Skip to main content
Artemis

Detection Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
$100k–$160k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior detection engineer (5+ yrs cybersecurity) to own detection content across cloud, identity, endpoint and SaaS. Must be strong in Sigma/KQL/SPL/YARA-L, Python, MITRE ATT&CK, detection-as-code (Git/CI/CD), and AI-assisted detection authoring. Remote.

Core skills

SigmaPythonDetection Engineering

Required skills

KQLSPLYARA-LGitCI/CDAWSAzureGCPOktaEntra IDEDRMITRE ATT&CK

Optional skills

Atomic Red TeamUEBAML-based detection methods

What you'll do

  • Build and maintain the detection library - Design, implement, and own high-fidelity detections across cloud (AWS, Azure, GCP), identity (Okta, Entra ID), endpoint (EDR), and SaaS log sources, from hypothesis to production.
  • Practice detection-as-code - Manage detection content like software: version-controlled rules, peer review, automated validation and testing, and CI/CD deployment across customer environments.
  • Map and close coverage gaps - Measure detection coverage against MITRE ATT&CK, prioritize gaps based on real-world threat activity, and systematically close them.
  • Validate against real attacks - Build and run attack simulations and test harnesses to prove detections fire on true positives and stay quiet on benign activity, before and after they ship.
  • Tune relentlessly - Own false-positive and false-negative rates across the fleet: analyze detection performance data, tune noisy logic at the source, and sunset detections that no longer earn their keep.
  • Use AI to write detections at scale - Leverage AI throughout the detection lifecycle: use AI-assisted workflows to author, convert, test, and document rules faster than any traditional team could, and build the tooling that makes AI-generated detection content trustworthy enough to ship.
  • Build behavioral and anomaly-based detections - Go beyond static signatures: establish behavioral baselines of normal activity per environment (identity, cloud, SaaS usage patterns) and engineer anomaly detections that surface deviations — impossible travel, unusual privilege use, novel API activity — with high signal and low noise.
  • Engineer detections for AI-powered investigation - Design detections that produce rich, structured context so the Artemis platform can investigate and resolve cases autonomously.
  • Turn intelligence into detections - Translate threat intelligence, incident findings, and threat hunt results from our research and SOC teams into durable, behavioral detection logic.
  • Partner with the SOC and research teams - Close the loop with Apollo analysts and security researchers: use case outcomes and analyst feedback to drive detection improvements, and give them documentation that makes every alert investigable.
  • Support customer-specific tuning - Adapt and tune detection content to each customer's environment and business context, reducing noise without sacrificing coverage.

What they require

  • 5+ years of hands-on cybersecurity experience, with significant time in detection engineering
  • Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms
  • Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA-L, and comfort writing code (Python preferred) for automation and testing
  • Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry
  • Experience with detection-as-code workflows: Git, peer review, automated testing, and CI/CD for detection content
  • Experience using AI tools to accelerate detection authoring, tuning, or validation — and judgment about when AI-generated logic is ready to ship
  • Experience building behavioral or anomaly-based detections: establishing baselines of normal activity and engineering detections that flag meaningful deviations
  • Strong log-analysis skills and demonstrated ability to distinguish malicious activity from benign noise across diverse data sources
  • Clear written and verbal communication — able to document detection logic and explain coverage and trade-offs to engineers, analysts, and customers

Benefits

  • Make a real world impact. You'll lead the human layer of defense that protects real companies. Every standard you set and process you sharpen raises the quality of protection customers depend on.
  • Be challenged to be better than ever before. Our team includes some of the smartest and most driven people in the world. We guarantee you will learn more in 1 year here than 10 years in another place.
  • Push the boundaries of technology. Lead a SOC built on the most advanced AI capabilities in cybersecurity, where the platform automates detection, investigation, and tuning, and your team owns the expertise, response, and relationship. You'll define what a modern, AI-native MDR looks like.
  • Innovative culture. We obsess about customers, move fast with high quality, and value open communication, mentorship and learning. You'll have the autonomy to shape the direction of the operation and own outcomes, not just run a runbook.

Artemis builds an AI-native security platform for cybersecurity teams defending against AI-powered cyber threats.

CybersecurityStartup
$100k–$160k/yr