Share Job

Business Sector

Financial Services

State

North Carolina

Work LOcation

Hybrid

Cyber Security Engineer – Threat Detection

Charlotte, NC — Hybrid
W2 Only Mid-Level —
5 to 7 Years
Banking / Financial Services MITRE ATT&CK

Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.

? Critical Requirements
  • Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience

Role Objectives
  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness
  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services
  • Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies
  • Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond
  • Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives
  • Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities
  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content
  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency
  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements
  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks
  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience

Qualifications & Skills
Cloud & On-Prem Log Analysis
SIEM / UEBA / EDR / SOAR
Detection-as-Code Pipelines
MITRE ATT&CK Framework
Query Languages & Data Analysis
Threat Intelligence Translation
Automation & Scripting
Windows & Linux OS
Behavioral Analytics
Security Telemetry & Correlation
Data Lake & Ingestion Pipelines
Response Playbook Development
? Additional Experience a Plus
  • Incident response
  • Threat intelligence operations
  • Vulnerability management
  • Security engineering
  • Cloud security

Latest Opportunities

Government
Biotech
Financial Services

Apply Now!

Accepted file types: pdf, doc, docx, Max. file size: 10 MB.