Threat Detection Engineer (India)

Threat Detection Engineer (India)

06 Aug
|
Sapphire Software Solutions
|
India

06 Aug

Sapphire Software Solutions

India

Please check the JD and share your updated resume to my email [email protected] and ping me on whatsapp (+91 (phone hidden)) along with your resume

Role: Detection Engineer

Years of experience: 5+

Duration: 6 month with continuous extensions

Location: Remote

Working Hrs: IST hrs – need to overlap with London UK (BST hrs)

:

Required Skills & Experience

-5+ years of hands-on detection engineering experience (writing production detection rules and understand correlation)

-MITRE ATT&CK; fluency - ability to think in techniques and map a red team finding to a detection gap

Knowledge of SPL - you can write effective Splunk searches and understand what makes a rule expensive or fragile

-Experience with at least one EDR platform at a detection level - CrowdStrike Falcon, Microsoft Defender for Endpoint, etc.

-Understanding of offensive security techniques (understand how attacks work at a technique level)

-Experience validating detections - atomic testing, purple team participation, or equivalent empirical validation methods

-Ability to work with incomplete data - can make a coverage decision with imperfect information and document the reasoning

Nice to Have Skills & Experience

-Purple team experience - either as a detection-side participant or having run exercises end-to-end

-Sigma rule authoring - vendor-agnostic detection development and the ability to translate rules across platforms

-Threat intelligence integration - consuming threat intel and translating it into detection requirements





-Risk-based alerting - understanding how to score and prioritize alerts rather than treating all alerts equally

-Offensive security background or certifications (OSCP, CRTE, or similar)

-Experience with CrowdStrike Falcon detection authoring specifically

-Familiarity with MITRE ATLAS for AI/ML threat scenarios

-Scripting ability (Python) - for detection automation, log parsing, or tooling integrations

-Experience writing or reviewing logging standards, detection standards, or security governance documentation

We are seeking a remote Detection Engineer to join a global consulting firm.

This person will work within the Security Operations team to help build the technical foundation of a continuous monitoring & detection program.

You will be the first Detection Engineer in the team, responsible for building advanced detections.

We use Splunk as our SIEM and have an MSSP, who currently handle L1 and L2 alert triage. Your mandate is to build the detection capability that sits above that - writing, validating, and owning detections that our CSIRT will depend on.

You will translate offensive security findings directly into detections, audit what we already have in Splunk, close coverage gaps, and build the governance that makes the program measurable and defensible. You will be working in an ambiguous, but large scale setting with a lot of unknowns, taking findings and turning them into actionable detections that genuinely contribute to the security posture of the organization.

📌 Threat Detection Engineer (India)
🏢 Sapphire Software Solutions
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: threat detection engineer (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: threat detection engineer (india) / india