Talent.com
This job offer is not available in your country.
Senior Detection Engineer - MITRE ATT&CK framework - XDR - EDR - AI - Cyber Security Startup - Remot

Senior Detection Engineer - MITRE ATT&CK framework - XDR - EDR - AI - Cyber Security Startup - Remot

CareerXperts ConsultingKollam, Kerala, India
5 hours ago
Job description

We’re seeking a Senior Detection Engineer to lead the next evolution of AI-augmented threat detection.

This role goes beyond traditional detection engineering : you’ll help improve and build our Detection Engineering Agent , responsible for continuously grading and improving detection coverage based on a customer’s available telemetry, configuration, and behavioral baselines.

You’ll work across multi-cloud , hybrid , and data-lake environments to design modular detections that don’t depend on centralized data storage, but instead leverage federated queries, metadata scoring, and AI-based prioritization.

The ideal candidate combines deep hands-on SIEM expertise with a product mindset : able to design scalable detection pipelines, integrate AI feedback, and quantify detection efficacy at enterprise scale.

Key Responsibilities

Design and maintain modular, high-fidelity detections using Sigma, KQL, SPL, Lucene, and other rule / query languages for Sentinel, Splunk, Chronicle, Elastic, and data-lake environments (Snowflake, BigQuery, Databricks).

Build and evolve Detection Engineering Agent , enabling real-time tracking, grading, and ranking of a customer’s environment based on data coverage, signal quality, and rule performance.

Develop detections that operate without centralized storage , leveraging federated queries, streaming analytics, and metadata summarization instead of raw data ingestion.

Quantify coverage gaps across identity, endpoint, cloud, network, and SaaS telemetry; collaborate cross-functionally to enhance observability and threat visibility.

Integrate AI and ML models for automated rule tuning, false positive reduction, and behavioral correlation.

Implement feedback-driven rule lifecycle management , including performance tracking (TP / FP / FN), version control, and graceful rule deprecation or promotion.

Collaborate with SOC, data science, and platform teams to continuously improve detection quality and automate enrichment or response actions via SOAR platforms.

Manage detection-as-code pipelines , ensuring CI / CD integration, modular content reuse, and full traceability of changes.

Required Skills

5+ years of experience in detection engineering, threat hunting, and SOC operations .

Expertise in at least two major SIEMs (Sentinel, Google SecOps / Chronicle, Splunk) and data-lake query environments (Snowflake / Databricks).

Strong command of Sigma, KQL, SPL, or Lucene , with the ability to abstract detection logic into environment-agnostic templates.

Experience with federated detection queries and data modeling for environments without long-term log storage.

Familiarity with AI / ML-driven prioritization for detection scoring, clustering, or environment-based tuning.

Ability to handle diverse telemetry : cloud (AWS / Azure / GCP), IAM, EDR, firewall, Windows event logs, network, and SaaS platforms.

Experience in GitOps / detection-as-code workflows with version control, testing, and deployment pipelines.

Excellent communication and documentation skills with a focus on translating technical detections into product-ready content.

Nice to Have

Experience building or contributing to detection optimization or coverage grading frameworks .

Scripting in Python or PowerShell for automation, enrichment, and testing.

Familiarity with SOAR integration , purple teaming frameworks , and automated response orchestration .

Background in AI / ML model feedback integration for detection scoring or prioritization.

Connect to me at rajeshwari.vh@careerxperts.com for more details.

Create a job alert for this search

Engineer Framework • Kollam, Kerala, India

Related jobs
  • Promoted
Security Researcher

Security Researcher

Altered SecurityThiruvananthapuram, IN
Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information secu...Show moreLast updated: 30+ days ago
  • Promoted
L3 Server Engineer – Major Incident Management

L3 Server Engineer – Major Incident Management

Nextbridge IT SolutionsAlappuzha, IN
Nextbridge IT Solutions is a US-based IT solution firm specializing in connecting exceptional talent with organizations driving transformation in infrastructure, cloud, and emerging technologies.We...Show moreLast updated: 23 days ago
  • Promoted
  • New!
Workday Security System Analyst

Workday Security System Analyst

AvalaraKollam, IN
Avalara is an AI-first company.We expect every engineer, manager, and to actively leverage AI to enhance productivity, quality, innovation, and customer value. AI is embedded in our workflows, and p...Show moreLast updated: 16 hours ago
  • Promoted
  • New!
Security Architect

Security Architect

Tata Consultancy Servicesalappuzha, kerala, in
Experience in datacentre, cloud and network.Hands-on experience in AWS and GCP cloud.Experience in Containers, Kubernetes and micro services. Experience in advance networking in public cloud.Terrafo...Show moreLast updated: 14 hours ago
  • Promoted
Chief Artificial Intelligence Solutions Architect

Chief Artificial Intelligence Solutions Architect

beBeeAIEngineerThiruvananthapuram, Kerala, India
We are seeking an experienced Senior AI Engineer to join our team.As a key member of our engineering group, you will be responsible for designing, developing, and implementing large language models...Show moreLast updated: 1 day ago
  • Promoted
  • New!
CyberArk Engineer

