Design, develop, tune, and optimize threat detections across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms
Own high-impact detections for complex use cases, critical risks, advanced adversary behaviors, and enterprise threats
Translate adversary behavior, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk into actionable analytics
Conduct detection gap analysis and threat modeling
Build detection validation practices with test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback
Lead SIEM and SOAR detection and response workflows
Build SIEM content including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment
Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support
Identify and automate repetitive, high-volume, or high-value SOC activities
Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT platforms
Build and mature the detection and automation lifecycle from intake through retirement
Manage the detection and automation roadmap and program metrics
Resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership
Maintain audit-ready documentation and communicate strategy, risk coverage, maturity, roadmap, and outcomes to technical, non-technical, and executive stakeholders
Requirements:
10+ years of cybersecurity experience working in SOC and in creating SIEM correlations/detections and automating incident information enrichment tasks
Experience building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases
Experience building SOAR playbooks and automation workflows
Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns
Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks
Experience designing detections for identity-based attacks, endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases
Experience working in large, complex enterprise or manufacturing environments
Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams
Ability to distinguish detection, telemetry, control, ownership, and response process gaps
Excellent analytical and problem-solving skills
Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries
Passion for automation, continuous improvement, high-quality engineering practices, and scalable security systems