Detection Engineer positions focus on delivering results in their domain. This page aggregates open Detection Engineer roles and what employers typically expect.
About the Role We're looking for a Detection Engineer to own the detection content that powers the Artemis platform. You'll design, build, test, and continuously tune high-fidelity detections across cloud, identity, endpoint, and SaaS environments — treating detection as code, and using AI as a force multiplier at every step: authoring rules with AI assistance, and building anomaly detections that learn what's normal in each environment and flag what isn't. Detections at Artemis don't just fire alerts; they feed an AI-native investigation pipeline, so precision, rich context, and machine-readable output matter as much as coverage. This is a hands-on engineering role where every rule you ship directly determines what threats we catch for customers and how fast we catch them. Responsibilities - Build and maintain the detection library - Design, implement, and own high-fidelity detections across cloud (AWS, Azure, GCP), identity (Okta, Entra ID), endpoint (EDR), and SaaS log sources, from hypothesis to production. - Practice detection-as-code - Manage detection content like software: version-controlled rules, peer review, automated validation and testing, and CI/CD deployment across customer environments. - Map and close coverage gaps - Measure detection coverage against MITRE ATT&CK, prioritize gaps based on real-world threat activity, and systematically close them. - Validate against real attacks - Build and run attack simulations and test harnesses to prove detections fire on true positives and stay quiet on benign activity, before and after they ship. - Tune relentlessly - Own false-positive and false-negative rates across the fleet: analyze detection performance data, tune noisy logic at the source, and sunset detections that no longer earn their keep. - Use AI to write detections at scale - Leverage AI throughout the detection lifecycle: use AI-assisted workflows to author, convert, test, and document rules faster than any traditional team could, and build the tooling that makes AI-generated detection content trustworthy enough to ship. - Build behavioral and anomaly-based detections - Go beyond static signatures: establish behavioral baselines of normal activity per environment (identity, cloud, SaaS usage patterns) and engineer anomaly detections that surface deviations — impossible travel, unusual privilege use, novel API activity — with high signal and low noise. - Engineer detections for AI-powered investigation - Design detections that produce rich, structured context so the Artemis platform can investigate and resolve cases autonomously. - Turn intelligence into detections - Translate threat intelligence, incident findings, and threat hunt results from our research and SOC teams into durable, behavioral detection logic. - Partner with the SOC and research teams - Close the loop with Apollo analysts and security researchers: use case outcomes and analyst feedback to drive detection improvements, and give them documentation that makes every alert investigable. - Support customer-specific tuning - Adapt and tune detection content to each customer's environment and business context, reducing noise without sacrificing coverage. Qualifications - 5+ years of hands-on cybersecurity experience, with significant time in detection engineering - Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms - Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA-L, and comfort writing code (Python preferred) for automation and testing - Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry - Experience with detection-as-code workflows: Git, peer review, automated testing, and CI/CD for detection content - Experience using AI tools to accelerate detection authoring, tuning, or validation — and judgment about when AI-generated logic is…