JOBSEARCHER

Senior Security Engineer, Detection Engineering

NVIDIASpringfield, MOL6 LeadSeptember 15th, 2026
Overview In this role, you will help build reliable detection coverage that enables responders to identify real threats quickly while reducing noise. You’ll work with incident response, threat intelligence, and security operations to turn signals into credible detections across enterprise, cloud, and developer environments. You will move from hypothesis to tested production content, explaining tradeoffs clearly. This position offers the chance to shape detection quality and impact across multiple platforms and teams. Compensation / Benefitsequitybenefitsremote-friendly ResponsibilitiesDesign and fine-tune high-confidence detections across platforms (Splunk, Microsoft Sentinel/Defender, CrowdStrike, cloud logs, identity telemetry, endpoints, SaaS, and developer systems).Translate incidents, hunts, threat intel, red-team findings, and vulnerability context into testable detection logic.Investigate telemetry before alerting, focusing on field behavior, timing, baselines, joins, and false positives.Own the full detection lifecycle: design, development, validation, peer review, deployment, tuning, monitoring, and retirement.Strengthen detection-as-code workflows with test data, metadata, rollout safety, coverage tracking, and health reporting.Collaborate with responders to reduce noise, add context, and refine severity and follow-up detections.Shape logging, enrichment, and retention requirements when telemetry is missing or difficult to use.Coach analysts and engineers through design and query reviews, providing guidance on detection credibility. Key requirements8+ years in detection engineering, security engineering, threat hunting, or related rolesDegree in Computer Science, Cybersecurity, Engineering, or equivalent experienceHands-on detection development in a major SIEM or security analytics platformStrong query/scripting skills (SPL, KQL, SQL, Python, or equivalent)Understanding of attacker behavior across identity, endpoints, cloud, network, email, collaboration, developers, secrets, and data theftAbility to translate raw logs into production-ready detections with field semantics, thresholds, joins, baselines, and triage contextExperience with Git, code reviews, CI/CD, documentation, and operational ownership of contentClear communication and sound judgment about what to alert and what to omitclear communicationsound judgmentcross-functional collaborationSPLKQLSQL