Job Type
Full-time
Description
Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You'll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.
Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.
Responsibilities
• Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
• Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
• Leverage APIs to automate rule deployment, validation, and telemetry inspection-reducing reliance on GUIs.
• Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
• Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
• Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
• Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
• Support documentation of detection logic, coverage rationale, and response guidance.
• Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.
Requirements
• 2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
• Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
• Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
• Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
• Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
• Ability to quickly learn new security technologies and adapt detection strategies accordingly.
• Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.
Preferred
• Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
• Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
• Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
• Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
• Experience in IR consulting and working across diverse EDR/SIEM stacks.
Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you're interested in joining a growing team with great perks, we encourage you to apply!