience.
Qualifications and Skills
- Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience.
- Hands-on experience analyzing logs and security telemetry from multiple sources, including endpoint, network, identity, cloud, infrastructure, and application platforms.
- Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies.
- Strong knowledge of query languages and data analysis techniques used to investigate security events and develop detection logic.
- Experience developing detection-as-code pipelines, automation, scripts, or repeatable processes to improve security operations efficiency.
- Ability to translate threat intelligence, adversary behaviors, and attack techniques into practical detections and monitoring use cases.
- Experience mapping detections to MITRE ATT&CK or similar security frameworks.
- Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments.
- Strong troubleshooting, analytical, and problem-solving skills, with the ability to identify root cause and recommend practical improvements.
- Ability to balance operational responsibilities with project delivery in a fast-paced environment.
- Strong documentation, communication, collaboration, and stakeholder management skills.
- Demonstrated ownership, attention to detail, and ability to work effectively in a global team environment.
- Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).