Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Detection Engineering Lead - REMOTE image - Rise Careers
Job details

Detection Engineering Lead - REMOTE

Description


Binary Defense is seeking a Detection Engineering Lead to serve as both a technical leader and hands-on contributor within our Detection Engineering function. This is a working manager position responsible for managing the day-to-day operations of the detection engineering team, while also actively participating in detection logic development, telemetry analysis, and strategy execution.


You’ll play a pivotal role in evolving and implementing a scalable detection GitOps process that aligns to business risk, quantifiable metrics, and coverage across the MITRE ATT&CK framework. This role requires deep technical expertise, strong cross-functional communication, and the ability to deliver high-impact security detections at scale.


Key Responsibilities:


  • Lead and mentor a team of Detection Engineers in designing, developing, and maintaining threat detection logic across SIEM, EDR, and cloud platforms.
  • Actively contribute to detection development efforts — including rule creation, tuning, threat modeling, and attack simulation — with an eye toward quality, performance, and detection efficacy.
  • Develop and maintain a structured detection engineering as code lifecycle — from ideation to testing, deployment, tuning, and retirement — with appropriate documentation and traceability.
  • Establish detection coverage tracking and reporting metrics aligned to business-critical assets and MITRE ATT&CK, including quantifiable risk scoring tied to each detection.
  • Collaborate across teams (Threat Intel, Incident Response, Security Engineering, Cloud Engineering, etc.) to ensure detections are informed by real-world threats and deployed across the correct telemetry.
  • Analyze telemetry quality and advocate for improvements to logging pipelines, data normalization, and event enrichment based on detection requirements.
  • Stay current on emerging attacker TTPs, threat actors, and malware trends to ensure proactive detection coverage.
  • Support attack testing to validate detection logic and improve effectiveness.
  • Own onboarding and documentation of detection tooling, processes, and coverage across the organization.
  • Serve as the subject matter expert on telemetry sources and their detection use cases across endpoint, network, application, and cloud layers.

Requirements

  

  • 5+ years of experience in detection engineering, threat hunting, or security operations.
  • 2+ years in a leadership or mentoring role within a security engineering team.
  • Proven experience developing and tuning detection rules across SIEM platforms (e.g., Splunk, Sentinel, Chronicle), EDR solutions (e.g., CrowdStrike, SentinelOne), and Cloud environments (e.g., AWS, GCP, Azure).
  • Deep understanding of telemetry sources such as Windows Event Logs, Sysmon, PowerShell logs, DNS, proxy/firewall, cloud audit logs, and their detection potential.
  • Familiarity with attack chains and adversary tradecraft including MITRE ATT&CK, LOLBAS, process injection, credential access, lateral movement, cloud control plane abuse, etc.
  • Strong understanding of security data modeling, detection-as-code practices, and the use of frameworks like SIGMA or YARA-L.
  • Experience with REST API interfaces and using automation to streamline detection development or testing.
  • Strong written and verbal communication skills with the ability to translate complex technical threats into understandable business risk.
  • Ability to balance project management responsibilities with individual technical contributions.


Preferred Qualifications


  • Experience implementing or contributing to a Detection Engineering framework or strategy (e.g., Palantir ADS, MITRE D3FEND, etc.)
  • Familiarity with risk scoring methodologies and mapping detections to risk reduction outcomes.
  • Experience working in a multi-tenant or MDR environment and building detections at scale.
  • Knowledge of data pipeline tools and log forwarding agents (e.g., Fluent Bit, Logstash, Elastic Agent, Sysmon XML config tuning).
  • Hands-on experience with attack simulation tools like Atomic Red Team, Caldera, or manual adversary emulation.


About Binary Defense


Binary Defense is a trusted leader in security operations, supporting companies of all sizes to proactively monitor, detect and respond to cyberattacks. The company offers a personalized Open XDR approach to Managed Detection and Response, advanced Threat Hunting, Digital Risk Protection, Phishing Response, and Incident Response services, helping customers mature their security program efficiently and effectively based on their unique risks and business needs.


With a world-class 24/7 SOC, deep domain expertise in cyber, and sophisticated technology, hundreds of companies across every industry have entrusted Binary Defense to protect their business. Binary Defense gives companies actionable insights within minutes not hours, the confidence in their program to be resilient to ever-changing threats, and the time back that matters most to their business.

