설명 및 참여 요건
The Security Detections Engineer is responsible for designing, building and continuously improving EA's detection and response capabilities across our global environment. This role owns the end-to-end detection lifecycle-from threat-informed use case design through validation, tuning, and operational handoff, while also developing automation that reduces engineering toil and increases speed and consistency in mitigating risks as they are discovered.
You will work closely with Security Operations (SOC) to produce meaningful alerts that mitigate risk, and with Security Engineering to evolve the automation platforms and integrations that enable scalable content delivery, enrichment, correlation, and noise reduction across EA's security tooling.
This position also contributes to EA's AI-assisted detection roadmap by implementing practical, governed approaches to applying ML/LLM techniques for threat intel consumption, detection candidate creation and data prioritisation, always with an emphasis on measurable outcomes, auditability and safety.
To be successful in this role you will be someone who operates with high agency and strong ownership; able to identify problems, propose pragmatic solutions, and execute with minimal direction. You should be comfortable taking ambiguous requirements and turning them into a clear plan, driving work end-to-end, and proactively communicating progress, risks, and trade-offs without needing close supervision. This role suits a self-starter who consistently looks for leverage: improving detection quality, reducing analyst toil through automation, and raising the team's operational maturity through better validation, documentation, and repeatable processes.
Required Skills and Experience:
- Demonstrated experience in security detection engineering in an enterprise environment
- Proficiency in automation development (Python preferred) and building/consuming APIs (REST, auth patterns, secrets handling)
- Experience building detection logic using endpoint and/or cloud telemetry, with a strong grasp of attacker tradecraft and common compromise chains
- Ability to design validation approaches and measure detection performance (precision/noise reduction) using data-driven methods
- Experience with security automation (SOAR) a plus
- Strong communication and collaboration skills