Senior Detection Engineer (Next-Gen Threat Hunter)

Intrado Life & Safety, Inc.Longmont, CO
Onsite

About The Position

The modern threat actor moves in seconds or minutes, not days. We are shifting to a detections capability focused on where our data is located (SaaS platforms, automation pipelines, user-controlled data storage) and the knowledge that the future of our perimeter is identity based. As a Detection Engineer, you will not just operate security tools—you will design a high-fidelity system that makes our multi-cloud and on-prem environment inherently hostile to adversaries. This position will be its own customer, building and operating detections, growing from feedback in the field, and iterating. This position will spend (for rough example) 70% on engineering detections for automated attack chains and performing response and triage, with 15% on more traditional log reviews or IOCs, and 15% on strategy and modeling the adversary.

Requirements

  • 5+ years of progressive experience in cybersecurity, including experience in detection engineering, security operations, incident response, threat hunting, security engineering, or a related discipline.
  • Background in technical/network security, systems and/or network engineering or cloud computing, and have done traditional SOC analyst work whether single-hatted or as a generalist role.
  • Minimum 3+ years of experience writing clean automations and scripts in Python, Go, BASH, Helm, or PowerShell to manipulate APIs and data structures.
  • Proven experience securing AWS and Azure control planes, specifically auditing IAM, storage access (e.g., S3, Azure Blobs), and cloud log management.
  • Strong engineering experience with Kubernetes, including securing cluster control planes, monitoring Kube-audit logs, and analyzing container runtime telemetry.
  • Demonstrated track record of hunting based on identity, behavioral baselines, and Living-off-the-Land (LotL) techniques rather than static signatures.
  • Hands-on experience engineering automation playbooks, integrations, and orchestration flows specifically within Cortex XSIAM.

Responsibilities

  • Design and implement high-fidelity detection pipelines that detect automated attack chains within minutes or seconds.
  • Shift focus from static indicators (like file hashes) to complex behavioral analytics and anomaly detection.
  • Monitor and protect AWS and Azure infrastructure by tracking API calls, configuration drift, and identity-based movements.
  • Dissolve boundaries between external attackers, non-human ID and insider threats by mastering the identity perimeter and focusing on potential credential activities.
  • Write production-grade Python and automated workflows in other scripting and automation languages/tools to turn manual threat-hunting hypotheses into instantiated detections code.
  • Align detection logic with modern matrices like MITRE ATT&CK, focusing heavily on cloud, container, and identity techniques.
  • Deploy deceptive assets, honey-tokens, and behavioral tripwires to detect adversary lateral movement or actions post-compromise.
  • Deep-dive into application, Kubernetes, and cloud-service APIs to detect malicious API-shimming, data staging, and account takeovers.
  • Lead analytics and incident response as SME to ensure clean response and containment, ingest post-mortem data and continuously harden detection logic against new variants. Mentor analyst and engineering staff in areas of expertise.
  • Refine data ingestion pipelines and engineer XSOAR playbooks to automatically triage and contain alerts with minimal analyst intervention.
  • Ensure that our stack stays positioned for the always-evolving future, but that we optimize our tools and capabilities as they exist today, getting the most for the dollars invested while planning for what's next.

Benefits

  • medical
  • dental
  • vision
  • life and disability coverage
  • paid time off
  • 401(k) retirement plan
  • paid parental leave
  • access to a robust library of personal and professional training resources
  • employee discounts
  • critical illness
  • hospital indemnity
  • access to legal support
  • pet insurance
  • identity theft protection
  • EAP (Employee Assistance Program) that includes free mental health resources/support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service