Role OverviewAs a Staff Security Engineer in Detection Engineering, you will architect, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS. You’ll drive strategy and technical design through hands-on implementations—detections-as-code, telemetry modeling, and rigorous efficacy metrics (signal-to-noise, precision/recall, latency).
What You Will Do
Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn. Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple-team validation.
Why It Might Be a Fit
This is a hands-on, staff-level role owning detection strategy, architecture, and mentoring. You will benefit from our culture, which strongly believes in the well-being of our employees and their families. We offer generous health and wellness programs and time away for employees of all levels.
Requirements
- BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
- 5+ years in security engineering, detection engineering, or incident response
- 2+ years technical leadership.
- Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP).
- Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)
- Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.
- Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.
- Experience designing schemas and data models (e.g., ASIM/OSSEM-like) and telemetry pipelines.
- Experience with SIGMA rule authoring and translation; adversary emulation/purple-team experience.
Benefits
- Generous health and wellness programs
- Time away for employees of all levels
- Annual performance bonus
- Stock
- Benefits
- Other applicable incentive compensation plans
]]>