JOB SUMMARY
\nThe Detection & Platform Engineering team owns the technology backbone of the Security Operations Center (SOC). The team is responsible for building, operating, and continuously improving the platforms, automation, and detection capabilities that enable effective threat detection and response.
\nOur charter spans four key areas:
\nSIEM & SOAR Platform Management — Engineering, administration, optimization, and reliability of the SIEM and SOAR platforms supporting SOC operations.
\nAI SOC — Deploying and scaling AI-driven investigation, triage, and analyst-assistance capabilities across the SOC.
\nSOAR & Security Automation — Building playbooks, integrations, APIs, and automated workflows that reduce analyst toil and improve response efficiency.
\nDetection Deployment — Developing, testing, validating, and deploying high-fidelity detections through a Detection-as-Code (DaC) pipeline.
\nRole Summary
\nWe are seeking an experienced Detection & Platform Engineer with hands-on SOC and security engineering experience and a strong software-engineering mindset.
\nThis is not a pure SOC analyst role. The ideal contractor will be comfortable building engineering solutions that improve the scalability and effectiveness of security operations. You will develop and maintain Detection-as-Code pipelines, automate SOC workflows, create and tune security detections, integrate security platforms through APIs, and leverage AI to improve investigation and detection-engineering productivity.
\nKey Responsibilities
\nDetection-as-Code Engineering
\nDesign, build, and maintain Detection-as-Code (DaC) pipelines.
\nDevelop, test, validate, version, and deploy security detections through automated CI/CD workflows.
\nImplement detection development standards, testing frameworks, code review processes, and deployment controls.
\nDevelop and tune high-fidelity detections across:
\nEndpoint/EDR telemetry
\nCloud environments
\nNetwork telemetry
\nEmail security telemetry
\nDLP telemetry
\nReduce false positives while improving detection coverage and alert fidelity.
\nMaintain detection logic, documentation, metadata, ownership, and lifecycle management.
\nCollaborate with threat detection and SOC teams to translate threat intelligence and analyst requirements into production detections.
\nSIEM & SOAR Engineering
\nSupport administration, engineering, optimization, and reliability of the SIEM/SOAR platform stack.
\nDevelop and maintain SIEM queries, correlation rules, dashboards, alerts, and detection content.
\nBuild SOAR playbooks to automate investigation, enrichment, containment, and response workflows.
\nDevelop API integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, threat intelligence, and other security platforms.
\nTroubleshoot platform integrations, data ingestion, automation failures, and detection deployment issues.
\nSecurity Automation
\nIdentify repetitive SOC processes and develop automation to reduce manual analyst effort.
\nBuild reusable Python/scripts, APIs, workflows, and automation components.
\nIntegrate security tools and services using REST APIs and webhooks.
\nAutomate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
\nImprove operational efficiency, response times, and consistency through automation.
\nAI SOC Engineering
\nSupport deployment and scaling of AI-driven investigation and triage capabilities.
\nIdentify opportunities to apply AI/LLMs to alert investigation, enrichment, summarization, detection development, and analyst workflows.
\nIntegrate AI capabilities with existing SOC platforms and automation workflows.
\nHelp establish appropriate validation, governance, and controls around AI-generated security outcomes.
\nPlatform Engineering & Operations
\nMonitor and optimize the performance, reliability, scalability, and availability of SOC security platforms.
\nTroubleshoot production issues and participate in incident resolution.
\nSupport platform upgrades, integrations, configuration changes, and operational improvements.
\nCreate technical documentation, runbooks, architecture documentation, and operational procedures.
\nWork closely with SOC analysts, threat hunters, detection engineers, threat intelligence teams, infrastructure engineers, and security leadership.
\nRequired Qualifications
\n5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or a related field.
\nHands-on experience building and maintaining Detection-as-Code or automated detection deployment pipelines.
\nStrong understanding of SIEM and SOAR platforms and SOC operational workflows.
\nExperience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
\nExperience with CI/CD, Git, version control, automated testing, and deployment pipelines.
\nStrong scripting/programming experience with Python or a similar language.
\nExperience developing SOAR playbooks, security automation, API integrations, and workflows.
\nStrong understanding of security events, logs, telemetry, alerting, detection logic, and incident-response processes.
\nExperience working with REST APIs and integrating multiple security platforms.
\nStrong troubleshooting and problem-solving skills.
\nAbility to work independently in a fast-paced engineering environment.
\nPreferred Qualifications
\nExperience with Sigma, YARA, or other detection/content-as-code frameworks.
\nExperience with major SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar.
\nExperience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar.
\nExperience with EDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar.
\nExperience with cloud security telemetry across AWS, Azure, or GCP.
\nExperience with GitHub/GitLab/Azure DevOps and CI/CD tooling.
\nExperience with threat intelligence platforms and automated enrichment.
\nExperience with LLMs, GenAI, AI agents, or AI-assisted SOC operations.
\nFamiliarity with MITRE ATT&CK and threat detection engineering methodologies.
\nExperience in large enterprise SOC environments.
\nTechnical Skills
\nDetection Engineering: Detection-as-Code, Sigma, YARA, detection logic, correlation rules, threat detection, MITRE ATT&CK
\nSIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent
\nSOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent
\nEndpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR platforms
\nAutomation & Development: Python, REST APIs, JSON, webhooks, scripting
\nDevOps: Git, GitHub/GitLab, CI/CD, automated testing, infrastructure/deployment pipelines
\nCloud: AWS, Azure, and/or GCP security telemetry
\nAI: Generative AI, LLMs, AI-assisted investigation, AI agents, automated triage
\nSecurity Frameworks: MITRE ATT&CK, threat detection lifecycle, incident response
\nSoft Skills
\nStrong engineering and automation mindset.
\nAbility to translate SOC requirements into scalable technical solutions.
\nStrong communication and documentation skills.
\nComfortable collaborating with security analysts and engineering teams.
\nAbility to troubleshoot complex production environments.
\nStrong ownership and ability to work independently.
\nDetail-oriented approach to detection quality and operational reliability.
\nTop 3 Required Skills
\nDetection-as-Code + CI/CD Detection Engineering
\nSIEM/SOAR Engineering + Security Automation
\nPython/API Integrations + SOC Detection Engineering
\nIdeal Candidate Profile
\nThe ideal candidate is a Security Detection/Automation Engineer rather than a traditional SOC Analyst—someone who can write code, build CI/CD pipelines, develop and tune detections, engineer SOAR workflows, integrate security platforms through APIs, and improve SOC operations through automation and AI.
| Location | Dallas, TX |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder