Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Cribl

Senior Threat Detection Engineer

Cribl

. Design, build, test, and tune detections as code (KQL) through a GitOps workflow .

Posted 10/7/2026full-timeRemote • United StatesSenior💰 $108,000 - $169,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in detection engineering and threat hunting, with strong capabilities in KQL and Python for building and maintaining detections as code. Proficient in incident response, log pipeline management, and collaboration across security and engineering teams.

Highest-signal resume keywords
Detection EngineeringThreat HuntingIncident ResponseKQL ProficiencyPython Programming

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection As CodeIncident InvestigationLog Pipeline ManagementData IngestionThreat Model AnalysisAdversary EmulationCI/CD AutomationGit-Based WorkflowsTelemetry AnalysisCoverage Analysis
Soft Skills
Technical WritingCollaborationMentoringProblem SolvingCommunication
Tools & Technologies
SIEMCribl StreamGitHub ActionsSigmaAI-Assisted Workflows
Certifications & Qualifications
GCIHGCDA
Industry Keywords
MITRE ATT&CKCloud SecuritySaaSIdentity ProvidersSecurity Operations

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformPython

About the role

Key responsibilities & impact
  • Design, build, test, and tune detections as code (KQL) through a GitOps workflow
  • Map detections to MITRE ATT&CK, identify coverage gaps, and prioritize investments based on the threat model
  • Review community and vendor rule releases such as Sigma and decide what to adopt, adapt, or skip
  • Reduce alert noise by tuning and retiring ineffective rules while tracking detection quality metrics
  • Plan and conduct hypothesis-driven threat hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry
  • Use adversary emulation to generate test events for detections
  • Convert hunt findings into durable detections, documentation, and backlog items
  • Participate in the incident response rotation during the initial 6–12 months
  • Triage, scope, contain, and investigate security incidents from first alert to closure
  • Run retrospectives and turn lessons into detections, playbook updates, and visibility fixes
  • Write and maintain incident response runbooks
  • Help own security log flow health, including onboarding sources, parsing, normalization, and monitoring data quality
  • Build and maintain Cribl Stream data pipelines to route, enrich, and reduce telemetry before SIEM ingestion
  • Maintain CI/CD and automation for the detection program, including GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and pull request review
  • Design processes, standards, and tools that help the team work effectively
  • Mentor teammates through code review, pairing, and documentation
  • Collaborate with IT, Infrastructure, Engineering, and GRC to improve visibility and detection coverage
  • Report to the Sr. Director, Security Engineering and Operations under the CISO

Requirements

What you’ll need
  • 5+ years in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response
  • Experience writing and maintaining detections as code in a modern SIEM
  • Strong Python skills and comfort with Git-based workflows, code review, and CI/CD
  • Strong KQL skills for writing detection queries
  • Working knowledge of MITRE ATT&CK and coverage analysis
  • Experience investigating incidents in cloud environments (AWS, GCP, and/or Azure), SaaS, and identity providers
  • Hands-on experience with log pipelines, including data ingestion, parsing, and troubleshooting
  • Ability to distinguish real signals from noise and determine when to escalate
  • Clear technical and non-technical writing skills for incident summaries, runbooks, and detection documentation
  • Routine use of AI in engineering work, with concrete examples of its impact on building, testing, or investigations
  • Bonus: experience with Cribl Stream or other telemetry pipeline tools
  • Bonus: experience with Sigma rules, adversary emulation (Atomic Red Team, Caldera, or similar), or purple teaming
  • Bonus: experience building agentic or AI-assisted workflows for security operations
  • Bonus: certifications such as GCIH, GCDA, or equivalent experience
  • Stand-by, on-call, or off-hours availability

Benefits

Comp & perks
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Short-term disability insurance
  • Life insurance
  • Paid holidays
  • Paid time off
  • Fertility treatment benefit
  • 401(k)
  • Equity
  • Cribl Corporate Bonus Program