CyberArk Engineer

Next VenturesThiruvananthapuram, IN
Job Opportunity : CyberArk Engineer.Contract / Permanent / Fixed Term.Privileged Access Management (PAM) implementations using CyberArk technologies. CyberArk Core-PAS, AAM, PTA, HTML5 Gateway.AUTOIT...Show moreLast updated: 16 hours ago
  • Promoted
  • New!
Cyber Security Engineer

Cyber Security Engineer

Nexoria Techworks Inc.thiruvananthapuram, kerala, in
Job Description : Cybersecurity Engineer.Cybersecurity, Information Security, Threat Management.Your core responsibilities will include : . Implement security measures to proactively identify and mitig...Show moreLast updated: 14 hours ago
  • Promoted
  • New!
Tripwire Cyber Security Expert

Tripwire Cyber Security Expert

RapidBrainsThiruvananthapuram, IN
Bachelor’s degree in Computer Science, Information Security, or related field.SIEM, vulnerability management, endpoint security, and compliance frameworks. Familiarity with Windows and Linux environ...Show moreLast updated: less than 1 hour ago
  • Promoted
IAM Engineer (CIAM)

IAM Engineer (CIAM)

PerfictKollam, IN
The IAM Senior Engineer will be responsible for the service design, build and documentation all key elements of Client Customer IAM and Certificate Lifecycle Management supporting infrastructure an...Show moreLast updated: 11 days ago
  • Promoted
  • New!
Vulnerability Management Specialist_9+years_Remote

Vulnerability Management Specialist_9+years_Remote

Tekgence IncThiruvananthapuram, IN
Remote
Job Title : Vulnerability Management Specialist (AWS & Wiz).Duration : 12+ months , extendable.We are seeking a skilled Vulnerability Management Specialist with hands-on experience in AWS environment...Show moreLast updated: 16 hours ago
  • Promoted
  • New!
EMC Networker Backup Engineer (Riyadh, Saudi based)

EMC Networker Backup Engineer (Riyadh, Saudi based)

FR Consultancy (Middle East)Alappuzha, IN
Backup Engineer (EMC Networker) - L3.Family members, Insurance and other benefits.Provide L3-level support in a mission-critical banking environment. Lead major incidents / war rooms; guide L1 / L2; pro...Show moreLast updated: 16 hours ago
  • Promoted
Cyber Security Engineer

Cyber Security Engineer

Paramount Computer SystemsAlappuzha, IN
Identity Governance and Administration (IGA).The role involves designing, implementing, and supporting enterprise-grade IGA solutions to ensure secure, efficient, and compliant identity lifecycle m...Show moreLast updated: 11 days ago
  • Promoted
  • New!
Network Security Engineer (Zeek / Suricata / Elastic- OT / Network Focus)

Network Security Engineer (Zeek / Suricata / Elastic- OT / Network Focus)

Microminder Cyber SecurityThiruvananthapuram, IN
We are looking for a Network Security Engineer with experience in deploying and managing open-source network security platforms. The role involves setting up visibility sensors, handling network tra...Show moreLast updated: 16 hours ago
  • Promoted
  • New!
Cyber Security Architect

Cyber Security Architect

Tata Consultancy Serviceskollam, kerala, in
In depth knowledge of IAM for AWS.Architect and automate the management of AWS Cloud IAM services.Support the Identity and Access Management team within the Technology Risk & Information Security O...Show moreLast updated: 14 hours ago
  • Promoted
Cyber Security Consultant

Cyber Security Consultant

Paramount Computer SystemsKollam, Kerala, India
As a IAM Consultant in Access Management, your role will involve : .Designing, implementing, optimizing and supporting identity and access management (IAM) solutions for enterprise clients.Your exper...Show moreLast updated: 1 day ago
  • Promoted
  • New!
Network Security Technician

Network Security Technician

Wimmer SolutionsThiruvananthapuram, IN
At Wimmer Solutions, we believe care creates community.We work smart; we have built a reputation for results-oriented, innovative, business and technology solutions that help companies execute on t...Show moreLast updated: less than 1 hour ago
  • Promoted
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

SentinelAlappuzha, IN
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA).The security function of a world renowned manufacturing organisation for power tools is seeking a Saviynt IGA Engineer ...Show moreLast updated: 15 days ago
  • Promoted
Quantiphi - Senior Cyber Security Engineer - DAST / SAST

Quantiphi - Senior Cyber Security Engineer - DAST / SAST

Quantiphi AnalyticsThiruvananthapuram
Role : Senior Cyber Security Engineer.Experience Level : 3+ Years.Work location : Mumbai, Bangalore & Trivandrum.Role & Responsibilities : ...Show moreLast updated: 30+ days ago
  • Promoted
Senior Penetration Tester

Senior Penetration Tester

Vista Applied Solutions Group IncAlappuzha, IN
Client is looking for Senior PenTester and this is remote position from India.Security and Penetration Testing.OSCP Certification - Industry-standard credential demonstrating practical penetration ...Show moreLast updated: 11 days ago
  • Promoted
  • New!
UKG Ready Implementation Specialist

UKG Ready Implementation Specialist

TechnoidLLCAlappuzha, IN
UKG Ready Implementation Specialist – Benefits & Payroll Integration (Contract / Consulting Role).Time- US SHIFT HOURS (6 : 30 PM IST- 3 AM IST). UKG Ready Implementation Specialist.The ideal candidate ...Show moreLast updated: less than 1 hour ago