Senior Security Engineer - Detection Engineering

LinkedIn

$129K — $212K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • BA/BS in CyberSecurity, Information Security, Computer Science, or practical experience.
  • 3+ years in security, detection engineering, or incident response.
  • Experience building detection content for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP).
  • Proficient in programming for detections/automation (e.g., Python) and query languages (KQL/SQL/SPL).
  • Knowledge of detections-as-code principles including CI/CD and rollback processes.
  • Familiarity with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics.
  • Experience with schemas/data models and telemetry pipelines.

Responsibilities

  • Implement and tune detection content across various telemetry platforms; measure efficacy metrics.
  • Develop and maintain detections-as-code with version control and CI/CD processes.
  • Author and translate SIGMA rules to KQL/SQL as necessary.
  • Integrate multi-cloud telemetry across Azure, AWS, and GCP.
  • Operationalize Microsoft Defender XDR and Sentinel signals; utilize Entra ID controls.
  • Conduct proactive threat hunting and create actionable hunt playbooks.
  • Build automation for incident response and integrate with existing workflows.

Benefits

  • Generous health and wellness programs for employees and their families.
  • Time off for employees at all levels to promote work-life balance.
  • Commitment to fair and equitable compensation practices.
Full Job Description
Job Description

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. This role may be remote or hybrid. At LinkedIn, hybrid roles are performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. Remote roles are performed from the designated home work location upon time of hire, and any changes to this home work location requires a review of remote status and approval.

This role can be remote anywhere in the United States or be hybrid in LinkedIn's Mountain View office location.

About the Team

LinkedIn's Information Security organization protects our members, data, and platforms by building resilient security controls, detecting threats early, and partnering across engineering to reduce risk at scale.

The Detection Engineering team is responsible for building and scaling LinkedIn's threat detection capabilities. We partner closely with Incident Response, Threat Intelligence, Red and Purple Teams, Product Security, Identity & Access Management, and Cloud Security to identify, contextualize, and detect adversary activity across the enterprise. Our team develops and maintains high-fidelity detections while advancing the underlying security telemetry ecosystem through log ingestion, schema design, data normalization, automation, threat hunting, incident response support, and audit enablement.

About the Role

As a senior individual contributor, you will design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code practices, telemetry modeling, and data-driven efficacy measurements to continuously improve detection coverage and quality. Working from adversary TTPs and threat hypotheses, you will develop resilient, low-noise detections validated through purple-team exercises, adversary emulation, and real-world incident learnings. This is a hands-on engineering role focused on technical leadership, execution, and cross-functional collaboration.

Responsibilities:
  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry; measure precision/recall, latency, lift, and signal-to-noise ratio.
  • Build detections-as-code with version control, CI/CD, unit/integration tests, staged canary rollouts, and safe rollback.
  • Author and maintain SIGMA rules; translate SIGMA to KQL/SQL as needed.
  • Integrate multi-cloud telemetry: Azure (Activity/Diagnostics), AWS (CloudTrail, GuardDuty), GCP (Cloud Audit Logs, SCC).
  • Operationalize Microsoft Defender XDR and Sentinel signals; leverage Entra ID controls (Conditional Access, sign-in risk).
  • Proactive threat hunting; create hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow; integrate with ticketing/chat ops.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and turn reports into testable hypotheses.
  • Own telemetry quality for assigned pipelines: schemas/normalization (e.g., ASIM/OCSF-like), enrichment, data contracts, reliability SLIs/SLOs.
  • Participate in incident retros; add post-incident detections and suppress noisy patterns.
  • Participate in on-call for critical detection pipelines and high-severity investigations.


Qualifications

Basic Qualifications
  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
  • 3+ years in security, detection engineering or incident response.
  • Experience building detection content and analytics for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP).
  • Experience programming for detections/automation (e.g., Python) and query languages (e.g., KQL/SQL/SPL).
  • Experience with detections-as-code (tests, CI/CD, canary/rollback) at scale.
  • Experience with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics.
  • Experience with schemas/data models (e.g., OSSEM/ASIM-like) and telemetry pipelines.

Preferred Qualifications
  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience.
  • Operating detections over large-scale, multi-region pipelines.
  • Detection testing harnesses, synthetic signal, and adversary emulation at scale.
  • Identity/security signals (Entra ID/Okta/SSO), endpoint internals (Windows/Linux/macOS), SaaS logs.
  • Applied analytics/ML for anomaly detection or risk scoring with robust evaluation.
  • Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection workflows.
  • Hands-on SIGMA authoring/translation; experience with adversary emulation/purple-team validation.
  • Experience with Microsoft Sentinel, Defender XDR, Entra ID; KQL, Python; GitHub Actions/Azure DevOps; Logic Apps; Azure Data Explorer/Kusto
  • Experience with Azure Activity/Diagnostics; AWS CloudTrail/GuardDuty; GCP Cloud Audit Logs/SCC


Suggested Skills:
  • Information Security
  • Detection Engineering
  • Detection as code
  • KQL


You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices.

The pay range for this role is $129,000 to $212,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Additional Information

Similar Jobs

More Jobs at LinkedIn

More Information Technology Jobs

Find similar Senior Security Engineer - Detection Engineering jobs: