SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Detection Engineer III

Shape Security - Warsaw, Poland - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

F5 is seeking a Security Detection Engineer III to join the Security Operations Platform Engineering (SOPE) team. This is a career-level security engineering role focused on developing, testing, deploying, and continuously improving detection capabilities that support Security Operations. You will be responsible for developing and maintaining custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows. The role involves analyzing and improving detection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework, identifying gaps and prioritizing enhancements. Key responsibilities include partnering with Incident Response, Threat Intelligence, Logging Engineering, and platform engineering teams to translate emerging threats and investigations into actionable detection content. You will validate and tune detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives. The engineer will automate and optimize detection engineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability. You'll support onboarding of new log sources and security telemetry by collaborating with engineering and infrastructure teams to establish detection coverage across new environments and technologies. A unique aspect of this role is helping define detection strategy for AI and agentic systems, including prompt injection, tool and function abuse, agent identity and credential misuse, and data exfiltration via model outputs. You'll also explore using AI to accelerate detection engineering workflows. Required qualifications include a Bachelor's degree in Information Security, Computer Science, Engineering, or related field (or equivalent practical experience), plus 5+ years in cybersecurity, security engineering, detection engineering, security operations, or threat hunting. You must have experience developing detections within a SIEM, EDR, log analytics, or security monitoring platform, and proficiency with scripting/automation using Python, PowerShell, SQL, KQL, SPL, or similar technologies. This is a full-time engineering role requiring participation in an engineering on-call rotation, which may occasionally require support outside normal business hours during critical incidents. Travel up to 5% may be required, including occasional international travel.

Similar roles