SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Detection Engineer III

Insight Engines - Hyderabad, Telangana, India - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

F5 is seeking a Security Detection Engineer III to join the Security Operations Platform Engineering (SOPE) team. This is a career-level security engineering role focused on developing, testing, deploying, and continuously improving detection capabilities that support Security Operations. You will be responsible for developing and maintaining custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows. You'll analyze and improve detection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework, identifying gaps and prioritizing enhancements. Key responsibilities include partnering with Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate emerging threats, investigations, and telemetry into actionable detection content. You will validate and tune detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives. You'll automate and optimize detection engineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability. Support onboarding of new log sources and security telemetry by collaborating with engineering and infrastructure teams to establish detection coverage across new environments and technologies. Additional responsibilities include creating and maintaining detection documentation, runbooks, coverage assessments, and technical standards while participating in an engineering on-call rotation. You'll help define detection strategy for AI and agentic systems (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs) and explore using AI to accelerate detection engineering workflows. This is a full-time engineering role and is not shift-based. Participation in an engineering on-call rotation is required and may occasionally require support outside normal business hours during critical incidents, platform outages, or detection-related operational events. Travel up to 5% may be required, including occasional international travel. **REQUIREMENTS:** - Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience - 5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or a related discipline - Experience developing, tuning, or maintaining detections within a SIEM, EDR, log analytics, or security monitoring platform - Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies - Strong understanding of attacker techniques, detection methodologies, and frameworks such as MITRE ATT&CK - Strong analytical, problem-solving, communication, and cross-functional collaboration skills **PREFERRED QUALIFICATIONS:** - Experience implementing Detection-as-Code practices, including Git-based workflows, automated testing, and CI/CD pipelines - Experience with adversary emulation, atomic testing, purple-team exercises, or detection validation frameworks - Experience performing detection coverage analysis and developing ATT&CK-based coverage roadmaps - Experience onboarding log sources and building detections across cloud, endpoint, network, identity, or SaaS environments - Experience with platforms such as CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic, or similar security technologies - Familiarity with AI/LLM threat models (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs) or frameworks such as MITRE ATLAS and the OWASP LLM Top 10

Similar roles