Detection Engineer
Listed on 2026-08-22
-
Software Development
AI Engineer (Applied/Software)
About the Role
We're looking for a Detection Engineer to own the detection content that powers the Artemis platform. You'll design, build, test, and continuously tune high-fidelity detections across cloud, identity, endpoint, and SaaS environments — treating detection as code, and using AI as a force multiplier at every step: authoring rules with AI assistance, and building anomaly detections that learn what's normal in each environment and flag what isn't.
Detections at Artemis don't just fire alerts; they feed an AI-native investigation pipeline, so precision, rich context, and machine-readable output matter as much as coverage. This is a hands‑on engineering role where every rule you ship directly determines what threats we catch for customers and how fast we catch them.
- Build and maintain the detection library - Design, implement, and own high‑fidelity detections across cloud (AWS, Azure, GCP), identity (Okta, Entra ), endpoint (EDR), and SaaS log sources, from hypothesis to production.
- Practice detection-as-code - Manage detection content like software: version‑controlled rules, peer review, automated validation and testing, and CI/CD deployment across customer environments.
- Map and close coverage gaps - Measure detection coverage against MITRE ATT&CK, prioritize gaps based on real‑world threat activity, and systematically close them.
- Validate against real attacks - Build and run attack simulations and test harnesses to prove detections fire on true positives and stay quiet on benign activity, before and after they ship.
- Tune relentlessly - Own false‑positive and false‑negative rates across the fleet: analyze detection performance data, tune noisy logic at the source, and sunset detections that no longer earn their keep.
- Use AI to write detections at scale - Leverage AI throughout the detection lifecycle: use AI‑assisted workflows to author, convert, test, and document rules faster than any traditional team could, and build the tooling that makes AI‑generated detection content trustworthy enough to ship.
- Build behavioral and anomaly‑based detections - Go beyond static signatures: establish behavioral baselines of normal activity per environment (identity, cloud, SaaS usage patterns) and engineer anomaly detections that surface deviations — impossible travel, unusual privilege use, novel API activity — with high signal and low noise.
- Engineer detections for AI‑powered investigation - Design detections that produce rich, structured context so the Artemis platform can investigate and resolve cases autonomously.
- Turn intelligence into detections - Translate threat intelligence, incident findings, and threat hunt results from our research and SOC teams into durable, behavioral detection logic.
- Partner with the SOC and research teams - Close the loop with Apollo analysts and security researchers: use case outcomes and analyst feedback to drive detection improvements, and give them documentation that makes every alert investigable.
- Support customer‑specific tuning - Adapt and tune detection content to each customer's environment and business context, reducing noise without sacrificing coverage.
- 5+ years of hands‑on cybersecurity experience, with significant time in detection engineering
- Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms
- Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA‑L, and comfort writing code (Python preferred) for automation and testing
- Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry
- Experience with detection‑as‑code workflows:
Git, peer review, automated testing, and CI/CD for detection content - Experience using AI tools to accelerate detection authoring, tuning, or validation — and judgment about when AI‑generated logic is ready to ship
- Experience building behavioral or anomaly‑based detections: establishing baselines of normal activity and engineering detections that flag meaningful deviations
- Strong log‑analysis skills and demonstrated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).