Job at a glance
#LI-CR2 #LI-Hybrid The Security Detection Engineer is a senior, hands-on technical role responsible for building, tuning, validating, and operating security detections across CBIZ environments. Detection engineering is the core of the role: translating threat intelligence, adversary behavior, incident findings, and business risk into dependable analytics that identify suspicious activity with useful context.
The engineer also investigates incidents, improves supporting controls, and uses automation to increase speed, consistency, and coverage. This is not a passive monitoring or ticket-routing role; the engineer owns detection problems from use-case design and telemetry validation through deployment, triage support, measurement, and continuous improvement. Essential Functions and Primary Duties Detection Engineering and Threat Analytics Design, test, deploy, document, and maintain detection content across SIEM, XDR, NDR, identity, email, endpoint, network, cloud, and application security platforms.
Turn threat intelligence, adversary tactics and techniques, incident findings, and business risk into prioritized detection use cases; develop behavioral, correlation, threshold, anomaly, and indicator-based analytics. Map detection coverage to recognized adversary behaviors and maintain clear traceability among threats, telemetry, analytics, response actions, and control owners. Validate detections through structured testing, historical-log review, attack simulation, purple-team exercises, and post-incident analysis; tune for meaningful signal while reducing false positives and duplicates.
Own the detection lifecycle, including intake, prioritization, peer review, testing, release, version control, performance review, exception handling, and retirement. Monitor detection health, data freshness, rule execution, alert quality, and coverage gaps; drive corrective action when controls or telemetry degrade. Telemetry, Logging, and Detection Architecture Partner with cloud, identity, endpoint, network, infrastructure, and application teams to onboard, normalize, and retain security-relevant telemetry.
Assess log quality and availability, including timestamps, identity context, event fidelity, field mapping, parsing, retention, and ingestion health required for reliable investigations and detections. Document data dependencies and recovery procedures for critical detections, and contribute to detection architecture, data-source strategy, and use-case roadmaps across hybrid and multi-cloud environments Security Operations, Incident Response, and Engineering Investigate and respond to alerts and incidents across SIEM, XDR, NDR, identity, email, endpoint, network, and cloud platforms; lead work from triage and scoping through containment, eradication, recovery, validation, and lessons learned.
Perform root-cause analysis, reconstruct activity across data sources, preserve relevant evidence, validate remediation, and convert incidents, near misses, and control failures into improved detections, playbooks, and preventive controls. Configure, harden, maintain, and troubleshoot security controls across Microsoft Azure, Azure Virtual Desktop, AWS, and Microsoft 365 security and compliance platforms, including identity protection, Conditional Access, email defense, endpoint security, DLP, cloud workload protection, and tenant baselines.
Support certificate-based authentication, encryption, and PKI dependencies; coordinate remediation and control changes with technology owners and confirm intended security outcomes. Participate in an on-call rotation and after-hours response as needed. Automation, Documentation, and Collaboration Use PowerShell, Python, Bash, APIs, SOAR workflows, and other automation methods to enrich alerts, test controls, improve data quality, orchestrate response, and reduce repetitive work.
Build reusable queries, scripts, integrations, dashboards, investigation guidance, runbooks, playbooks, SOPs, and kn