Descripción y requisitos
We are seeking a Senior Detection Engineer to advance our detection engineering strategy within the Enterprise Security team. This role is essential to safeguarding EA’s cloud and production environments and will directly impact our ability to detect, respond to, and prevent cyber threats at scale.
As a senior individual contributor reporting to the Director of Threat Intelligence and Detections, you will play a central role in the technical leadership of the Detection Engineering team. You’ll mentor junior engineers, help define engineering direction, and lead the development of scalable, innovative threat detection solutions—including those leveraging AI and cloud-native technologies.
This is a unique opportunity to contribute to EA’s most strategic cybersecurity initiatives, including cloud and container security, network visibility, and the evolution of our detection lifecycle governance.
Key Responsibilities
Technical Leadership
Design, develop, and operationalize advanced detections across cloud, container, and on-prem environments.
Build integrations for diverse data sources (e.g., Wiz, host telemetry, network sensors) into EA’s detection infrastructure.
Define and implement detection lifecycle processes to ensure maturity, governance, and performance metrics.
Lead development of AI-driven detection proof-of-concepts
Mentorship & Collaboration
Provide technical mentorship to more junior engineers, supporting their professional development and elevating team output.
Guide peers in building scalable, maintainable detection infrastructure and tuning detection content.
Serve as a key technical liaison with cross-functional teams to align engineering initiatives with broader platform and production security goals.
Strategic Execution
Own and execute major goals tied to EA’s cyber defense strategy.
Support strategic priorities like product detection assessments, threat-led risk prioritization, and production telemetry uplift.
Minimum Qualifications
Experience in detection engineering, security engineering, or software development with a focus on cybersecurity.
Proven experience developing detections and integrations within SIEM platforms (e.g., Splunk, Elastic, QRadar), ideally making use of Risk Based Alerting.
Strong skills in Python and JavaScript, with familiarity in NodeJS and Kubernetes environments.
Familiarity with cybersecurity frameworks (e.g., MITRE ATT&CK, Cyber Kill Chain, NIST CSF).
Excellent communication skills with the ability to lead technical discussions and influence cross-functional partners.
Preferred Qualifications
Experience with cloud security platforms (e.g., Wiz) and integrating their outputs into detection pipelines.
Background in AI/ML or data science applied to cybersecurity detections.
Deep understanding of cloud-native architectures, container security, and host-based detection.
Experience leading PoCs or greenfield development initiatives in a complex security ecosystem.
Demonstrated success mentoring junior engineers in a non-managerial capacity.