Security Spec Lead
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Security Management & Operations
Job Summary
We are seeking a highly motivated Detection Engineer to join our Cybersecurity Intelligence and Defense team. The Detection Engineer will be responsible for designing, developing, tuning, and maintaining threat detection capabilities across enterprise environments. This role works closely with Threat Intelligence Analysts, Threat Hunters, Incident Responders, and Security Operations Center (SOC) personnel to identify emerging threats and improve the organization’s ability to detect malicious activity.
Job DescriptionThe ideal candidate possesses a strong understanding of adversary tactics, techniques, and procedures (TTPs), security monitoring technologies, and data analysis. This individual will play a critical role in advancing detection coverage, reducing false positives, and improving overall cyber resilience.
What you’ll do:Essential Job Functions & Tasks
Design, develop, test, and deploy security detections across SIEM, EDR, NDR, cloud, and other security platforms.
Translate threat intelligence and threat hunting findings into actionable detection content.
Create and maintain detection rules, correlation searches, behavioral analytics, and alerting mechanisms.
Tune existing detections to improve fidelity and reduce alert fatigue.
Map detections to the MITRE ATT&CK framework and identify coverage gaps.
Collaborate with Threat Hunting and Incident Response teams to improve detection effectiveness.
Develop use cases and detection strategies for emerging threats and adversary behaviors.
Analyze security telemetry from endpoints, networks, cloud environments, and identity providers.
Measure and report on detection performance, effectiveness, and coverage.
Support purple team exercises, tabletop exercises, and adversary emulation activities.
Maintain documentation, detection standards, and engineering processes.
Automate detection engineering workflows where appropriate.
Licenses and
Certifications:
CSFA, GCCC, GCDA, GCED, GCFA, GCFE, GCIA, GCIH, GCIP, GCTI, GDAT, GICSP, GMON, GOSI, GREM, GRID, GSOM, GXPN, OSCP, OSEE, Tread stone Certified Threat Intelligence Analyst/Certified Threat Counterintelligence Analyst, CERT Incident Response Process Professional, CREST Certified Host Intrusion Analyst, CREST Certified Incident manager, CREST Certified malware Reverse Engineer, CREST Certified Network Intrusion Analyst, CREST Certified Threat Intelligence Manager
Experience:Detection Engineer
Incident Response Analyst
CIRC/SOC Lead
Threat Intelligence or Counterintelligence Analyst
Cyber Threat Hunt Analyst
Malware Reverse Engineer
Clearance:
Current government security clearance or ability to obtain a security clearance at a minimum of the Secret level.
Education requirements are listed below:
Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) or NERC CIP compliance; OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cyber Security Program; alternatively,may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment).
7 or more years of Information Technology related experience; OR 5 or more years of security related experience, which may include military/government work experience in addition to any experience identified above; OR NERC-CIP compliance in addition to any experience identified above.
At AEP, we’re more than just an energy company — we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you're passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you!
Compensation$ - $
Physical DemandsThe Physical Demand Level for this job is: S – Sedentary Work:
Exerting up to 10 pounds of force occasionally…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).