Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Senior Detection Engineer (AI-Augumented)

Senior • On-site

Warsaw, MZ, Poland

The Senior Detection Engineer is part of the Cyber Defense Technology team and is responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. The role combines detection engineering with agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.

How success looks like

  • Detection rules catch real threats and generate minimal noise.
  • Alert fidelity (TP rate) improves measurably and SOC case volume is reduced.
  • Work is performed independently within the detection-as-code workflow: branch, validate, deploy.
  • AI tooling is used daily to accelerate work.
  • Quarterly deliverables are reviewed with the manager through continuous mentoring and coaching.

Job Responsibilities

Detection Engineering (Core)

  • Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk.
  • Write detection logic across SIEM and data lake platforms.
  • Manage detection content as code through git-based workflows, PR reviews, and CI/CD deployment pipelines.
  • Investigate and systematically suppress false positives using lookup-based architectures.
  • Collaborate with Threat Hunting and Threat Intelligence teams through structured TI→TH→DE handover processes.
  • Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns.

AI-Augmented Detection

  • Use AI agents and LLM-assisted workflows to accelerate detection-rule development, validation, and coverage analysis.
  • Use and contribute to MCP tooling for AI-assisted detection validation, including telemetry queries, LOLBAS/GTFOBins assessment, and coverage-gap checks.
  • Operate agentic pipelines that triage large rule libraries against live telemetry at scale.
  • Apply AI/ML techniques to anomaly detection, behavioral analytics, or pattern identification in security datasets where appropriate.
  • Stay current on frontier AI threats, including agentic attacks, LLM-assisted exploitation, and AI-generated phishing, and translate them into detection opportunities.

Collaboration & Operations

  • Work with SOC analysts to understand alert-quality feedback and improve fidelity.
  • Collaborate with data engineers on telemetry availability, data quality, and log-source onboarding.
  • Contribute to detection-coverage reporting and MITRE ATT&CK posture measurement.
  • Document detection logic, tuning rationale, and suppression decisions.

Job Qualifications

Required Technical Competencies and Experience

  • 5+ years in detection engineering, security operations, or threat detection roles.
  • Proven experience writing and tuning SIEM detection rules and analytics, including correlation rules, scheduled queries, and real-time alerts.
  • Strong understanding of the MITRE ATT&CK framework and its application to detection coverage.
  • Python proficiency for automation, scripting, and tooling.
  • Experience with git-based workflows, including branching, PRs, and CI/CD, for managing security content.
  • Familiarity with EDR, identity, cloud, network, and proxy security log sources.
  • Strong analytical skills and ability to distinguish true threats from noise in large datasets.
  • Bachelor’s degree in Information Systems, Information Technology, Computer Science, Engineering, or another technical/IT field, and/or at least 5 years of relevant experience.

Preferred Certifications

  • CISSP
  • CCSP
  • OSCP
  • GIAC Certified Detection Analyst (GCDA)
  • GCIA
  • Relevant cloud and ML/AI certifications

Preferred Experience

  • Experience with multiple query languages.
  • Experience with detection-as-code practices and YAML-based rule formats, including Sigma and custom schemas.
  • Working knowledge of AI/LLM capabilities and security implications, both as detection targets and engineering tools.
  • Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows.
  • Familiarity with SOAR platforms and their integration with detection pipelines.
  • Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments.

We offer

  • Large-scale projects and access to leading IT partners and technologies from day one.
  • Training and certification paths.
  • Competitive starting salary and benefits program, including private health care, stock, savings plans, and sport cards.
  • Regular salary increases and promotion opportunities based on results and performance.
  • Opportunity to change roles every few years.
  • Hybrid work model: work from home up to two days a week and work in the office for collaboration and communication.
  • Employment is exclusively offered under an Umowa o Pracę (full-time employment contract). Apply only if you agree to these conditions.

Similar jobs you might like