EngineerJobs.io
← Back to all jobs

Job Description

Calance US is seeking a Senior Cybersecurity Detection Engineer for an onsite role in Charlotte, NC. This hands-on position emphasizes SIEM based detection engineering, data analysis, and algorithm development, with a focus on designing, deploying, and operationalizing detections across enterprise networks, SaaS, cloud, and on-prem environments.

Responsibilities

  • Design, build, and optimize detections by crafting correlation rules, algorithms, and Python scripts that leverage security telemetry and enterprise data sources.
  • Work hands-on within SIEM and detection platforms (Splunk or equivalent), configuring rules, tuning alerts, and enhancing signal quality.
  • Analyze large datasets by querying databases (SQL or similar), joining multiple data sources, and identifying data essential for detections.
  • Research threat scenarios and determine required data sets in collaboration with Analysts, Focus Area Leads, and other subject matter experts.
  • Integrate new data feeds by reviewing documentation, assessing readiness, documenting feed attributes, and supporting onboarding efforts.
  • Test, onboard, and operationalize alerts through defined team processes, including micro-playbook development and SOAR-related activities.
  • Investigate security events by examining raw data, validating detections, and understanding network, endpoint, and cloud behaviors.
  • Document detections, integrations, and processes clearly to facilitate knowledge sharing across the team.
  • Continue expanding technical breadth, including applied data analysis, detection engineering techniques, and emerging automation approaches.
  • Take a security problem or integration from concept to deployment.
  • Write Python scripts to connect data sources, ingest data, build correlations, and generate actionable detections.
  • Understand the data behind detections, including what is populated, what is missing, and what requires improvement.
  • Collaborate effectively with a high-performing team, sharing knowledge and contributing to collective outcomes.
  • Deliver practical algorithms and tuned detections that improve enterprise security outcomes.

Requirements

  • 3-5 years of professional experience in cybersecurity, detection engineering, or a closely related technical role.
  • Hands-on experience working in a SIEM, including writing and tuning detection rules (Splunk or similar).
  • Strong Python skills applied in real-world environments.
  • Solid experience with data analysis and querying, including SQL and handling large data sets.
  • Experience joining data, analyzing patterns, and determining relevance for threat detection.
  • Understanding of network security fundamentals and how enterprise environments are defended.
  • Strong communication skills and the ability to clearly explain technical work to teammates.
  • A collaborative mindset where success is measured by team outcomes rather than individual visibility.

Technologies

  • Python
  • SQL
  • Splunk
  • CRIBL
  • Palo Alto XSIAM
  • Databricks
  • Apache Spark

Similar Jobs