Role: Threat Detection Engineer
Rate: ***/hour all inclusive
Location: New York, NY or Pittsburgh, PA (ON SITE ROLE, LOCAL CANDIDATES PREFERRED) US
Description:
The Threat Detection Engineer will develop and enhance enterprise threat detection capabilities across security monitoring platforms. This role will focus on creating advanced detection logic, threat hunting, incident identification, security analytics, and monitoring of both traditional and AI-enabled environments. The engineer will work closely with SOC, cyber defense, and threat intelligence teams to improve detection coverage and reduce organizational cyber risk.
Key Responsibilities
Develop and tune SIEM detection use cases and correlation rules.
Perform proactive threat hunting and behavioral analytics.
Create and maintain security monitoring content.
Investigate emerging threats and map detections to MITRE Telecommunication&CK.
Improve detection coverage for cloud, endpoint, and network environments.
Build automated response workflows and security analytics dashboards.
Support detection strategies for AI, GenAI, and LLM-based technologies.
Key Responsibilities
AI / Agentic Systems Development
Design and implement agentic workflows (ReAct, multi-agent orchestration, tool-augmented agents)
Build autonomous or semi-autonomous AI agents to handle development, testing, and operational workflows
Integrate agents with enterprise systems (Jira, Git, ServiceNow, APIs, etc.)
RAG & Knowledge
Build and optimize Retrieval-Augmented Generation (RAG) pipelines
Work with vector databases, embeddings, document chunking, indexing, retrieval tuning
Enable enterprise knowledge use cases (e.g., FAQ bots, nuggets/knowledge artifacts, AI copilots)
Implement evaluation frameworks for LLMs:
Functional correctness
Response quality
Hallucination detection
Experience with AI testing frameworks (e.g., RAGAS, DeepEval, custom evaluation harnesses)
Build scalable APIs/services (FastAPI, Flask, etc.)
Ensure performance, observability, and reliability of AI systems
Primary Skills
Threat Detection Engineering (SIEM/EDR)
Splunk & Security Analytics
Threat Hunting & Incident Response
Secondary Skills
Security Automation (SOAR)
AI Security & GenAI Monitoring
Experience
7+ years of cybersecurity and security operations experience.
Hands-on experience with Splunk, Sentinel, QRadar, or similar SIEM tools.
Experience building detection content and threat-hunting methodologies.
Familiarity with cloud security, EDR technologies, and MITRE Telecommunication&CK framework.?