Senior Detection Engineer
Cary, Wake County, North Carolina, 27518, USA
Listed on 2026-08-13
-
IT/Tech
Cybersecurity, Systems Engineer
When you join Verizon
You want more out of a career. A place to share your ideas freely - even if they're daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love - driving innovation, creativity, and impact in the world.
Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together - lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.
What you'll be doing...
The GN&T Network Security team is looking for a highly motivated and experienced Security Engineer with expertise in security detections, EDR systems and data engineering to join the Network Security Foundational team.
Successful candidates will be able to apply their expertise in the design, and implementation of cutting-edge and mission critical security detections used to detect and mitigate sophisticated threats facing Verizon and our customers. The Network Intelligence infrastructure consists of several large scale compute and storage clusters that are used to analyze petabyte scale network and security event data sets for anomalous and malicious network activity.
As a Security Engineer on our team, you won't just be monitoring dashboards; you will be the architect of our detection strategy and the primary defender of our infrastructure and global network.
In this role, you will be an owner of our Endpoint Detection and Response (EDR) ecosystem and our SIEM visibility. You will be expected to anticipate how an adversary thinks, build the systems to catch them, and lead the technical discussions when high-stakes incidents occur.
Key Responsibilities- Detection Engineering:
Design, build, and optimize advanced security detections within the Splunk platform. You will move beyond basic alerts to create high-fidelity, risk-based alerting (RBA) models that identify complex attack patterns. - EDR Strategy & Management:
Serve as the global SME for our Crowd Strike environment. This includes managing large-scale deployments, tuning prevention policies, and performing deep-dive forensic analysis on endpoint telemetry. - Linux Security Mastery:
You will work primarily on linux-based systems developing detections and investigating EDR-based alerts and detections. - Data Engineering:
Analyze, normalize and utilize data to identify certain security patterns and properties. - Scripting and Coding:
Build small programs and scripts to solve problems and automate tasks to allow the team to move faster and be more efficient.
In this hybrid role, you'll have a defined work location that includes work from home and assigned office days in one of the offices listed for this position, or any other Verizon office.
What we're looking for...
You’ll need to have:- Bachelor's degree in Computer Science, Cybersecurity, or a related field or four or more years of work experience.
- Four or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training.
- Extensive background in overseeing EDR/XDR detections on a large scale.
- Experience managing Linux systems, including deep knowledge of the boot process, PAM, and persistence mechanisms.
- Network Intelligence:
Advanced knowledge of networking protocols (BGP, TLS/SSL, DNS). - Expert knowledge in developing scripts and writing programs (e.g. Python) to automate tasks and solve problems.
- Data Engineering:
Advanced knowledge of database systems, the relational database model and hands-on expertise working with data. - Extensive experience in a dedicated security engineering or incident response role, with a track record of defending enterprise-scale environments.
- Splunk Proficiency:
Expert-level knowledge of Splunk SPL. You should be capable of building custom macros, data models, and automated lookups to streamline investigations. - Attack & Mitigation Knowledge:
You don't just know what a "Golden Ticket" or "Living off the Land" attack is; you know exactly what telemetry is required to block or detect it. - Preferred Tools:
Hands-on experience with Crowd Strike Falcon (including RTR and Fusion) and Splunk ES is highly preferred. - Strong analytical skills and attention to detail with a proven track record of managing and delivering results.
- Leadership experience as a subject matter expert with effective written, interpersonal, and verbal communication skills.
If you believe this job posting is missing information required by the Virginia wage or salary range transparency law, please report it via
Where you'll be workingIn this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).