{"schemaVersion":"jobsearcher.job.v1","id":"f0a42db6eab683710d110ea7","url":"https://jobsearcher.com/jobs/f0a42db6eab683710d110ea7","canonicalUrl":"https://jobsearcher.com/jobs/f0a42db6eab683710d110ea7","title":"Detection Engineer","description":"About The RoleYou translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.What you will doBuild detections from real attacker behaviourMeasure each rule's false positive rate and own itHunt for what current detections would have missedWhat they ask forKnows what attacks look like in telemetry, not just in theoryQuery languages and a scripting languageWilling to delete your own rules when they stop earning their placeNice to havePurple team experienceSigma rulesIncident response background","company":"Rooted","rawCompany":"rooted","city":"Reston","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-23T08:16:00.945Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Detection Engineer","description":"About The RoleYou translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.What you will doBuild detections from real attacker behaviourMeasure each rule's false positive rate and own itHunt for what current detections would have missedWhat they ask forKnows what attacks look like in telemetry, not just in theoryQuery languages and a scripting languageWilling to delete your own rules when they stop earning their placeNice to havePurple team experienceSigma rulesIncident response background","datePosted":"2026-08-23T08:16:00.945Z","dateModified":"2026-08-23T08:16:00.945Z","hiringOrganization":{"@type":"Organization","name":"Rooted","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Reston","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f0a42db6eab683710d110ea7"},"url":"https://jobsearcher.com/jobs/f0a42db6eab683710d110ea7"}}