Haystack
← Back to Jobs
Remote
Engineering
DE

100% Remote Detection Engineer/ SOC Integration/12+ Months Contract

Dexperts IncUnited States🇺🇸United StatesPosted Sep 22, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
2 days ago

Job Description

Hello,                                                                                                 

 

I have below exclusive position with one of our Client. Please review the requirement criteria below and revert to me with your updated resume so that we can move ahead for further steps.

 

Job Title: Detection Engineer/ SOC Integration

Location: 100% Remote

Duration: 12+ Months Contract Potential for extension

 

Responsibilities:

       Ingest and normalize every source so an analyst can pivot on user, session, and model - without this the SIEM holds data nobody can investigate with

       Write the detections: usage and cost anomalies, connector and tool-use activity, failed DLP and guardrail events, grant scope widened, managed-settings tamper, ZDR setting changed

       Tune to a false-positive rate the SOC will actually work - an alert set that floods the queue gets muted in week three and the control is then decorative

       Build and validate the four WS7 IR runbooks against containment capabilities that actually exist.

Must Have:

       Production detection engineering in Google SecOps and/or Cribl - has written, tuned, and maintained real content

       Has built SaaS audit log ingestion from API sources: pagination, cursor management, rate limiting, backfill

       Has written IR runbooks that were used in a real incident and revised afterward

Mission:

  • Turn the telemetry every other workstream produces into working detections, alerts, and runbooks inside Client existing SOC.

Similar jobs