3 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
Principal Detection Engineer (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Principal Detection Engineer (Cybersecurity): Building cross-domain threat detection coverage across endpoint, cloud, NG-SIEM, identity, SaaS security, and FEM with an accent on high-fidelity correlation logic, threat-informed prioritization, and AI-assisted workflows. Focus on correlating telemetry across security surfaces, closing detection gaps, guiding detection engineers, and improving platform capabilities against rapidly evolving adversary campaigns.
Location: United Kingdom - Remote
Company
Cybersecurity company providing an AI-native platform for detecting and preventing breaches across large-scale distributed systems.
What you will do
- Own the cross-domain detection strategy across endpoint, cloud, NG-SIEM, identity, SaaS security, and FEM.
- Design high-fidelity correlation detections using entity resolution, temporal reasoning, behavioral layering, and Platform IOAs.
- Translate internal and external threat intelligence into detection priorities and multi-domain coverage.
- Coordinate detection development across teams so cross-domain scenarios receive consistent coverage.
- Apply AI and large language models to gap analysis, threat-intelligence triage, and correlation-logic prototyping.
- Coach detection engineers, set technical standards, and influence telemetry and platform direction.
Requirements
- Extensive experience writing production detection content across multiple platforms or data domains.
- Experience designing or contributing to detections that correlate signals across endpoint, cloud, identity, SaaS, network, or runtime environments.
- Strong knowledge of threat actors, campaigns, TTPs, detection content lifecycles, telemetry limitations, false-positive drift, and detection performance.
- Strong communication, cross-team influence, technical leadership, and experience mentoring or reviewing detection engineers.
- Proven experience using AI technologies to improve decision-making, workflows, efficiency, and business outcomes.
Nice to have
- Experience applying AI or LLMs to detection or security operations workflows.
- EDR or SIEM vendor-side product experience and MITRE ATT&CK fluency.
- Published security research, malware analysis, or reverse engineering experience.
- Experience quantifying detection efficacy, including precision, recall, and bypass resistance.
Culture & Benefits
- Full-time employment with compensation and equity awards.
- Physical and mental wellness programs.
- Competitive vacation, holidays, and paid parental and adoption leave.
- Professional development opportunities for all employees.
- Employee networks, geographic neighborhood groups, and volunteer opportunities.
- Equal employment opportunity and support for veterans and individuals with disabilities.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β