Security Detection Engineer III

F5
Warsaw, Hyderabad, Guadalajara
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 5+ yearsEducation: bachelorsSkills: ["Analytical","Problem-solving","Communication","Cross-functional collaboration"]

Develop, test, deploy, and continuously improve detection capabilities that turn threat intelligence and telemetry into reliable, actionable detections for Security Operations. Build detections using Detection-as-Code with version control and CI/CD, improve coverage via MITRE ATT&CK mappings, validate detections with adversary emulation and purple-team exercises, and automate detection engineering workflows. Support onboarding new log sources and define AI/agentic detection strategy while participating in an engineering on-call rotation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
F5
F5
2 days ago

Security Detection Engineer III

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Develop, test, deploy, and continuously improve detection capabilities that turn threat intelligence and telemetry into reliable, actionable detections for Security Operations. Build detections using Detection-as-Code with version control and CI/CD, improve coverage via MITRE ATT&CK mappings, validate detections with adversary emulation and purple-team exercises, and automate detection engineering workflows. Support onboarding new log sources and define AI/agentic detection strategy while participating in an engineering on-call rotation.
Location: Warsaw, Hyderabad, Guadalajara
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Develop and maintain custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows.
  • •Map telemetry and detections to adversary behaviors and MITRE ATT&CK to identify coverage gaps and prioritize enhancements.
  • •Translate emerging threats, investigations, and telemetry into actionable detection content with Incident Response, Threat Intelligence, Logging Engineering, and platform engineering teams.
  • •Validate and tune detections using adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives.
  • •Automate and optimize detection engineering workflows and alert enrichment, support onboarding new log sources, and maintain documentation/runbooks while participating in on-call rotation.
Travel: Low travel

Key Requirements

  • •Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience.
  • •5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or a related discipline.
  • •Experience developing, tuning, or maintaining detections within a SIEM, EDR, log analytics, or security monitoring platform.
  • •Scripting/automation/data analysis experience using Python, PowerShell, SQL, KQL, SPL, or similar technologies.
  • •Strong understanding of attacker techniques and detection methodologies/frameworks such as MITRE ATT&CK.
Experience:5+ yearsCybersecuritySecurity operationsDetection engineeringThreat hunting
Education:Bachelor's in Information Security, Computer Science, Engineering, or related field
Skills:AnalyticalProblem-solvingCommunicationCross-functional collaboration
Tech Stack:Detection-as-CodeVersion controlPeer reviewTestingCI/CDMITRE ATT&CKAdversary emulationAtomic testingPurple-team exercisesSIEMEDRLog analyticsSecurity monitoringPythonPowerShellSQLKQLSPLGitCrowdStrike

Company Brief

F5
Provides application delivery networking, load balancing, and security solutions for on-premises and cloud environments, helping organizations optimize, secure, and scale applications and APIs across multi-cloud infrastructures.
Industry: Networking Equipment
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Seattle, United States
Founded: 1996
Glassdoor
Glassdoor: 3.8
WebsiteLinkedIn