Cyber Operations Senior Detection Engineer
AstraZeneca · Gaithersburg, MD · 3 wk ago
EngineeringFull-time
About the role
The Senior Detection Engineer is a technical specialist within the Global Security Operations Centre (GSOC), based in Gaithersburg, Maryland, working with the Director, Cyber Security Detection Engineering. The role is characterised by leadership of detection content development initiatives that protect enterprise assets across cloud, on-premises, and OT/ICS environments. Responsibility is held for the design, implementation, and optimisation of detection logic through which threats are identified, investigated, and mitigated with precision and efficiency.
Responsibilities
- Detection engineering initiatives: oversee detection engineering efforts across multiple projects spanning threat coverage, detection logic development, and efficacy validation; technical guidance is provided to ensure that detection capabilities address the most significant threats across all technology domains.
- Advanced detection frameworks and methodologies: implement detection engineering frameworks to enhance the organization's defensive posture through improved threat coverage, reduced false positives, and accelerated threat identification; industry guidelines for detection engineering are adopted and tailored to organizational requirements.
- Enterprise-wide detection content library development and management: design and optimize detection libraries to ensure comprehensive coverage of adversary tactics, techniques, and procedures as defined by frameworks such as MITRE ATT&CK; detection logic is developed that balances sensitivity with operational efficiency.
- Detection development oversight: provide technical guidance of detection development operations including coordination with external suppliers and platform vendors for comprehensive threat coverage; detection performance is monitored and issues are called out and resolved in collaboration with relevant collaborators.
- Proactive detection development and coverage management: proactively expand detection coverage through periodic assessments of threat landscape evolution, detection gaps, and emerging attack techniques; critical coverage deficiencies are identified and resolution is driven through systematic detection development.
- Stakeholder management: maintain engagement with security leadership to communicate emerging detection requirements driven by threat intelligence and incident findings; strategic action plans are proposed for addressing coverage gaps and enhancing detection capabilities.
- External partner relationship management: maintain and develop relationships with external partners, threat intelligence providers, and industry peers to identify innovative detection approaches and emerging techniques applicable to enterprise defense.
Qualifications
- Education: Bachelor's degree in information security, computer science, or related field (or equivalent experience).
- Technical expertise: At least five (5) years of experience in detection engineering, preferably within security operations centres or detection engineering teams; demonstrated success in leading detection initiatives and implementing innovative approaches at enterprise scale.
- Detection platform expertise: Deep hands-on experience with at least one major detection platform including advanced detection logic development, tuning, and validation; recognised internally as an expert in detection capabilities and standards.
- Threat landscape knowledge: Working experience with threat intelligence, adversary TTPs, and attack techniques across cloud, on-premises, and OT environments; familiarity with how threats evolve and how detection strategies must adapt.
- Global collaboration: Experience working in a global organization with geographically dispersed teams and partners, including matrix working environments; ability to coordinate across time zones and cultural contexts.
- Collaborator engagement: At least five (5) years of experience collaborating with security operations teams, incident responders, and threat intelligence analysts to identify, document, and address detection requirements; proven ability to manage relationships and communications with third-party suppliers and vendors.
- Project delivery: Experience delivering and managing large-scale detection engineering projects including planning, execution, and organizational change; ability to navigate dependencies across multiple teams and technical domains.
- Problem-solving and innovation: Recognised internally as an expert problem solver for complex detection challenges; track record of designing, shaping, and implementing innovative detection solutions that address emerging threats.
Skills
- Scripting and automation: Advanced proficiency in scripting languages such as Python, PowerShell, or similar for detection logic development and automation tasks; experience with detection-as-code practices and version control for detection content.
- Detection formats and standards: Extensive experience with standardised detection formats including Sigma rules, YARA signatures, and platform-specific query languages; ability to develop detection logic that is portable and maintainable across platforms.
- Performance optimization: Deep understanding of detection tuning, false positive reduction, and query optimisation techniques; proven ability to balance detection sensitivity with operational efficiency.
- OT/ICS detection considerations: Familiarity with operational technology environments and the unique constraints affecting detection in industrial settings; awareness of safety implications and availability requirements that influence detection approaches.
- Purple team collaboration: Experience working with offensive security teams to validate detection efficacy and identify coverage gaps; understanding of how adversary emulation informs detection improvement.
Benefits
- Annual base pay for this position ranges from $136,044.00 - $204,066.00 USD Annual.
- Short-term incentive bonus opportunity.
- Equity-based long-term incentive program (salaried roles).
- Retirement contribution (hourly roles).
- Commission payment eligibility (sales roles).
- Qualified retirement program [401(k) plan].
- Paid vacation and holidays.
- Paid leaves.
- Health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans.