Haystack
← Back to Jobs
Technology
PT

Senior Detection Engineer / SOC Platform Engineer / Security Engineer $84.69/hr W2

Projas Technologies, LLCDallas, TX🇺🇸United StatesPosted Oct 6, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Dallas, TX, United States
Posted
18 hours ago
SAMLSSOSplunkCDNDNSGenerative AIGitGitHub ActionsKubernetesLLMPythonRESTWAFZero Trust

Job Description

Job Title: Senior Detection Engineer / SOC Platform Engineer

Location: Dallas, TX (Preferred) | Also open to San Diego, CA and Mountain View, CA
Work Model: Hybrid, 3 days onsite per week

<>Overview

We are seeking a highly skilled Senior Detection Engineer / SOC Platform Engineer to support a mature Threat Operations organization. This role is focused on building and maintaining the technology backbone of a modern Security Operations Center (SOC), including SIEM, SOAR, detection engineering, SOC automation, AI-driven security operations, and security case management.

This is a hands-on engineering position rather than a traditional analyst role. The ideal candidate will have experience developing security detections, managing Security Incident Response platforms, automating SOC workflows, and leveraging AI technologies to improve operational effectiveness.

<>Responsibilities
  • Administer and enhance the Security Incident Response (SIR) platform, including workflow design, escalation rules, assignment logic, SLAs, UI configuration, and integrations.
  • Design, build, and maintain Detection-as-Code (DaC) pipelines using modern CI/CD methodologies.
  • Develop, test, tune, and deploy detections across endpoint, cloud, network, email, and data protection telemetry sources.
  • Build SOAR playbooks, API integrations, and workflow automations to improve SOC efficiency.
  • Support SIEM and SOAR platform administration, optimization, and content deployment.
  • Contribute to AI-powered SOC initiatives, including investigation automation, alert triage, and operational efficiency improvements.
  • Apply detection engineering best practices including MITRE ATT&CK mapping, false-positive reduction, detection lifecycle management, and validation standards.
  • Partner with SOC analysts and incident responders to translate operational challenges into scalable engineering solutions.
<>Required Qualifications
  • Proven experience in Detection Engineering, Security Engineering, Threat Detection, Threat Operations, or advanced SOC roles.
  • Hands-on administration experience with Security Incident Response (SIR) platforms in production environments.
  • Strong scripting and automation experience with Python.
  • Experience developing or contributing to Detection-as-Code pipelines.
  • Strong knowledge of:
    • MITRE ATT&CK
    • Pyramid of Pain
    • Cyber Kill Chain
    • Incident Response methodologies
  • Deep expertise in one or more of:
    • Endpoint Security (Windows and macOS telemetry, detection engineering, host investigations)
    • Cloud Security (Cloud-native services, Kubernetes security, runtime detection)
  • Strong networking fundamentals, including DNS.
  • Experience with Identity and Access Management (IAM), SAML, OIDC, and Zero Trust architectures.
  • Understanding of Data Loss Prevention (DLP) technologies and use cases.
  • Knowledge of AI Detection & Response concepts, including monitoring and securing enterprise AI/LLM usage.
  • Familiarity with agentic AI frameworks and practical AI applications within SOC operations.
<>Preferred Qualifications
  • Relevant Service Management and Security Incident Response certifications.
  • Experience with Git, GitHub Actions, or similar CI/CD tooling.
  • Experience integrating AI/LLM capabilities into detection engineering or SOC triage workflows.
  • Knowledge of Risk-Based Alerting methodologies.
  • Experience operating large-scale SIEM and SOAR environments.
<>Technology Environment

Experience with the following technologies is highly desirable:

  • Endpoint Detection & Response (EDR)
  • SIEM platforms
  • SOAR platforms
  • Security Incident Response platforms
  • Cloud Security Posture Management (CSPM)
  • Kubernetes Security
  • Network Security and Secure Web Gateway technologies
  • Data Loss Prevention (DLP)
  • Email Security
  • Web Application Firewall (WAF)
  • Content Delivery Networks (CDN)
  • AI Security Monitoring and AI Detection & Response platforms
<>Education

Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related technical discipline. Equivalent practical experience will also be considered. Security certifications are a plus but hands-on engineering experience is valued most.

Senior Detection Engineer, Detection Engineer, SOC Platform Engineer, Security Engineer, Threat Detection Engineer, Threat Operations Engineer, Detection-as-Code Engineer, Cyber Security Engineer, SIEM Engineer, SOAR Engineer, Security Automation Engineer, Security Platform Engineer, Incident Response Engineer, Threat Hunting Engineer, SOC Engineer, Blue Team Engineer, Security Operations Engineer

Detection Engineering, Detection as Code, DaC, SOC, Security Operations Center, Threat Operations, Threat Detection, Threat Hunting, Security Engineering, Incident Response, Security Automation, Python, API Integration, REST API, SOAR, SIEM, Detection Development, Detection Tuning, Alert Engineering, Detection Lifecycle Management, MITRE ATT&CK, Pyramid of Pain, Cyber Kill Chain, Threat Intelligence, Security Monitoring, Security Analytics, FP Reduction, Risk Based Alerting, CI/CD, Git, GitHub Actions, Version Control, Automated Deployment, DevSecOps, ServiceNow, Security Incident Response, SIR, Workflow Automation, Business Rules, SLA Management, Case Management, Security Workflows, EDR, Endpoint Security, Windows Security, macOS Security, Cloud Security, Kubernetes Security, Runtime Detection, CSPM, Network Security, DNS, IAM, Identity Access Management, SSO, SAML, OIDC, Zero Trust, DLP, Data Loss Prevention, Email Security, WAF, CDN, AI Security, AI Detection and Response, AI SOC, LLM Security, Agentic AI, Generative AI Security, Security Orchestration, Investigation Automation, Alert Triage Automation, Security Platforms, Security Content Deployment, Security Integrations, SOC Engineering, Splunk, CrowdStrike, Zscaler, Wiz, Akamai, Security Operations Automation

Detection Engineering, SIEM Administration, SOAR Development, ServiceNow Administration, Security Incident Response, Python Development, Automation Engineering, CI/CD Pipelines, Threat Detection, Incident Management, Security Operations, Cloud Security, Endpoint Security, Kubernetes Security, Network Security, DNS Analysis, Identity Security, DLP Engineering, AI Security Operations, Threat Intelligence Integration, Security Workflow Development, API Development, Detection Tuning, Alert Management, Detection Validation, Security Content Engineering, Security Platform Administration, SOC Automation, Threat Modeling, Cyber Defense, Blue Team Operations, Investigation Engineering, Security Analytics, Detection Pipeline Development, Enterprise Security Monitoring, Automation Frameworks, AI-Driven SOC Operations

Similar jobs