Sr. Detection Engineer
Listed on 2026-07-13
-
IT/Tech
Cybersecurity
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting‑edge solutions like Zelle, Paze and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment visa sponsorship.
Overall PurposeThe Detection Engineer is part of a high‑performance team, responsible for creating detections, investigating and evaluating threats and malware for a variety of digital devices, computers, storage media, servers, networks, and cloud‑based services. The core responsibility of this position is to create alerts that allow the organization to detect and respond to critical or urgent threats.
Essential Functions- Continuous validation of detections and identification of gaps to ensure comprehensive coverage based on the industry standards (MITRE)
- Solves logging problems by optimization of current logs and onboarding new logs to ensure a logging standard are met
- Impacts the CSIRTS team to be able to respond to threats by creating, tuning and testing high fidelity rules for our SIEM platform
- Actively hunt for APT Tactics, Techniques and Procedures
- Classify/categorize hunting use cases based on MITRE ATT&CK framework and cyber kill chain
- Work with incident detection, incident response, cyber threat intelligence, and other teams to coordinate and create remediation plans
- Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of detecting threats.
- Performs the tracking of malicious threats and groups and their tactics and procedures used
- Performs complex analysis of potentially malicious activities and software
- Performs network/system/application/log intrusion detection analysis and trends
- Maintains awareness of trends in security, regulatory, technology, and operational requirements
- Maintains awareness of the current threat landscape, including adversary tactics, techniques, and procedures.
- Maps attacks to well‑known APT groups and reports to leadership ongoing threats and threat landscape of Early Warning Systems
- Represents the Security team at internal and external cybersecurity forums
- Document and update processes and procedures
- Ensures the company's commitment to protect the integrity and confidentiality of systems and data.
- Education and/or experience typically obtained through completion of a Bachelor’s degree or 4 year degree in Computer Science, Engineering, Math or Physical Science.
- Minimum 8 years of information security technology experience
- Expert, progressive experience with Malware analysis and reverse engineering
- Proven expert experience in creating detections to detect advanced threats in an environment
- Expert knowledge of network monitoring and network exploitation techniques
- Expert experience in responding to malicious threats coming from various sources
- Proven advanced analytical skills across various technologies
- Ability to work within a team environment as well as independently
- Effective communication skills to speak and write for all technology experience levels.
- Effective interpersonal skills, able to comfortably present to peers, coworkers, and customers
- A propensity for continued development of skills though research and training
- Background and drug screen.
- Additional related education, certifications and/or experience is beneficial
- Working experience in cloud technology security
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).