Community Health Systems

Detection Engineering Specialist

Remote
SIEM SOAR Python PowerShell IDS/IPS
Description

Detection Engineering Specialist (Remote)

Location: United States

Job Summary

As a Detection Engineer Specialist, you will leverage your extensive expertise in threat detection, security analytics, and automation to design, implement, and manage advanced detection and response capabilities across the organization’s security monitoring ecosystem. This role is responsible for the end-to-end lifecycle of detection engineering, including the development, tuning, and optimization of detections within Security Information and Event Management (SIEM) platforms, as well as the design and governance of Security Orchestration, Automation, and Response (SOAR) playbooks and automation workflows.

You will serve as a technical leader with deep hands-on proficiency in SIEM, SOAR, and security automation technologies, applying detection engineering best practices to improve alert fidelity, reduce mean time to detect and respond, and enable scalable, repeatable incident handling. This role requires strong analytical and problem-solving skills, the ability to translate threat intelligence and incident learnings into actionable detections and automations, and close collaboration with the incident response team, platform engineers, and third-party security partners.

You are expected to work independently with minimal supervision, take ownership of complex initiatives, and provide technical mentorship and training to team members. You will play a key role in shaping detection and automation strategy, ensuring operational resiliency, and continuously enhancing the organization’s overall security posture.


Essential Functions

  • Lead the design and implementation of SIEM and SOAR solutions, ensuring they meet the organization’s security requirements and industry best practices.
  • Lead the development and implementation of advanced detection strategies to identify potential security threats and vulnerabilities.
  • Work closely with other security teams to integrate detection capabilities with overall security operations, including customization, and optimization of detection rules.
  • Perform advanced threat detection, analysis, and correlation using various detection tools and techniques to identify and mitigate security threats.
  • Collaborate with the Incident Response, Threat Intelligence, and Threat Hunting teams to analyze and respond to security threats, providing expert guidance on detection-related issues.
  • Develop and maintain documentation for detection engineering practices on how to create and refine detection use cases and techniques.
  • Proactively identify new detection opportunities and improve existing detection methodologies using threat models and frameworks that ensure a comprehensive detection strategy and rule set. 
  • Maintain comprehensive documentation of detection configurations, processes, and activities.
  • Provide technical leadership and mentorship to the Incident Response, Threat Intelligence, and Threat Hunting teams. 
  • Develop and accumulate lessons learned documentation from incidents to identify controls and new detections to prevent identified malicious activity from reoccurring.

     

Qualifications

  • H.S. Diploma or GED required
  • Associate Degree or Bachelor’s Degree in Cyber Security, Computer Science, Information Systems, or related field preferred
  • Deep knowledge of typical IT platforms, operating systems, and configuration methods
  • Deep knowledge of security threat tactics, techniques, and procedures (TTPs), incident response methodologies, and detection techniques
  • Extensive experience with detection technologies (e.g., IDS/IPS, SIEM) and threat detection practices.
  • 5+ years of IT or Information Security experience, including 3+ years SIEM Management or Detection Engineering experience
  • Preferred: 
    • Industry recognized cyber security training or certifications to include SANS, ISC2, EC-Council or CompTIA vendors
    • Familiarity with MITRE ATT&CK, Cyber Kill Chain, and other threat modeling frameworks
    • Experience in scripting and automation (e.g., Python, PowerShell) for security operations
Community Health Systems
Community Health Systems

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say