Threat-Led Detection Engineer
This role involves designing, building, and maintaining high-fidelity threat detections across SIEM, EDR/XDR, cloud, identity, and network environments using a threat-led approach. The engineer will map detections to frameworks like MITRE ATT&CK, tune rules to reduce false positives, and collaborate with SOC, threat hunting, and incident response teams. Emphasis is placed on Detection-as-Code practices, adversary emulation, and integrating AI/automation into detection workflows.