Senior Detection Engineer; AI-ML Focus
Listed on 2026-08-24
-
IT/Tech
Cybersecurity, AI Engineer (Applied/Software)
Senior Detection Engineer
At P&G, we believe that diverse experiences help build strong leaders. Mobility is a key component of many management careers, providing opportunities to grow through different assignments, locations, and business challenges. Candidates should be prepared to consider relocation opportunities throughout their career as business needs and development opportunities arise.
The Senior Detection Engineer plays a vital role in Info Sec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI — using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.
You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands-on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.
Key Success Metrics
- Detection rules you write catch real threats and generate minimal noise
- You measurably improve alert fidelity (TP rate) and reduce SOC case volume
- You operate independently within the detection-as-code workflow (branch → validate → deploy)
- You leverage AI tooling to work faster — not as a research project, but as a daily force multiplier
- Quarterly deliverables reviewed with your manager through continuous mentoring and coaching
- Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk
- Write detection logic across the SIEM and data lake platforms
- Manage detection content as code — Git-based workflows, PR reviews, CI/CD deployment pipelines
- Investigate and suppress false positives systematically using lookup-based architectures
- Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI→TH→DE pipeline)
- Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns
- Leverage AI agents and LLM-assisted workflows to accelerate detection rule development, validation, and coverage analysis
- Use and contribute to MCP (Model Context Protocol) tooling that enables AI-assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps)
- Operate agentic pipelines that triage large rule libraries against live telemetry at scale
- Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets
- Stay current on frontier AI threats (agentic attacks, LLM-assisted exploitation, AI-generated phishing) and translate them into detection opportunities
- Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements
- Collaborate with data engineers on telemetry availability, data quality, and log source onboarding
- Contribute to detection coverage reporting and MITRE ATT&CK posture measurement
- Document detection logic, tuning rationale, and suppression decisions
Job Qualifications
Technical Competencies and
Experience:
Required:
- Bachelor's degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience in detection engineering, security operations, or threat detection roles
- Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real-time alerts)
- Strong understanding of MITRE ATT&CK framework and its application to detection coverage
- Proficiency in Python for automation, scripting, and tooling
- Experience with git-based workflows (branching, PRs, CI/CD) for managing security content
- Familiarity with security log sources: EDR, identity, cloud, network, proxy
- Strong analytical skills and ability to distinguish true threats from noise in large datasets
Preferred:
- Certifications…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).