Axiom Path

Cybersecurity Detection Engineer x2

Axiom Path Charlotte, North Carolina, United States

IT Services and IT Consulting · 51-200 employees

4 h ago
security Mid (2-5 yrs) Contractor United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Design, develop, and maintain threat detection logic across cloud and on-premises environments to improve monitoring visibility. Collaborate with SOC analysts and incident responders to validate detection effectiveness and translate threat intelligence into actionable use cases.

What they look for

Threat Detection Security Analytics Detection Engineering SIEM UEBA EDR SOAR MITRE ATT&CK Automation Detection-as-code Log Analysis Incident Response Threat Intelligence Cloud Security Scripting Data Analysis

Requirements

Requires at least 3 years of experience in detection engineering, security analytics, or cybersecurity operations. Candidates must have hands-on experience with SIEM, EDR, and security data analysis, along with proficiency in scripting and mapping detections to the MITRE ATT&CK framework.

Full description

Be Part of a High-Performing Team

Join a global financial services organization committed to maintaining resilient, secure, and highly regulated technology operations. The cybersecurity organization protects complex cloud and on-premises environments by strengthening monitoring, threat detection, and incident response capabilities.

This position supports a collaborative Security Operations team that works closely with SOC analysts, incident responders, threat intelligence specialists, security engineers, and technology partners. The environment is fast-paced and analytical, with a strong emphasis on measurable detection coverage, automation, operational excellence, and continuous improvement.

What s In Store For You

  • Engagement: W2 only; no C2C or 1099 arrangements.
  • Hybrid position based in Charlotte, North Carolina.
  • Opportunity to develop sophisticated threat detections across cloud and on-premises environments.
  • Exposure to security analytics, detection-as-code, automation, MITRE ATT&CK, and modern security monitoring technologies.
  • Collaboration with global cybersecurity, threat intelligence, incident response, and technology teams.
  • Opportunity to directly improve the organization s ability to identify and respond to emerging cyber threats.

How You Will Make an Impact

  • Design, develop, test, tune, and maintain threat detection logic across cloud and on-premises environments.
  • Improve alert quality, monitoring visibility, and the organization s ability to detect and respond to malicious activity.
  • Build and maintain log onboarding and data-ingestion processes for endpoint, network, identity, cloud, application, and infrastructure telemetry.
  • Translate threat intelligence, attacker behaviors, and indicators of compromise into actionable monitoring use cases.
  • Develop correlation rules, behavioral analytics, signatures, alert thresholds, and detection content that reduce false positives.
  • Partner with SOC analysts and incident responders to investigate alerts, validate detection effectiveness, and identify coverage gaps.
  • Map detection logic and security-monitoring coverage to the MITRE ATT&CK framework.
  • Apply scripting, automation, and detection-as-code practices to improve testing, deployment, scalability, and lifecycle management.
  • Evaluate security data sources, analytics capabilities, and monitoring technologies to identify opportunities for improvement.
  • Maintain documentation covering detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
  • Ensure detection-engineering practices align with regulatory obligations, internal controls, and cybersecurity standards.
  • Assess the effectiveness of monitoring controls and recommend practical improvements that strengthen cyber resilience.

Requirements

Do You Bring Proven Success in Threat Detection and Security Analytics?

  • At least 3 years of experience in detection engineering, SOC engineering, security analytics, cybersecurity operations, or a related discipline.
  • Hands-on experience analyzing logs and telemetry from endpoint, network, identity, cloud, infrastructure, and application platforms.
  • Experience working with SIEM, UEBA, EDR, SOAR, security data lakes, or comparable security-monitoring technologies.
  • Strong knowledge of security query languages and data-analysis methods used to investigate events and build detection logic.
  • Experience developing automation, scripts, detection-as-code pipelines, or repeatable security operations processes.
  • Ability to convert threat intelligence, adversary behaviors, and attack techniques into practical detections.
  • Experience mapping detections or security coverage to MITRE ATT&CK or a similar framework.
  • Working knowledge of Windows, Linux, enterprise infrastructure, and cloud environments.
  • Strong troubleshooting, analytical, and root-cause analysis capabilities.
  • Ability to independently manage operational responsibilities and project deliverables.
  • Clear written and verbal communication skills, including the ability to document technical detection logic and tuning decisions.
  • Strong ownership, attention to detail, and the ability to collaborate effectively within a global team.
  • Experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is preferred.

Similar roles