Detection Engineer - REMOTE

Binary DefenseHouston, TX
Remote

About The Position

Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You’ll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments. Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.

Requirements

  • 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
  • Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
  • Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies accordingly.
  • Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.

Nice To Haves

  • Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
  • Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
  • Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
  • Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
  • Experience in IR consulting and working across diverse EDR/SIEM stacks.

Responsibilities

  • Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
  • Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
  • Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
  • Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
  • Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
  • Support documentation of detection logic, coverage rationale, and response guidance.
  • Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Benefits

  • competitive medical, dental and vision coverage for employees and dependents
  • a 401k match which vests every payroll
  • a flexible and remote friendly work environment
  • training opportunities to expand your skill set
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service