Binary Defense is also the Trusted Cybersecurity Partner of the Cleveland Browns and partners with PGA TOUR players. For more information, visit our website, check out our blog, or follow us on LinkedIn.


Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Detection Engineering Lead - REMOTE, Binary Defense

Are you ready to take on an exciting leadership role in cybersecurity? Binary Defense is on the hunt for a Detection Engineering Lead to join our dynamic team in Houston, Texas. This unique position combines technical leadership with hands-on responsibilities, allowing you to shape the future of our Detection Engineering function. In this role, you'll be responsible for leading and mentoring a talented team of Detection Engineers while actively contributing to the development of detection logic and telemetry analysis. You'll implement a robust detection GitOps process that aligns with business risks and measurable metrics, all while ensuring that our security detections are scaled effectively. As the Detection Engineering Lead, you'll work closely with various teams, including Threat Intelligence and Incident Response, to ensure that our detections are informed by real-world threats. Your technical expertise in SIEM, EDR, and cloud platforms will be crucial as you create, tune, and implement detection rules, helping us stay ahead of emerging threats. If you have over five years of experience in detection engineering and a knack for communicating complex security concepts clearly, we'd love to hear from you. Join Binary Defense and help us provide actionable insights that allow us to protect countless businesses around the clock!

Frequently Asked Questions (FAQs) for Detection Engineering Lead - REMOTE Role at Binary Defense
What are the responsibilities of a Detection Engineering Lead at Binary Defense?

As the Detection Engineering Lead at Binary Defense, you'll oversee the daily operations of the detection engineering team while directly contributing to the development of detection logic and telemetry analysis. This involves leading your team in designing and maintaining threat detection across various platforms, actively participating in rule creation and tuning, and developing a structured detection lifecycle. You'll also work closely with other teams to ensure our detections are relevant to real-world threats and track metrics that align with critical business assets.

Join Rise to see the full answer
What qualifications do I need to apply for the Detection Engineering Lead position at Binary Defense?

To be considered for the Detection Engineering Lead position at Binary Defense, candidates should have a minimum of five years of experience in detection engineering or threat hunting, including at least two years in a leadership role. Proficiency in developing and tuning detection rules across SIEM platforms and a deep understanding of various telemetry sources such as Windows Event Logs and cloud audit logs are essential. Additionally, familiarity with frameworks like MITRE ATT&CK and strong communication skills are critical for this position.

Join Rise to see the full answer
How does Binary Defense support the growth of its Detection Engineering team?

At Binary Defense, we believe in the continuous growth of our team members. The Detection Engineering Lead will mentor team members and ensure they stay current on the latest industry trends and attacker tactics. We offer training opportunities to help you expand your skill set, and our remote-friendly environment allows flexibility, making it easier for you to balance personal and professional development.

Join Rise to see the full answer
What technologies will I work with as the Detection Engineering Lead at Binary Defense?

In this role, the Detection Engineering Lead will work with a variety of advanced technologies, including SIEM platforms like Splunk and Chronicle, EDR solutions such as CrowdStrike, and cloud environments like AWS, GCP, and Azure. You will also engage with tools for detection simulation and automation, enabling you to streamline detection development processes efficiently.

Join Rise to see the full answer
What is the company culture like at Binary Defense for the Detection Engineering team?

Binary Defense prides itself on fostering a positive and collaborative culture. The Detection Engineering team works closely together, promoting an environment of mentorship and continuous learning, where everyone’s ideas are valued. With a focus on teamwork and professional growth, we ensure that our employees have the support needed to thrive in their roles.

Join Rise to see the full answer
Common Interview Questions for Detection Engineering Lead - REMOTE
Can you explain your experience in developing detection rules across different platforms?

In answering this question, consider detailing your specific experiences with SIEM platforms and EDR solutions. Share examples of rules you've developed, the challenges you faced, and how you tuned them for optimal performance. Emphasize your analytical skills and how you leveraged data to enhance detection capabilities.

Join Rise to see the full answer
How do you stay updated with the latest threats and TTPs?

To effectively respond to this question, discuss the resources you utilize for staying informed, such as industry news, threat intelligence reports, and cybersecurity forums. Mention any communities or affiliations you have that provide insights into current trends and share your methods for aligning these threats with your detection strategies.

Join Rise to see the full answer
Could you walk us through your process for telemetry analysis?

