Senior Security Engineer - Detection Engineering

LinkedInRemote, REMOTE
$129,000 - $212,000Hybrid

About The Position

LinkedIn's Information Security organization protects our members, data, and platforms by building resilient security controls, detecting threats early, and partnering across engineering to reduce risk at scale. The Detection Engineering team is responsible for building and scaling LinkedIn’s threat detection capabilities. We partner closely with Incident Response, Threat Intelligence, Red and Purple Teams, Product Security, Identity & Access Management, and Cloud Security to identify, contextualize, and detect adversary activity across the enterprise. Our team develops and maintains high-fidelity detections while advancing the underlying security telemetry ecosystem through log ingestion, schema design, data normalization, automation, threat hunting, incident response support, and audit enablement. As a senior individual contributor, you will design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code practices, telemetry modeling, and data-driven efficacy measurements to continuously improve detection coverage and quality. Working from adversary TTPs and threat hypotheses, you will develop resilient, low-noise detections validated through purple-team exercises, adversary emulation, and real-world incident learnings. This is a hands-on engineering role focused on technical leadership, execution, and cross-functional collaboration.

Requirements

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
  • 3+ years in security, detection engineering or incident response.
  • Experience building detection content and analytics for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP).
  • Experience programming for detections/automation (e.g., Python) and query languages (e.g., KQL/SQL/SPL).
  • Experience with detections-as-code (tests, CI/CD, canary/rollback) at scale.
  • Experience with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics.
  • Experience with schemas/data models (e.g., OSSEM/ASIM-like) and telemetry pipelines.

Nice To Haves

  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience.
  • Operating detections over large-scale, multi-region pipelines.
  • Detection testing harnesses, synthetic signal, and adversary emulation at scale.
  • Identity/security signals (Entra ID/Okta/SSO), endpoint internals (Windows/Linux/macOS), SaaS logs.
  • Applied analytics/ML for anomaly detection or risk scoring with robust evaluation.
  • Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection workflows.
  • Hands-on SIGMA authoring/translation; experience with adversary emulation/purple-team validation.
  • Experience with Microsoft Sentinel, Defender XDR, Entra ID; KQL, Python; GitHub Actions/Azure DevOps; Logic Apps; Azure Data Explorer/Kusto
  • Experience with Azure Activity/Diagnostics; AWS CloudTrail/GuardDuty; GCP Cloud Audit Logs/SCC

Responsibilities

  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry; measure precision/recall, latency, lift, and signal-to-noise ratio.
  • Build detections-as-code with version control, CI/CD, unit/integration tests, staged canary rollouts, and safe rollback.
  • Author and maintain SIGMA rules; translate SIGMA to KQL/SQL as needed.
  • Integrate multi-cloud telemetry: Azure (Activity/Diagnostics), AWS (CloudTrail, GuardDuty), GCP (Cloud Audit Logs, SCC).
  • Operationalize Microsoft Defender XDR and Sentinel signals; leverage Entra ID controls (Conditional Access, sign-in risk).
  • Proactive threat hunting; create hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow; integrate with ticketing/chat ops.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and turn reports into testable hypotheses.
  • Own telemetry quality for assigned pipelines: schemas/normalization (e.g., ASIM/OCSF-like), enrichment, data contracts, reliability SLIs/SLOs.
  • Participate in incident retros; add post-incident detections and suppress noisy patterns.
  • Participate in on-call for critical detection pipelines and high-severity investigations.

Benefits

  • Generous health and wellness programs
  • Time away for employees of all levels
  • Annual performance bonus
  • Stock
  • Other applicable incentive compensation plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service