Detection & Platform Engineer

Compunnel

$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 9+ years of experience in cybersecurity or related fields.
  • Hands-on experience with Detection-as-Code and automated detection pipelines.
  • Strong knowledge of SIEM and SOAR platforms.
  • Experience developing security detections across various telemetry.
  • Proficiency in CI/CD, Git, and automated testing.
  • Strong programming skills in Python or similar languages.
  • Proven ability to troubleshoot and solve complex problems.

Responsibilities

  • Design and maintain Detection-as-Code pipelines.
  • Develop and deploy security detections through CI/CD workflows.
  • Optimize SIEM/SOAR platform performance and reliability.
  • Automate manual SOC processes to improve efficiency.
  • Integrate AI technologies into existing SOC workflows.
  • Document technical procedures and operational guidelines.
  • Collaborate with multiple security teams to enhance detection capabilities.

Benefits

  • Opportunity to work with cutting-edge AI technologies.
  • Exposure to various security platforms and integration techniques.
  • Collaborative environment with cross-functional teams.
  • Enhanced career growth in SOC and security engineering fields.
Full Job Description
Role Summary

We are seeking an experienced Detection & Platform Engineer with hands-on SOC and security engineering experience and a strong software-engineering mindset.

This is not a pure SOC analyst role. The ideal contractor will be comfortable building engineering solutions that improve the scalability and effectiveness of security operations. You will develop and maintain Detection-as-Code pipelines, automate SOC workflows, create and tune security detections, integrate security platforms through APIs, and leverage AI to improve investigation and detection-engineering productivity.

Key Responsibilities

Detection-as-Code Engineering
• Design, build, and maintain Detection-as-Code (DaC) pipelines.
• Develop, test, validate, version, and deploy security detections through automated CI/CD workflows.
• Implement detection development standards, testing frameworks, code review processes, and deployment controls.
• Develop and tune high-fidelity detections across endpoint/EDR, cloud, network, email security, and DLP telemetry.
• Reduce false positives while improving detection coverage and alert fidelity.
• Maintain detection logic, documentation, metadata, ownership, and lifecycle management.
• Collaborate with threat detection and SOC teams to translate threat intelligence and analyst requirements into production detections.

SIEM & SOAR Engineering
• Support administration, engineering, optimization, and reliability of SIEM/SOAR platforms.
• Develop and maintain SIEM queries, correlation rules, dashboards, alerts, and detection content.
• Build SOAR playbooks to automate investigation, enrichment, containment, and response workflows.
• Develop API integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, threat intelligence, and other security platforms.
• Troubleshoot platform integrations, data ingestion, automation failures, and detection deployment issues.

Security Automation
• Identify repetitive SOC processes and develop automation to reduce manual analyst effort.
• Build reusable Python scripts, APIs, workflows, and automation components.
• Integrate security tools and services using REST APIs and webhooks.
• Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
• Improve operational efficiency, response times, and consistency through automation.

AI SOC Engineering
• Support deployment and scaling of AI-driven investigation and triage capabilities.
• Identify opportunities to apply AI/LLMs to alert investigation, enrichment, summarization, detection development, and analyst workflows.
• Integrate AI capabilities with existing SOC platforms and automation workflows.
• Help establish appropriate validation, governance, and controls around AI-generated security outcomes.

Platform Engineering & Operations
• Monitor and optimize the performance, reliability, scalability, and availability of SOC security platforms.
• Troubleshoot production issues and participate in incident resolution.
• Support platform upgrades, integrations, configuration changes, and operational improvements.
• Create technical documentation, runbooks, architecture documentation, and operational procedures.
• Work closely with SOC analysts, threat hunters, detection engineers, threat intelligence teams, infrastructure engineers, and security leadership.

Required Qualifications
• 9+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or a related field.
• Hands-on experience building and maintaining Detection-as-Code or automated detection deployment pipelines.
• Strong understanding of SIEM and SOAR platforms and SOC operational workflows.
• Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
• Experience with CI/CD, Git, version control, automated testing, and deployment pipelines.
• Strong scripting/programming experience with Python or a similar language.
• Experience developing SOAR playbooks, security automation, API integrations, and workflows.
• Strong understanding of security events, logs, telemetry, alerting, detection logic, and incident-response processes.
• Experience working with REST APIs and integrating multiple security platforms.
• Strong troubleshooting and problem-solving skills.
• Ability to work independently in a fast-paced engineering environment.

Preferred Qualifications
• Experience with Sigma, YARA, or other detection/content-as-code frameworks.
• Experience with major SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar.
• Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar.
• Experience with EDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar.
• Experience with cloud security telemetry across AWS, Azure, or GCP.
• Experience with GitHub, GitLab, Azure DevOps, and CI/CD tooling.
• Experience with threat intelligence platforms and automated enrichment.
• Experience with LLMs, GenAI, AI agents, or AI-assisted SOC operations.
• Familiarity with MITRE ATT&CK and threat detection engineering methodologies.
• Experience in large enterprise SOC environments.

Technical Skills
• Detection Engineering: Detection-as-Code, Sigma, YARA, detection logic, correlation rules, threat detection, MITRE ATT&CK.
• SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent.
• SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent.
• Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR platforms.
• Automation & Development: Python, REST APIs, JSON, webhooks, scripting.
• DevOps: Git, GitHub/GitLab, CI/CD, automated testing, infrastructure/deployment pipelines.
• Cloud: AWS, Azure, and/or GCP security telemetry.
• AI: Generative AI, LLMs, AI-assisted investigation, AI agents, automated triage.
• Security Frameworks: MITRE ATT&CK, threat detection lifecycle, incident response.

Soft Skills
• Strong engineering and automation mindset.
• Ability to translate SOC requirements into scalable technical solutions.
• Strong communication and documentation skills.
• Comfortable collaborating with security analysts and engineering teams.
• Ability to troubleshoot complex production environments.
• Strong ownership and ability to work independently.
• Detail-oriented approach to detection quality and operational reliability.

Top 3 Required Skills
• Detection-as-Code + CI/CD Detection Engineering
• SIEM/SOAR Engineering + Security Automation
• Python/API Integrations + SOC Detection Engineering

Similar Jobs

More Jobs at Compunnel

  • IoT Developer
    $120K — $140K *
    Plano, TX 75025 (Collin County)
    Information Technology
    In-Person
  • SW 356 SYSTEMS ADMINISTRATOR
    $80K — $95K *
    Princeton, NJ 08540 (Mercer County)
    Information Technology
    In-Person
  • SIMCORP GAIN Consultant
    $110K — $130K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • PLM Project Manager
    $100K — $120K *
    Beverly Hills, CA 90210 (Los Angeles County)
    Technical Services
    In-Person
  • SW 354 SYSTEMS ANALYST
    $80K — $95K *
    Princeton, NJ 08540 (Mercer County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Detection & Platform Engineer jobs: