Logo for Binary Defense

Detection Engineer - REMOTE

Role overview

Qualifications

  • 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows
  • Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL

Responsibilities

  • Design and implement detections using a detection-as-code approach across SIEM and EDR platforms
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control
  • Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors

Key facts

  • Remote from: Texas (USA)
  • Full time
  • Senior (5-10 years)
  • English

Other skills

  • Collaboration
  • Problem Solving
  • Adaptability

About the company

Binary Defense logo

Binary Defense

Cybersecurity

Founded in 2014 by the industry’s top cybersecurity experts, Binary Defense is on a mission to change the security industry for the better and help organizations defend against threats of all kinds. We believe that the best defense against cyber threats uses a human-driven, technology-assisted approach. We protect businesses of all sizes through our advanced cybersecurity solutions including Managed Detection and Response, Threat Hunting, Digital Risk Protection, Incident Response, Phishing Response, and Analysis on Demand. Binary Defense was spawned from the need for better monitoring and detection capabilities in companies. The founder of Binary Defense, David Kennedy, also founded TrustedSec which specializes in information security services including penetration testing. The cutting edge, white hat hackers noticed almost every organization with monitoring capabilities really struggled, especially when using an MSSP. Countless attacks went undetected, and breaches were missed which left companies wondering what to do. As a result, Binary Defense was first put into motion in July of 2012 with the development of our Managed Detection, Deception and Response software (Binary Defense Vision) based on profiling how attackers think. A number of years of development, marrying up attack intelligence with our extensive threat intelligence, has made our product the best consolidation of technologies in the industry to predict, prevent, detect, deceive and respond to attacks.

Company details

Company typeSME
IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Type
Full-time
Description


Binary Defense is seeking  an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You’ll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.
 

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.


Responsibilities


· Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).

· Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.

· Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs.

· Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.

· Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.

· Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.

· Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.

· Support documentation of detection logic, coverage rationale, and response guidance.

· Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Requirements

  

· 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response.

· Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.

· Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.

· Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.

· Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.

· Ability to quickly learn new security technologies and adapt detection strategies accordingly.

· Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.


Preferred


· Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).

· Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).

· Exposure to multi-tenant or MDR environments and scaling detections across customer environments.

· Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.

· Experience in IR consulting and working across diverse EDR/SIEM stacks.


About Binary Defense


Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.


For more information, visit our website, check out our blog, or follow us on LinkedIn.


Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Binary Defense

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.