Threat Detection Engineer

Ampcus Inc.New York, NY
Onsite

About The Position

The Threat Detection Engineer will develop and enhance enterprise threat detection capabilities across security monitoring platforms. This role will focus on creating advanced detection logic, threat hunting, incident identification, security analytics, and monitoring of both traditional and AI-enabled environments. The engineer will work closely with SOC, cyber defense, and threat intelligence teams to improve detection coverage and reduce organizational cyber risk.

Requirements

  • 7+ years of cybersecurity and security operations experience.
  • Hands-on experience with Splunk, Sentinel, QRadar, or similar SIEM tools.
  • Experience building detection content and threat-hunting methodologies.
  • Familiarity with cloud security, EDR technologies, and MITRE Telecommunication & CK framework.
  • Splunk & Security Analytics
  • Threat Hunting & Incident Response

Nice To Haves

  • Security Automation (SOAR)
  • AI Security & GenAI Monitoring Experience

Responsibilities

  • Develop and tune SIEM detection use cases and correlation rules.
  • Perform proactive threat hunting and behavioral analytics.
  • Create and maintain security monitoring content.
  • Investigate emerging threats and map detections to MITRE Telecommunication & CK.
  • Improve detection coverage for cloud, endpoint, and network environments.
  • Build automated response workflows and security analytics dashboards.
  • Support detection strategies for AI, GenAI, and LLM-based technologies.
  • Design and implement agentic workflows (ReAct, multi-agent orchestration, tool-augmented agents).
  • Build autonomous or semi-autonomous AI agents to handle development, testing, and operational workflows.
  • Integrate agents with enterprise systems (Jira, Git, ServiceNow, APIs, etc.).
  • Build and optimize Retrieval-Augmented Generation (RAG) pipelines.
  • Work with vector databases, embeddings, document chunking, indexing, and retrieval tuning.
  • Enable enterprise knowledge use cases (e.g., FAQ bots, nuggets/knowledge artifacts, AI copilots).
  • Implement evaluation frameworks for LLMs, including: Functional correctness, Response quality, Hallucination detection.
  • Experience with AI testing frameworks (e.g., RAGAS, DeepEval, custom evaluation harnesses).
  • Build scalable APIs/services (FastAPI, Flask, etc.).
  • Ensure performance, observability, and reliability of AI systems.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service