Why This Role Stands Out
Leverage your expertise in security detection engineering within a long-term contract role at Maureen Data Systems Inc, offering a competitive hourly rate of $80-$100 and hybrid flexibility. This opportunity is perfect for a mid-senior level professional passionate about building advanced security detections and reducing organizational risk across diverse technologies. Apply now to contribute to impactful client projects and further develop your skills in a dynamic environment.
Quick Overview
Job Description
Detection Engineer (Contract)
Location: United States (Remote)
Employment Type: Contract (Full-Time, 40 hours/week)
Duration: Long-term, supporting multiple client projects
Compensation: $80–$100/hour (DOE).
About the Role
We are seeking an experienced Detection Engineer to design, develop, and maintain advanced security detections that enable Security Operations Centers (SOC) to identify and respond to modern cyber threats. This is a long-term contract opportunity supporting multiple enterprise security initiatives, where you will work across SIEM, endpoint, cloud, identity, and network technologies to improve detection coverage and reduce organizational risk.
This role is ideal for someone passionate about threat detection engineering, adversary behaviors, and continuously improving security operations through automation and detection-as-code practices.
Responsibilities
- Design, develop, and maintain detection rules, analytics, alerts, dashboards, and threat hunting queries across SIEM, endpoint, identity, cloud, and network platforms.
- Author and optimize detections using KQL, Sigma, YAML-based detection rules, and other query languages.
- Own the full detection lifecycle, including design, peer review, testing, deployment, versioning, tuning, maintenance, and retirement.
- Implement Detection-as-Code practices using source control, peer reviews, and CI/CD pipelines.
- Translate threat intelligence, incident response findings, and adversary TTPs into effective and resilient detection logic.
- Map detections to the MITRE ATT&CK Framework and identify gaps in detection coverage.
- Continuously tune detections to improve fidelity while reducing false positives.
- Validate detections through adversary emulation, attack simulations, and threat hunting exercises.
- Monitor detection health and performance metrics, including alert volume, precision, and coverage.
- Partner with engineering teams to onboard new log sources, improve telemetry quality, and address data gaps.
- Develop analyst documentation, including triage guidance, expected false positives, and escalation procedures.
- Collaborate closely with SOC analysts, incident responders, threat hunters, red teams, and platform engineers.
- Utilize approved AI tools to accelerate documentation, testing, and automation while maintaining human review of all production content.
Required Qualifications
- 3+ years of experience in Detection Engineering, Security Operations, Threat Hunting, or Incident Response.
- Strong experience building and tuning detections within enterprise SIEM platforms.
- Experience authoring detection content using KQL, Sigma, Sentinel Analytics Rules, Elastic Detection Rules, or other YAML-based detection frameworks.
- Experience operationalizing threat intelligence into actionable detection content.
- Strong understanding of the MITRE ATT&CK Framework and adversary tradecraft.
- Experience with Git, source control, CI/CD pipelines, and Detection-as-Code methodologies.
- Proficiency with Python or PowerShell for automation and testing.
- Hands-on experience analyzing:
- Windows Event Logs
- Sysmon
- Microsoft Entra ID Sign-In & Audit Logs
- Endpoint telemetry
- Network telemetry
- Cloud control-plane logs (Azure, AWS, or Google Cloud Platform)
- Strong understanding of detection evasion techniques and behavioral detection strategies.
- Excellent troubleshooting, documentation, and communication skills.
Preferred Qualifications
- Experience with Splunk SPL or additional SIEM query languages.
- Experience with YARA, Snort, Suricata, or Zeek.
- Experience with adversary emulation or Breach & Attack Simulation (BAS) tools.
- Familiarity with normalization schemas such as ASIM, OCSF, or ECS.
- Experience integrating detections with SOAR platforms and automated response workflows.
- Experience leveraging AI to improve security operations.
- Relevant certifications in SIEM, cloud security, incident response, or threat intelligence.
Position Details
- Location: Must be authorized to work in the United States.
- Language Requirement: English required.
- Schedule: Full-time contract (40 hours/week).
- Duration: Long-term engagement supporting multiple concurrent security projects.
Similar jobs
- SP
Sr. Classified Cyber Assurance Analyst
NewSpaceX
Washington, DC🇺🇸$130k - $195k/yrRemoteYesterdaySplunkComplianceTriageTechnology - DC
Security Analyst/Technical Support Analyst
NewData Capital Inc
Richmond, VA🇺🇸On-siteYesterdayActive DirectorySSOMFA+1Technology - GE
IT Security Specialist
Genesis10
Charlotte, NC🇺🇸$67 - $75/hrOn-site3 days agoSplunkTechnology - NG
Industrial Security Analyst with Security Clearance
Northrop Grumman
Redondo Beach, CA🇺🇸$75.8k - $113.8k/yrHybrid3 weeks agoTechnology - EG
Security Engineer, Incident Response
NewEliassen Group
Burbank, CA🇺🇸$55 - $64/hrOn-siteYesterdayAWSAzureGoogle Cloud+1Technology - BL
Information Assurance Specialist III (Information Security Analy with Security Clearance
By Light
Butlerville, IN🇺🇸Hybrid3 days agoComplianceRisk Management