When answering this question, describe your systematic approach to telemetry analysis. Discuss the importance of data normalization and event enrichment in improving detection quality. Provide examples of how you have analyzed telemetry data to derive actionable insights for your detection engineering efforts.

Join Rise to see the full answer
What experience do you have with MITRE ATT&CK and its application in detection engineering?

Reflect on your familiarity with the MITRE ATT&CK framework and how you have used it to inform threat detection strategies. Share specific examples of how you've mapped detections to the framework's tactics and techniques and how this process aids in identifying coverage gaps.

Join Rise to see the full answer
How do you ensure that your detection processes align with business risk?

In your response, highlight the importance of understanding the organization's unique risks and objectives. Discuss how you establish metrics that reflect these risks and your techniques for prioritizing detection efforts based on business impact, ensuring that security measures align with overall strategy.

Join Rise to see the full answer
Describe a time when you had to lead a team through a challenging detection problem.

Use this question to showcase your leadership and problem-solving skills. Share a specific situation where you encountered a complex detection issue, the steps you took to rally your team, and the ultimate solution you achieved together. Focus on the outcome and your role in promoting collaboration.

Join Rise to see the full answer
What strategies do you implement for tuning existing detection rules?

In responding, discuss your approach to rule tuning, including performance metrics you monitor and how you determine which rules need adjustment. Provide examples of how your tuning efforts have led to improved detection efficacy and reduced false positives.

Join Rise to see the full answer
What role does automation play in your detection engineering process?

Explain how you incorporate automation into your detection development lifecycle. Discuss specific tools you've used to streamline processes and enhance efficiency, focusing on how automation allows you to focus on higher-level strategic tasks while maintaining detection quality.

Join Rise to see the full answer
Can you give an example of a successful collaboration with other teams, like Threat Intelligence or Incident Response?

Reflect on a specific instance where you collaborated with other teams to improve detection capabilities. Discuss the goals of the collaboration, the communication strategies you employed, and the impact that this teamwork had on enhancing security posture.

Join Rise to see the full answer
What do you consider the most critical aspect of developing a comprehensive detection strategy?

Your answer should emphasize the need for a balanced approach that combines technical capabilities, understanding of business risks, and real-time feedback from detection experiences. Discuss how you ensure that your strategies evolve with changing threat landscapes while remaining aligned with organizational priorities.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

GDIT is seeking a Senior Systems Administrator to support vital DoD missions and maintain critical IT systems.

Photo of the Rise User

As a Senior Director at Visa, you will spearhead the implementation of cutting-edge AI solutions while driving engineering excellence in a dynamic team environment.

Photo of the Rise User

Become the Chief Information Security Officer at Sword Health and lead the charge in building a security infrastructure that empowers a pain-free future through AI.

Photo of the Rise User

The Pennsylvania Turnpike Commission is looking for an IT Training Analyst to enhance training through innovative learning options and materials.

Photo of the Rise User

Join UNIVERSAL Technologies as a Dynamics 365 Technical Lead, where you'll guide development teams in delivering impactful IT projects.

Posted 3 days ago

Seeking a Camunda Expert to join our team for a long-term remote contract focused on process modeling.

Photo of the Rise User
Posted 4 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Seize the opportunity to lead Data Governance initiatives at American Express and shape their data strategy for future growth.

Photo of the Rise User

Join Oritain as a Senior Salesforce Administrator to enhance our commercial tech stack and support sustainable supply chains globally.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Binary Defense is a managed security services provider and software developer with solutions including SOC-as-a-Service, Managed Detection & Response, Security Information & Event Management, Threat Hunting and Counterintelligence. With our human-...

2 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 17, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Marysville just viewed Security Specialist at Anduril Industries
Photo of the Rise User
Someone from OH, Cincinnati just viewed Learning Content Designer at QuantHub
Photo of the Rise User
Someone from OH, Tallmadge just viewed Manufacturing and Process Engineer at CVRx
Q
Someone from OH, Columbus just viewed Part-Time Medical Assistant at QualDerm Partners
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Intern – Finance – Michigan at Stryker
Photo of the Rise User
19 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Cleveland just viewed Remote Customer Service Representative at Conduent
Photo of the Rise User
Someone from OH, Cleveland just viewed Customer Support Team Lead (6-month Contract) at Jane App
o
Someone from OH, Cincinnati just viewed Marketing and Communications Consultant at osu
Photo of the Rise User
Someone from OH, Toledo just viewed Registered Nurse (Part-time) at Calibrate