Quick Overview
Job Description
Senior Detection & Platform Engineer – SOC / Security Automation
Job Title: Senior Detection & Platform Engineer
Location: Dallas, TX (Hybrid)
Employment Type: Long-Term Contract
Job Summary
We are seeking an experienced Detection & Platform Engineer with strong hands-on experience in SOC engineering, detection engineering, security automation, and security platform integration.
This is not a traditional SOC Analyst role. The ideal candidate will have a strong software-engineering mindset and experience building scalable solutions that improve the effectiveness and efficiency of security operations.
The engineer will be responsible for developing and maintaining Detection-as-Code (DaC) pipelines, SIEM/SOAR integrations, security automation, detection content, API integrations, and AI-assisted SOC capabilities. The role will work closely with SOC Analysts, Threat Hunters, Detection Engineers, Threat Intelligence teams, Infrastructure Engineers, and Security Leadership.
Key Responsibilities
Detection-as-Code & Detection Engineering
- Design, build, and maintain Detection-as-Code (DaC) pipelines.
- Develop, test, validate, version, and deploy security detections through CI/CD pipelines.
- Establish detection development standards, automated testing, code review, and deployment processes.
- Develop and tune high-fidelity detections across:
- Endpoint/EDR telemetry
- Cloud security telemetry
- Network telemetry
- Email security telemetry
- DLP telemetry
- Reduce false positives while improving detection coverage and alert fidelity.
- Maintain detection logic, metadata, documentation, ownership, and lifecycle management.
- Translate threat intelligence and SOC analyst requirements into production-ready detection content.
- Apply detection engineering methodologies aligned with MITRE ATT&CK and enterprise security requirements.
SIEM & SOAR Engineering
- Engineer, administer, optimize, and support SIEM/SOAR platforms.
- Develop and maintain SIEM queries, correlation rules, alerts, dashboards, and detection content.
- Build and maintain SOAR playbooks for investigation, enrichment, containment, and response.
- Develop integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, and threat intelligence platforms.
- Troubleshoot security data ingestion, platform integrations, automation failures, and detection deployment issues.
- Improve the reliability, scalability, and performance of security operations platforms.
Security Automation & API Integration
- Identify repetitive SOC processes and develop automation to reduce manual analyst effort.
- Develop reusable Python scripts, APIs, workflows, and automation components.
- Integrate security platforms and services using REST APIs, JSON, and webhooks.
- Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
- Improve investigation efficiency, response times, consistency, and overall SOC productivity.
AI-Assisted SOC Engineering
- Identify opportunities to leverage Generative AI, LLMs, and AI agents within security operations.
- Support AI-driven alert investigation, triage, enrichment, summarization, and detection development.
- Integrate AI capabilities with existing SIEM, SOAR, and SOC workflows.
- Establish appropriate validation, governance, and controls for AI-assisted security outcomes.
Platform Engineering & Operations
- Monitor and optimize the performance, reliability, scalability, and availability of security platforms.
- Troubleshoot production issues and participate in incident resolution.
- Support platform upgrades, integrations, configuration changes, and operational improvements.
- Develop and maintain technical documentation, architecture diagrams, runbooks, and operational procedures.
- Collaborate with SOC, Threat Hunting, Threat Intelligence, Detection Engineering, Infrastructure, and Security Leadership teams.
Required Qualifications
- 5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or related fields.
- Hands-on experience with Detection-as-Code or automated security detection deployment.
- Strong experience with SIEM and SOAR platforms and SOC operational workflows.
- Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
- Strong experience with Python or similar scripting/programming languages.
- Hands-on experience with security automation, SOAR playbooks, REST APIs, and platform integrations.
- Experience with Git, CI/CD, version control, automated testing, and deployment pipelines.
- Strong understanding of security events, logs, telemetry, detection logic, alerting, and incident response.
- Experience integrating multiple security platforms through REST APIs and webhooks.
- Strong troubleshooting, analytical, and problem-solving skills.
- Ability to work independently in a fast-paced engineering environment.
Preferred Qualifications
- Experience with Sigma, YARA, or other detection/content-as-code frameworks.
- Experience with Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar SIEM platforms.
- Experience with Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar SOAR platforms.
- Experience with CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar EDR platforms.
- Experience with security telemetry from AWS, Azure, and/or Google Cloud Platform.
- Experience with GitHub, GitLab, Azure DevOps, or similar DevOps platforms.
- Experience with threat intelligence platforms and automated enrichment.
- Experience with Generative AI, LLMs, AI agents, or AI-assisted SOC operations.
- Strong understanding of MITRE ATT&CK and modern detection engineering methodologies.
- Experience working in a large-scale enterprise SOC environment.
Technical Skills
Detection Engineering: Detection-as-Code, Sigma, YARA, Detection Logic, Correlation Rules, MITRE ATT&CK
SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent
SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent
Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR
Automation & Development: Python, REST APIs, JSON, Webhooks, Scripting
DevOps: Git, GitHub/GitLab, CI/CD, Automated Testing
Cloud Security: AWS, Azure, Google Cloud Platform
AI: Generative AI, LLMs, AI-Assisted Investigation, AI Agents, Automated Triage
Security Frameworks: MITRE ATT&CK, Threat Detection Lifecycle, Incident Response
Top 3 Required Skills
- Detection-as-Code + CI/CD Detection Engineering
- SIEM/SOAR Engineering + Security Automation
- Python + REST API Integrations + SOC Detection Engineering
Key Competencies
- Strong security engineering and automation mindset
- Detection engineering and content development
- SIEM/SOAR platform engineering
- Security automation and API integration
- Detection quality and false-positive reduction
- Threat detection and incident response
- AI-assisted security operations
- Production troubleshooting and platform reliability
- Strong communication and technical documentation
- Ability to work independently and collaborate across security teams
Similar jobs
- CA
Test Automation & DevOps Engineer with Security Clearance
CACI
Chantilly, VA🇺🇸$94.4k - $198.2k/yrHybrid5 weeks agoDockerMongoDBRust+22Technology - NT
DevOps Applications Developer with Security Clearance
NewNewGen Technologies
Herndon, VA🇺🇸Hybrid19 hours agoDockerRubyShell+8Technology - TS
W2 - Infrastructure/DevOps Engineer Sr. - GJ2026
NewTechLink Systems, Inc.
Marysville, OH🇺🇸On-site19 hours agoAWSAnsibleAzure+7Technology - TE
Sr. Devops Engineer with Salesforce and Copado
NewTECHProjects
Trenton, NJ🇺🇸On-site19 hours agoDockerAWSAnsible+5Technology - LT
Google Cloud Platform DATA Platform Engineer in Charlotte, NC (Onsite)-Contract
NewLorven Technologies, Inc.
Charlotte, NC🇺🇸On-site19 hours agoApacheGoogle CloudRESTTechnology - PE
HPC Software Deployment Configuration Manager, Lead with Security Clearance
Peraton
Fort Meade, MD🇺🇸$104k - $166k/yrHybrid3 weeks agoHTTPSTechnology