Senior Cybersecurity Detection Engineer
Job Description
Calance US is seeking a Senior Cybersecurity Detection Engineer for an onsite role in Charlotte, NC. This hands-on position emphasizes SIEM based detection engineering, data analysis, and algorithm development, with a focus on designing, deploying, and operationalizing detections across enterprise networks, SaaS, cloud, and on-prem environments.
Responsibilities
- Design, build, and optimize detections by crafting correlation rules, algorithms, and Python scripts that leverage security telemetry and enterprise data sources.
- Work hands-on within SIEM and detection platforms (Splunk or equivalent), configuring rules, tuning alerts, and enhancing signal quality.
- Analyze large datasets by querying databases (SQL or similar), joining multiple data sources, and identifying data essential for detections.
- Research threat scenarios and determine required data sets in collaboration with Analysts, Focus Area Leads, and other subject matter experts.
- Integrate new data feeds by reviewing documentation, assessing readiness, documenting feed attributes, and supporting onboarding efforts.
- Test, onboard, and operationalize alerts through defined team processes, including micro-playbook development and SOAR-related activities.
- Investigate security events by examining raw data, validating detections, and understanding network, endpoint, and cloud behaviors.
- Document detections, integrations, and processes clearly to facilitate knowledge sharing across the team.
- Continue expanding technical breadth, including applied data analysis, detection engineering techniques, and emerging automation approaches.
- Take a security problem or integration from concept to deployment.
- Write Python scripts to connect data sources, ingest data, build correlations, and generate actionable detections.
- Understand the data behind detections, including what is populated, what is missing, and what requires improvement.
- Collaborate effectively with a high-performing team, sharing knowledge and contributing to collective outcomes.
- Deliver practical algorithms and tuned detections that improve enterprise security outcomes.
Requirements
- 3-5 years of professional experience in cybersecurity, detection engineering, or a closely related technical role.
- Hands-on experience working in a SIEM, including writing and tuning detection rules (Splunk or similar).
- Strong Python skills applied in real-world environments.
- Solid experience with data analysis and querying, including SQL and handling large data sets.
- Experience joining data, analyzing patterns, and determining relevance for threat detection.
- Understanding of network security fundamentals and how enterprise environments are defended.
- Strong communication skills and the ability to clearly explain technical work to teammates.
- A collaborative mindset where success is measured by team outcomes rather than individual visibility.
Technologies
- Python
- SQL
- Splunk
- CRIBL
- Palo Alto XSIAM
- Databricks
- Apache Spark