← Zurück zur Liste
Stelle

Detection Engineer

Sonstige • Remote • Vollzeit Europäische Union EU/EMEA

Artemis is a security platform whose AI-driven detection content is owned by the Detection Engineer. The role designs, builds and tunes high-fidelity detections across cloud, identity, endpoint and SaaS environments, treating detection as code. The goal is for detections to feed rich, machine-readable context into an AI-native investigation pipeline, not just fire alerts.

Responsibilities

  • Design, implement and own high-fidelity detections across cloud (AWS, Azure, GCP), identity (Okta, Entra ID), endpoint (EDR) and SaaS log sources
  • Practice detection-as-code: version-controlled rules, peer review, automated validation and CI/CD deployment
  • Map detection coverage against MITRE ATT&CK and systematically close gaps
  • Build and run attack simulations and test harnesses to validate detections against real attacks
  • Continuously analyze false-positive and false-negative rates and tune noisy logic
  • Leverage AI-assisted workflows to author, convert, test and document detection rules
  • Build behavioral and anomaly-based detections by establishing normal activity baselines
  • Translate threat intelligence and incident findings into durable, behavioral detection logic
  • Partner with SOC and research teams to drive detection improvements
  • Support customer-specific tuning to reduce noise without sacrificing coverage

Requirements

  • 5+ years of hands-on cybersecurity experience, with significant time in detection engineering
  • Proven track record designing, building and tuning detections at scale across SIEM, EDR or custom detection platforms
  • Strong proficiency in detection languages and formats such as Sigma, KQL, SPL or YARA-L

About the company

Artemis is an AI-native security platform whose detection content is built with a code-based approach, feeding rich context into an AI-driven investigation pipeline.

Ähnliche Stellen