← Takaisin työpaikkoihin

Sr Detection Engineer II

  • Paikan päällä
  • Ruotsi
  • Englanti
  • Julkaistu 16.09.26 17:31

Senior Security Detection & Automation Engineer

Role Overview

We are looking for a Senior Security Detection & Automation Engineer with 4 to 8 years of hands-on cybersecurity experience.

This role focuses on designing high-quality security detections, building scalable automation, integrating security technologies, and improving the efficiency and effectiveness of security monitoring. This is an core security position, not a Tier 1 or Tier 2 alert-monitoring role.

Key Responsibilities

Detection Engineering

Design, develop, test, deploy, and maintain security detections across endpoint, identity, cloud, network, email, and application environments.Translate threat intelligence, attacker behaviors, threat-hunting findings, and security risks into actionable detection logic.Develop behavioral, anomaly-based, and correlation-based detections across multiple data sources.Create detection content using Sigma, KQL, SPL, YARA, Suricata, or platform-specific query languages.Map detection coverage to MITRE ATT&CK and identify gaps across priority attack techniques and critical assets.Tune detections to improve fidelity, reduce false positives, and minimize unnecessary analyst workload.Define detection requirements, including data dependencies, logic, severity, confidence, response guidance, and ownership.Manage the complete detection lifecycle, from initial development through validation, deployment, maintenance, and retirement.Measure detection quality through coverage, precision, alert volume, false-positive rates, and detection performance.

Security Automation

Design and develop automation for alert enrichment, correlation, prioritization, evidence collection, case creation, and analyst recommendations.Automate repetitive Tier 1 and Tier 2 activities to improve analyst capacity and consistency.Build integrations between SIEM, EDR, XDR, SOAR, identity, cloud, threat intelligence, vulnerability management, ticketing, and communication platforms.Develop reusable scripts, APIs, services, connectors, and automation components using Python, PowerShell, or comparable languages.Implement reliable workflows with error handling, retry logic, logging, monitoring, auditability, and failure notifications.Apply appropriate access controls, secrets management, testing, approval points, and rollback capabilities.Evaluate AI-assisted security workflows with appropriate validation, evidence tracking, security controls, and human oversight.Measure automation value through reduced handling time, improved consistency, lower manual effort, and increased analyst capacity.

Detection-as-Code

Manage detection content through version-controlled detection-as-code practices.Build automated pipelines for detection validation, testing, deployment, and rollback.Create unit tests, regression tests, and simulation-based tests for detection logic.Validate detections against representative attack data and expected business activity.Conduct peer reviews of detection rules and automation code.Maintain clear documentation covering detection purpose, logic, telemetry requirements, ATT&CK mapping, testing evidence, known limitations, and response guidance.Monitor changes to schemas, data sources, APIs, and security platforms that may affect detection or automation reliability.

Security Research and Continuous Improvement

Research emerging attacker techniques, security technologies, and detection opportunities relevant to the organization.Perform threat hunting and controlled attack simulations to validate detection coverage.Identify telemetry gaps and work with technology owners to improve security data quality and visibility.Develop reusable engineering standards, libraries, templates, and frameworks.Review existing alerts and workflows to identify opportunities for tuning, consolidation, or automation.Provide technical guidance on detection logic, telemetry interpretation, and automated workflows.Convert security risks and control gaps into measurable engineering improvements.

Required Experience

4 to 8 years of hands-on cybersecurity experience, with significant exposure to detection engineering, security automation, threat hunting, SOC engineering, or security engineering.Demonstrated experience creating, testing, and tuning production security detections.Strong experience with at least one enterprise SIEM platform and one EDR or XDR platform.Practical scripting or software development experience using Python, PowerShell, or a comparable language.Experience building API-based integrations using REST APIs, webhooks, JSON, and structured security data.Experience with Git, peer review, automated testing, and controlled deployment practices.Strong understanding of endpoint, identity, cloud, network, email, and application security telemetry.Working knowledge of MITRE ATT&CK and common adversary behaviors.Ability to distinguish malicious activity from expected business and system behavior.Ability to convert a security requirement into a tested, maintainable, and measurable engineering solution.