Detection Engineer - REMOTE

Binary Defense

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-5+ years in detection engineering, threat hunting, or incident response.
  • Proficient in Python and REST APIs for EDR/SIEM automation.
  • Experience writing detection logic in Sigma, YARA-L, Splunk SPL, KQL, or XQL.
  • Knowledge of Windows security logs, Sysmon, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK framework and detection mapping.
  • Ability to learn new security technologies quickly.
  • Able to thrive in a fast-paced, threat-driven environment.

Responsibilities

  • Design and implement detections using a detection-as-code methodology across various platforms.
  • Develop detection logic in YAML/Sigma/YARA-L, ensuring documentation and version control.
  • Automate rule deployment and telemetry inspection using APIs, minimizing GUI dependence.
  • Collaborate with other teams to create threat-informed detections based on actual threat scenarios.
  • Identify detection opportunities and gaps through threat modeling efforts.
  • Analyze various telemetry sources to define detection use cases and readiness.
  • Participate in adversary simulations to validate detection efficacy.

Benefits

  • Medical, dental, and vision coverage for employees and dependents.
  • 401k match that vests every payroll.
  • Flexible and remote-friendly work environment.
  • Training opportunities to expand your skill set.
Full Job Description
Job Type

Full-time

Description

Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You'll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.

Responsibilities
• Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
• Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
• Leverage APIs to automate rule deployment, validation, and telemetry inspection-reducing reliance on GUIs.
• Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
• Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
• Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
• Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
• Support documentation of detection logic, coverage rationale, and response guidance.
• Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Requirements
• 2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
• Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
• Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
• Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
• Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
• Ability to quickly learn new security technologies and adapt detection strategies accordingly.
• Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.

Preferred
• Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
• Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
• Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
• Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
• Experience in IR consulting and working across diverse EDR/SIEM stacks.

Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you're interested in joining a growing team with great perks, we encourage you to apply!

Similar Jobs

More Jobs at Binary Defense

More Information Technology Jobs

Find similar Detection Engineer - REMOTE jobs: