Haystack
← Back to Jobs
Engineering
MD

Detection Engineer (Contract)

Maureen Data Systems IncUnited States🇺🇸United StatesPosted Sep 14, 2026

Why This Role Stands Out

Leverage your expertise in security detection engineering within a long-term contract role at Maureen Data Systems Inc, offering a competitive hourly rate of $80-$100 and hybrid flexibility. This opportunity is perfect for a mid-senior level professional passionate about building advanced security detections and reducing organizational risk across diverse technologies. Apply now to contribute to impactful client projects and further develop your skills in a dynamic environment.

Quick Overview

Salary
$80 - $100/hr
Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
3 days ago

Job Description

Detection Engineer (Contract)

Location: United States (Remote)
Employment Type: Contract (Full-Time, 40 hours/week)
Duration: Long-term, supporting multiple client projects
Compensation: $80–$100/hour (DOE). 

About the Role

We are seeking an experienced Detection Engineer to design, develop, and maintain advanced security detections that enable Security Operations Centers (SOC) to identify and respond to modern cyber threats. This is a long-term contract opportunity supporting multiple enterprise security initiatives, where you will work across SIEM, endpoint, cloud, identity, and network technologies to improve detection coverage and reduce organizational risk.

This role is ideal for someone passionate about threat detection engineering, adversary behaviors, and continuously improving security operations through automation and detection-as-code practices.

Responsibilities

  • Design, develop, and maintain detection rules, analytics, alerts, dashboards, and threat hunting queries across SIEM, endpoint, identity, cloud, and network platforms.
  • Author and optimize detections using KQL, Sigma, YAML-based detection rules, and other query languages.
  • Own the full detection lifecycle, including design, peer review, testing, deployment, versioning, tuning, maintenance, and retirement.
  • Implement Detection-as-Code practices using source control, peer reviews, and CI/CD pipelines.
  • Translate threat intelligence, incident response findings, and adversary TTPs into effective and resilient detection logic.
  • Map detections to the MITRE ATT&CK Framework and identify gaps in detection coverage.
  • Continuously tune detections to improve fidelity while reducing false positives.
  • Validate detections through adversary emulation, attack simulations, and threat hunting exercises.
  • Monitor detection health and performance metrics, including alert volume, precision, and coverage.
  • Partner with engineering teams to onboard new log sources, improve telemetry quality, and address data gaps.
  • Develop analyst documentation, including triage guidance, expected false positives, and escalation procedures.
  • Collaborate closely with SOC analysts, incident responders, threat hunters, red teams, and platform engineers.
  • Utilize approved AI tools to accelerate documentation, testing, and automation while maintaining human review of all production content.

Required Qualifications

  • 3+ years of experience in Detection Engineering, Security Operations, Threat Hunting, or Incident Response.
  • Strong experience building and tuning detections within enterprise SIEM platforms.
  • Experience authoring detection content using KQL, Sigma, Sentinel Analytics Rules, Elastic Detection Rules, or other YAML-based detection frameworks.
  • Experience operationalizing threat intelligence into actionable detection content.
  • Strong understanding of the MITRE ATT&CK Framework and adversary tradecraft.
  • Experience with Git, source control, CI/CD pipelines, and Detection-as-Code methodologies.
  • Proficiency with Python or PowerShell for automation and testing.
  • Hands-on experience analyzing:
    • Windows Event Logs
    • Sysmon
    • Microsoft Entra ID Sign-In & Audit Logs
    • Endpoint telemetry
    • Network telemetry
    • Cloud control-plane logs (Azure, AWS, or Google Cloud Platform)
  • Strong understanding of detection evasion techniques and behavioral detection strategies.
  • Excellent troubleshooting, documentation, and communication skills.

Preferred Qualifications

  • Experience with Splunk SPL or additional SIEM query languages.
  • Experience with YARA, Snort, Suricata, or Zeek.
  • Experience with adversary emulation or Breach & Attack Simulation (BAS) tools.
  • Familiarity with normalization schemas such as ASIM, OCSF, or ECS.
  • Experience integrating detections with SOAR platforms and automated response workflows.
  • Experience leveraging AI to improve security operations.
  • Relevant certifications in SIEM, cloud security, incident response, or threat intelligence.

Position Details

  • Location: Must be authorized to work in the United States.
  • Language Requirement: English required.
  • Schedule: Full-time contract (40 hours/week).
  • Duration: Long-term engagement supporting multiple concurrent security projects.

Similar jobs