×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Sr. Detection Engineer

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Cboe Exchange
Full Time position
Listed on 2026-10-01
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Job Description:

At Cboe, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world. We’re building inclusive ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader.

Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. Our Associate Resource Groups champion diversity, equity and inclusion, giving associates a safe space to network, share ideas and create opportunities.  

Sound like the place for you? Join us! The Security Operations team is hiring a Senior Detection Engineer. The Senior Detection Engineer is a hands-on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role authors the rules, then executes the techniques those rules are meant to catch, building the tooling, sandboxes, and reusable test content required to demonstrate coverage rather than assume it.

A detection is not finished when it is written. It is finished when someone has run the attack against it, confirmed it fired, confirmed it stayed quiet on benign activity, and left behind a test case that will re-confirm both after the next platform change. The work spans endpoint, identity, cloud, SaaS, network, and application telemetry. The role requires fluency in attacker tradecraft at a mechanical level: how a technique actually executes, what artifacts it produces, and which of those artifacts are reliable enough to build durable detection logic on.

This position partners closely with Threat Hunting, Incident Response, and Security Engineering to ensure detection coverage is measured continuously rather than assumed. To set expectations clearly, this is a detection authoring and validation role, not a data pipeline role. Log source onboarding, parser development, and ingestion engineering are owned elsewhere. You will need to understand our telemetry well enough to know what is and is not detectable with it, and you will be expected to raise gaps when the data cannot support a detection, but building the pipes is not the job.

In this role you’ll be responsible for:
Writing, tuning, and maintaining production detection logic across SIEM, EDR, identity, and cloud platforms, with explicit attention to fidelity and false positive cost Validating every detection by executing the technique it targets, so that no rule reaches production unproven Building and maintaining internal tooling that simulates adversary behavior on demand, making detection testing repeatable rather than manual Building reusable validation packages and automated regression testing so coverage is re-verified continuously and after every agent, platform, or configuration change Building and operating sandbox and detonation infrastructure, including disposable, instrumented environments for exploit triage, malware analysis, and safe technique development Evaluating newly published proof-of-concept exploit code to determine whether it functions, what telemetry it generates, and whether Cboe is exposed, then converting the answer into detection or hunting content Producing threat hunting validation content, including seeded artifacts, known-truth datasets, and repeatable test cases that establish…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary