FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in detection engineering and threat hunting, with strong capabilities in KQL and Python for building and maintaining detections as code. Proficient in incident response, log pipeline management, and collaboration across security and engineering teams.
Highest-signal resume keywords
Detection EngineeringThreat HuntingIncident ResponseKQL ProficiencyPython Programming
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Detection As CodeIncident InvestigationLog Pipeline ManagementData IngestionThreat Model AnalysisAdversary EmulationCI/CD AutomationGit-Based WorkflowsTelemetry AnalysisCoverage Analysis
Soft Skills
Technical WritingCollaborationMentoringProblem SolvingCommunication
Tools & Technologies
SIEMCribl StreamGitHub ActionsSigmaAI-Assisted Workflows
Certifications & Qualifications
GCIHGCDA
Industry Keywords
MITRE ATT&CKCloud SecuritySaaSIdentity ProvidersSecurity Operations
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformPython
About the role
Key responsibilities & impact- Design, build, test, and tune detections as code (KQL) through a GitOps workflow
- Map detections to MITRE ATT&CK, identify coverage gaps, and prioritize investments based on the threat model
- Review community and vendor rule releases such as Sigma and decide what to adopt, adapt, or skip
- Reduce alert noise by tuning and retiring ineffective rules while tracking detection quality metrics
- Plan and conduct hypothesis-driven threat hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry
- Use adversary emulation to generate test events for detections
- Convert hunt findings into durable detections, documentation, and backlog items
- Participate in the incident response rotation during the initial 6–12 months
- Triage, scope, contain, and investigate security incidents from first alert to closure
- Run retrospectives and turn lessons into detections, playbook updates, and visibility fixes
- Write and maintain incident response runbooks
- Help own security log flow health, including onboarding sources, parsing, normalization, and monitoring data quality
- Build and maintain Cribl Stream data pipelines to route, enrich, and reduce telemetry before SIEM ingestion
- Maintain CI/CD and automation for the detection program, including GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and pull request review
- Design processes, standards, and tools that help the team work effectively
- Mentor teammates through code review, pairing, and documentation
- Collaborate with IT, Infrastructure, Engineering, and GRC to improve visibility and detection coverage
- Report to the Sr. Director, Security Engineering and Operations under the CISO
Requirements
What you’ll need- 5+ years in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response
- Experience writing and maintaining detections as code in a modern SIEM
- Strong Python skills and comfort with Git-based workflows, code review, and CI/CD
- Strong KQL skills for writing detection queries
- Working knowledge of MITRE ATT&CK and coverage analysis
- Experience investigating incidents in cloud environments (AWS, GCP, and/or Azure), SaaS, and identity providers
- Hands-on experience with log pipelines, including data ingestion, parsing, and troubleshooting
- Ability to distinguish real signals from noise and determine when to escalate
- Clear technical and non-technical writing skills for incident summaries, runbooks, and detection documentation
- Routine use of AI in engineering work, with concrete examples of its impact on building, testing, or investigations
- Bonus: experience with Cribl Stream or other telemetry pipeline tools
- Bonus: experience with Sigma rules, adversary emulation (Atomic Red Team, Caldera, or similar), or purple teaming
- Bonus: experience building agentic or AI-assisted workflows for security operations
- Bonus: certifications such as GCIH, GCDA, or equivalent experience
- Stand-by, on-call, or off-hours availability
Benefits
Comp & perks- Health insurance
- Dental insurance
- Vision insurance
- Short-term disability insurance
- Life insurance
- Paid holidays
- Paid time off
- Fertility treatment benefit
- 401(k)
- Equity
- Cribl Corporate Bonus Program
