Haystack
← Back to Jobs
Engineering

Detection Engineer

Delviom LLCArlington, VA🇺🇸United StatesPosted 27 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

  • Experience developing, tuning, and validating SIEM detection rules for enterprise security monitoring.
  • Strong knowledge of detection engineering for data exfiltration, Amazon S3 uploads, Google Drive, VPN/tunneling, SMB traffic, USB activity, RDP, LOLBins, and cloud security monitoring.
  • Experience creating behavioral detections using UEBA, GeoIP enrichment, Identity telemetry, and endpoint correlation.
  • Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, Elastic, QRadar, or similar) and enterprise log source integration.
  • Strong understanding of MITRE ATT&CK, threat detection use cases, false positive reduction, and detection lifecycle management.
  • Experience validating detection effectiveness through testing, operational evidence collection, rule tuning, and production deployment.
  • Knowledge of automation technologies including SOAR workflows, ServiceNow integration, and scripting using Python or PowerShell.

Similar jobs