Haystack
← Back to Jobs
Technology

Cyber Security Engineer - Threat Detection

Sharp DecisionsNC🇺🇸United StatesPosted 30 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Charlotte, NC - Hybrid
W2 Only Mid-Level -
5 to 7 Years
Banking / Financial Services MITRE ATT&CK

Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.

? Critical Requirements
  • Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience


Role Objectives
  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness
  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services
  • Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies
  • Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond
  • Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives
  • Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities
  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content
  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency
  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements
  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks
  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience


Qualifications & Skills

Cloud & On-Prem Log Analysis

SIEM / UEBA / EDR / SOAR

Detection-as-Code Pipelines

MITRE ATT&CK Framework

Query Languages & Data Analysis

Threat Intelligence Translation

Automation & Scripting

Windows & Linux OS

Behavioral Analytics

Security Telemetry & Correlation

Data Lake & Ingestion Pipelines

Response Playbook Development

? Additional Experience a Plus
  • Incident response
  • Threat intelligence operations
  • Vulnerability management
  • Security engineering
  • Cloud security


#LI-EW1

Similar jobs