Detection and Threat Engineer
Location: Remote
Compensation: Salary
Reviewed: Tue, Oct 06, 2026
This job expires in: 30 days
Job Summary
To enhance security monitoring capabilities, the remote Detection and Threat Engineer will develop advanced threat detections, write complex SPL queries, and implement Risk-Based Alerting methodologies while collaborating with various security teams.
Key responsibilities
- Develop and maintain advanced detection content within Splunk Enterprise Security and related security platforms
- Write complex SPL queries to identify threats and suspicious behaviors
- Design and optimize Risk-Based Alerting methodologies to improve detection fidelity
Required qualifications
- 4+ years of experience in Detection Engineering, Threat Detection, or Security Engineering
- Advanced experience writing SPL queries from scratch in Splunk
- Strong hands-on experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA)
- Knowledge of threat actor tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework
- Experience supporting SOC, Incident Response, or Threat Hunting functions
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 39,110 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee