CronJobs

security jobs

Senior Threat Detection Engineer

Cribl · Remote - United States

remotesenior$108,000–$108,000Posted Oct 7, 2026PythonKQLGitGitHub ActionsCI/CDMITRE ATT&CKAWSGCP

Apply on the employer site

About this role

**Join the company that’s building the telemetry infrastructure for the AI era.** Cribl partners with IT and Security teams at many of the world’s biggest enterprises to bridge the gap between AI ambition and infrastructure reality. As the AI Platform for Telemetry, we give customers the choice, control, and flexibility to manage and analyze telemetry for both humans and agents. --- ## Why You’ll Love This Role Cribl builds telemetry infrastructure for some of the world’s biggest security teams—and now we’re looking for someone to protect Cribl itself. You’ll join **Cribl’s internal security team (Team Alpine)** to run **detection as code**. Our pipeline keeps rules in Git, tests them in CI, and deploys to our SIEM automatically. AI agents help watch for coverage gaps and support review of every change. This is a hands-on senior role covering the whole detection lifecycle: hunt for threats nobody has written a rule for yet, turn findings into detections, and keep the log pipelines behind those detections healthy. For the first **[6–12] months**, you’ll also be a core part of our incident response rotation while we build out that function. --- ## As an Active Member of Our Team, You Will… ### Detection Engineering - Design, build, test, and tune **detections as code (KQL)** through a **GitOps** workflow (issue → pull request → unit/back-testing → automated deployment) - Map detections to **MITRE ATT&CK**, find coverage gaps, and decide where to invest next based on our threat model - Review new community and vendor rule releases (e.g., **Sigma**) and decide what to adopt, adapt, or skip - Cut alert noise by tuning and retiring rules that no longer earn their place; track detection quality metrics ### Threat Hunting - Plan and run hypothesis-driven hunts across **cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry** - Use adversary emulation to generate test events for detections that have nothing to fire on yet - Turn hunt findings into durable detections, documentation, and backlog items ### Incident Response (initial [6–12] months) - Participate in the IR rotation: triage, scope, contain, and investigate security incidents from first alert to closure - Run retrospectives and turn lessons into new detections, playbook updates, and fixes to visibility gaps - Write and maintain runbooks so others on the team can respond consistently ### Detection Infrastructure & Log Pipelines - Assist in ownership of the health of security log flow: onboard new sources, maintain parsing/normalization, and monitor for dropped/delayed/malformed data - Assist and build/maintain data pipelines with **Cribl Stream** to route, enrich, and reduce telemetry before it reaches the SIEM - Maintain CI/CD and automation behind the detection program (e.g., **GitHub Actions**, SIEM API integrations, and AI-assisted gap analysis + PR review) ### Across the Team - Work independently and help design processes, standards, and tools that enable others - Mentor teammates through code review, pairing, and clear documentation - Partner with IT, Infrastructure, Engineering, and GRC to close visibility gaps and improve detection coverage - This position will require stand-by, on-call, or off-hours duties --- ## If You’ve Got It — We Want It - **5+ years** in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response - Experience writing and maintaining detections as code in a modern SIEM -

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord