Haystack
← Back to Jobs
Technology
TS

Detection and platform engineer

Tixy Services LLCDallas, TX🇺🇸United StatesPosted 25 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Dallas, TX, United States
Posted
19 hours ago
AWSSplunkAzureGenerative AIGitGoogle CloudPythonREST

Job Description

Senior Detection & Platform Engineer – SOC / Security Automation

Job Title: Senior Detection & Platform Engineer
Location: Dallas, TX (Hybrid)
Employment Type: Long-Term Contract

Job Summary

We are seeking an experienced Detection & Platform Engineer with strong hands-on experience in SOC engineering, detection engineering, security automation, and security platform integration.

This is not a traditional SOC Analyst role. The ideal candidate will have a strong software-engineering mindset and experience building scalable solutions that improve the effectiveness and efficiency of security operations.

The engineer will be responsible for developing and maintaining Detection-as-Code (DaC) pipelines, SIEM/SOAR integrations, security automation, detection content, API integrations, and AI-assisted SOC capabilities. The role will work closely with SOC Analysts, Threat Hunters, Detection Engineers, Threat Intelligence teams, Infrastructure Engineers, and Security Leadership.

Key Responsibilities

Detection-as-Code & Detection Engineering

  • Design, build, and maintain Detection-as-Code (DaC) pipelines.
  • Develop, test, validate, version, and deploy security detections through CI/CD pipelines.
  • Establish detection development standards, automated testing, code review, and deployment processes.
  • Develop and tune high-fidelity detections across:
    • Endpoint/EDR telemetry
    • Cloud security telemetry
    • Network telemetry
    • Email security telemetry
    • DLP telemetry
  • Reduce false positives while improving detection coverage and alert fidelity.
  • Maintain detection logic, metadata, documentation, ownership, and lifecycle management.
  • Translate threat intelligence and SOC analyst requirements into production-ready detection content.
  • Apply detection engineering methodologies aligned with MITRE ATT&CK and enterprise security requirements.

SIEM & SOAR Engineering

  • Engineer, administer, optimize, and support SIEM/SOAR platforms.
  • Develop and maintain SIEM queries, correlation rules, alerts, dashboards, and detection content.
  • Build and maintain SOAR playbooks for investigation, enrichment, containment, and response.
  • Develop integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, and threat intelligence platforms.
  • Troubleshoot security data ingestion, platform integrations, automation failures, and detection deployment issues.
  • Improve the reliability, scalability, and performance of security operations platforms.

Security Automation & API Integration

  • Identify repetitive SOC processes and develop automation to reduce manual analyst effort.
  • Develop reusable Python scripts, APIs, workflows, and automation components.
  • Integrate security platforms and services using REST APIs, JSON, and webhooks.
  • Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
  • Improve investigation efficiency, response times, consistency, and overall SOC productivity.

AI-Assisted SOC Engineering

  • Identify opportunities to leverage Generative AI, LLMs, and AI agents within security operations.
  • Support AI-driven alert investigation, triage, enrichment, summarization, and detection development.
  • Integrate AI capabilities with existing SIEM, SOAR, and SOC workflows.
  • Establish appropriate validation, governance, and controls for AI-assisted security outcomes.

Platform Engineering & Operations

  • Monitor and optimize the performance, reliability, scalability, and availability of security platforms.
  • Troubleshoot production issues and participate in incident resolution.
  • Support platform upgrades, integrations, configuration changes, and operational improvements.
  • Develop and maintain technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Collaborate with SOC, Threat Hunting, Threat Intelligence, Detection Engineering, Infrastructure, and Security Leadership teams.

Required Qualifications

  • 5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or related fields.
  • Hands-on experience with Detection-as-Code or automated security detection deployment.
  • Strong experience with SIEM and SOAR platforms and SOC operational workflows.
  • Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
  • Strong experience with Python or similar scripting/programming languages.
  • Hands-on experience with security automation, SOAR playbooks, REST APIs, and platform integrations.
  • Experience with Git, CI/CD, version control, automated testing, and deployment pipelines.
  • Strong understanding of security events, logs, telemetry, detection logic, alerting, and incident response.
  • Experience integrating multiple security platforms through REST APIs and webhooks.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Ability to work independently in a fast-paced engineering environment.

Preferred Qualifications

  • Experience with Sigma, YARA, or other detection/content-as-code frameworks.
  • Experience with Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar SIEM platforms.
  • Experience with Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar SOAR platforms.
  • Experience with CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar EDR platforms.
  • Experience with security telemetry from AWS, Azure, and/or Google Cloud Platform.
  • Experience with GitHub, GitLab, Azure DevOps, or similar DevOps platforms.
  • Experience with threat intelligence platforms and automated enrichment.
  • Experience with Generative AI, LLMs, AI agents, or AI-assisted SOC operations.
  • Strong understanding of MITRE ATT&CK and modern detection engineering methodologies.
  • Experience working in a large-scale enterprise SOC environment.

Technical Skills

Detection Engineering: Detection-as-Code, Sigma, YARA, Detection Logic, Correlation Rules, MITRE ATT&CK

SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent

SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent

Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR

Automation & Development: Python, REST APIs, JSON, Webhooks, Scripting

DevOps: Git, GitHub/GitLab, CI/CD, Automated Testing

Cloud Security: AWS, Azure, Google Cloud Platform

AI: Generative AI, LLMs, AI-Assisted Investigation, AI Agents, Automated Triage

Security Frameworks: MITRE ATT&CK, Threat Detection Lifecycle, Incident Response

Top 3 Required Skills

  1. Detection-as-Code + CI/CD Detection Engineering
  2. SIEM/SOAR Engineering + Security Automation
  3. Python + REST API Integrations + SOC Detection Engineering

Key Competencies

  • Strong security engineering and automation mindset
  • Detection engineering and content development
  • SIEM/SOAR platform engineering
  • Security automation and API integration
  • Detection quality and false-positive reduction
  • Threat detection and incident response
  • AI-assisted security operations
  • Production troubleshooting and platform reliability
  • Strong communication and technical documentation
  • Ability to work independently and collaborate across security teams

Similar jobs