Skip to main content
Dropzone AI

Detection Engineering Lead

RemoteUnited States only
Published
Role
Security
Experience
Principal
Employment
Full-time
Company size
Startup
$200k–$250k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior/principal detection engineer with 5+ years in detection engineering and deep expertise in at least two major SIEM platforms. Must know MITRE ATT&CK, adversary emulation, detection coverage analysis, and telemetry across endpoint, cloud, identity, network, and SaaS. Remote US role for someone who can turn expert detection knowledge into AI-driven security product work.

Core skills

SIEMMITRE ATT&CK

Required skills

Microsoft Sentinel/Splunk/QRadar/Elastic/Chronicle/Sumo Logic

Optional skills

EDRCrowdStrikeMicrosoft DefenderSentinelOnePalo Alto Cortex XDRAWSAzureGCP

What you'll do

  • Serve as one of Dropzone AI's foremost experts in adversary tradecraft, threat detection, detection efficacy evaluation, and SIEM content.
  • Work closely with product management and engineering teams to ensure the AI detection engineer can draft new detection contents and improve existing detection rules as well as the best detection engineer on the planet.
  • Focus on building software that replicates expert detection intuitions and techniques.
  • Reimagine how having unlimited detection engineering capacity could change Detection and Response teams and how future security practitioners interact with an AI detection engineer.
  • Prototype, validate, and continuously improve an AI agent that programmatically generates detection content across diverse security environments.
  • Experiment autonomous agentic loops between detection engineering and other D&R functions such as threat intelligence and threat hunting.
  • Partner with engineering teams to encode expert detection knowledge into the product.
  • Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and SaaS security platforms.
  • Provide guidance on detection methodologies used by mature SOCs.
  • Establish best practices for detection quality, tuning, testing, and lifecycle management.
  • Influence product roadmap decisions based on customer and operational needs.
  • Stay current on emerging threats, attacker techniques, and defensive strategies.
  • Conduct original research into detection opportunities and gaps.
  • Develop novel approaches for AI-assisted threat detection.

What they require

  • 5+ years of experience in detection engineering.
  • Deep expertise with two or more major SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, Chronicle, Sumo Logic, etc.).
  • Strong understanding of endpoint, cloud, identity, network, and SaaS telemetry.
  • Expertise in MITRE ATT&CK, adversary emulation, and detection coverage analysis.
  • Experience building and tuning high-fidelity detections at scale.
  • Strong understanding of modern attacker tradecraft across Windows, Linux, cloud, identity, and SaaS environments.
  • Excellent communication skills with the ability to engage practitioners, executives, and customers.
  • Early-stage startup mindset.
  • You thrive on ambiguity and move with lightspeed execution.
  • Being data-driven is part of your DNA.
  • Preferred: Experience leading detection engineering programs at large complex environments.
  • Preferred: Public speaking, research publication, or conference presentation experience.
  • Semi-frequent travel to professional office settings and other events locally and nationally; some overnight travel expected.

Benefits

  • 100% remote company where you will work from your home with company-provided equipment to set you up for success.
  • Significant above market new hire equity grants.
  • Generous benefits package.
  • Company paid health insurance.
  • 401K Plan with employer match.
  • Self-Managed PTO.
  • Parental leave.

Dropzone’s mission is to scale cybersecurity beyond human limits, and augment every single human security engineer/analyst with an army of AI security specialists. Powered by Gen AI advancements, our technology offloads repetitive day-to-day work and frees human analysts to focus on real threats and higher-value projects.

CybersecurityStartup

Details

Apply routeGreenhouse
$200k–$250k/yr