freehire launches on Product Hunt on 26 August.

Follow →

Cybersecurity Detection Engineer 3643279 (Charlotte, NC)

Open 20d

Summary

Designs and maintains cybersecurity detection logic for cloud and on-premises environments to identify and respond to threats, using SIEM, EDR, and MITRE ATT&CK frameworks.

Be Part of a High-Performing Team

Join a global financial services organization committed to maintaining resilient, secure, and highly regulated technology operations. The cybersecurity organization protects complex cloud and on-premises environments by strengthening monitoring, threat detection, and incident response capabilities.

This position supports a collaborative Security Operations team that works closely with SOC analysts, incident responders, threat intelligence specialists, security engineers, and technology partners. The environment is fast-paced and analytical, with a strong emphasis on measurable detection coverage, automation, operational excellence, and continuous improvement.

What’s In Store For You

  • Engagement: W2 only; no C2C or 1099 arrangements.
  • Hybrid position based in Charlotte, North Carolina.
  • Opportunity to develop sophisticated threat detections across cloud and on-premises environments.
  • Exposure to security analytics, detection-as-code, automation, MITRE ATT&CK, and modern security monitoring technologies.
  • Collaboration with global cybersecurity, threat intelligence, incident response, and technology teams.
  • Opportunity to directly improve the organization’s ability to identify and respond to emerging cyber threats.

How You Will Make an Impact

  • Design, develop, test, tune, and maintain threat detection logic across cloud and on-premises environments.
  • Improve alert quality, monitoring visibility, and the organization’s ability to detect and respond to malicious activity.
  • Build and maintain log onboarding and data-ingestion processes for endpoint, network, identity, cloud, application, and infrastructure telemetry.
  • Translate threat intelligence, attacker behaviors, and indicators of compromise into actionable monitoring use cases.
  • Develop correlation rules, behavioral analytics, signatures, alert thresholds, and detection content that reduce false positives.
  • Partner with SOC analysts and incident responders to investigate alerts, validate detection effectiveness, and identify coverage gaps.
  • Map detection logic and security-monitoring coverage to the MITRE ATT&CK framework.
  • Apply scripting, automation, and detection-as-code practices to improve testing, deployment, scalability, and lifecycle management.
  • Evaluate security data sources, analytics capabilities, and monitoring technologies to identify opportunities for improvement.
  • Maintain documentation covering detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
  • Ensure detection-engineering practices align with regulatory obligations, internal controls, and cybersecurity standards.
  • Assess the effectiveness of monitoring controls and recommend practical improvements that strengthen cyber resilience.

Do You Bring Proven Success in Threat Detection and Security Analytics?

  • At least 3 years of experience in detection engineering, SOC engineering, security analytics, cybersecurity operations, or a related discipline.
  • Hands-on experience analyzing logs and telemetry from endpoint, network, identity, cloud, infrastructure, and application platforms.
  • Experience working with SIEM, UEBA, EDR, SOAR, security data lakes, or comparable security-monitoring technologies.
  • Strong knowledge of security query languages and data-analysis methods used to investigate events and build detection logic.
  • Experience developing automation, scripts, detection-as-code pipelines, or repeatable security operations processes.
  • Ability to convert threat intelligence, adversary behaviors, and attack techniques into practical detections.
  • Experience mapping detections or security coverage to MITRE ATT&CK or a similar framework.
  • Working knowledge of Windows, Linux, enterprise infrastructure, and cloud environments.
  • Strong troubleshooting, analytical, and root-cause analysis capabilities.
  • Ability to independently manage operational responsibilities and project deliverables.
  • Clear written and verbal communication skills, including the ability to document technical detection logic and tuning decisions.
  • Strong ownership, attention to detail, and the ability to collaborate effectively within a global team.
  • Experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is preferred.


See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available