897,836open jobs
55,571companies
150,838added this week
Browse all
Salary
≈ $86k – $180k per year (Estimated)
Location
Hybrid (Independence, United States)
Seniority
Middle · 3+ years exp

Confirmed on the employer's own hiring board on Sep 28, 2026. First seen by Alion on Sep 18, 2026. Cbiz scores B on the Alion truth index.

Overview
Company
Impact
Profile match
CBIZ is a national professional services firm built for the middle market that provides accounting, tax, advisory, benefits, insurance, and technology solutions to businesses and organizations. The company combines local relationships with national resources to deliver services including audit and attest (through its licensed CPA entity), tax planning and compliance, risk and advisory, HR and benefits administration, insurance solutions, investment and transaction advisory, and technology and cybersecurity services. CBIZ focuses on industry-specific guidance and data-driven insights to help clients grow, manage risk, and improve operations.

#LI-CR2 #LI-Hybrid

The Security Detection Engineer is a senior, hands-on technical role responsible for building, tuning, validating, and operating security detections across CBIZ environments. Detection engineering is the core of the role: translating threat intelligence, adversary behavior, incident findings, and business risk into dependable analytics that identify suspicious activity with useful context. The engineer also investigates incidents, improves supporting controls, and uses automation to increase speed, consistency, and coverage. This is not a passive monitoring or ticket-routing role; the engineer owns detection problems from use-case design and telemetry validation through deployment, triage support, measurement, and continuous improvement.

Essential Functions and Primary Duties

Detection Engineering and Threat Analytics

  • Design, test, deploy, document, and maintain detection content across SIEM, XDR, NDR, identity, email, endpoint, network, cloud, and application security platforms.

  • Turn threat intelligence, adversary tactics and techniques, incident findings, and business risk into prioritized detection use cases; develop behavioral, correlation, threshold, anomaly, and indicator-based analytics.

  • Map detection coverage to recognized adversary behaviors and maintain clear traceability among threats, telemetry, analytics, response actions, and control owners.

  • Validate detections through structured testing, historical-log review, attack simulation, purple-team exercises, and post-incident analysis; tune for meaningful signal while reducing false positives and duplicates.

  • Own the detection lifecycle, including intake, prioritization, peer review, testing, release, version control, performance review, exception handling, and retirement.

  • Monitor detection health, data freshness, rule execution, alert quality, and coverage gaps; drive corrective action when controls or telemetry degrade.

Telemetry, Logging, and Detection Architecture

  • Partner with cloud, identity, endpoint, network, infrastructure, and application teams to onboard, normalize, and retain security-relevant telemetry.

  • Assess log quality and availability, including timestamps, identity context, event fidelity, field mapping, parsing, retention, and ingestion health required for reliable investigations and detections.

  • Document data dependencies and recovery procedures for critical detections, and contribute to detection architecture, data-source strategy, and use-case roadmaps across hybrid and multi-cloud environments

Security Operations, Incident Response, and Engineering

  • Investigate and respond to alerts and incidents across SIEM, XDR, NDR, identity, email, endpoint, network, and cloud platforms; lead work from triage and scoping through containment, eradication, recovery, validation, and lessons learned.

  • Perform root-cause analysis, reconstruct activity across data sources, preserve relevant evidence, validate remediation, and convert incidents, near misses, and control failures into improved detections, playbooks, and preventive controls.

  • Configure, harden, maintain, and troubleshoot security controls across Microsoft Azure, Azure Virtual Desktop, AWS, and Microsoft 365 security and compliance platforms, including identity protection, Conditional Access, email defense, endpoint security, DLP, cloud workload protection, and tenant baselines.

  • Support certificate-based authentication, encryption, and PKI dependencies; coordinate remediation and control changes with technology owners and confirm intended security outcomes.

  • Participate in an on-call rotation and after-hours response as needed.

Automation, Documentation, and Collaboration

  • Use PowerShell, Python, Bash, APIs, SOAR workflows, and other automation methods to enrich alerts, test controls, improve data quality, orchestrate response, and reduce repetitive work.

  • Build reusable queries, scripts, integrations, dashboards, investigation guidance, runbooks, playbooks, SOPs, and knowledge articles that improve operational consistency.

  • Evaluate AI-enabled security capabilities responsibly to improve detection development and investigation efficiency while retaining appropriate human review and control.

  • Partner with Security Operations, GRC, IT, Cloud, Networking, Systems, Endpoint, application owners, threat intelligence, vulnerability management, and red/purple teams; provide technical guidance and peer review when appropriate.

Preferred Qualifications

  • 3-5 years of experience in information security, security operations, detection engineering, incident response, threat hunting, or security engineering.

  • Proven hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform.

  • Strong ability to analyze authentication, endpoint, network, email, cloud, and application telemetry and translate findings into durable detection logic.

  • Hands-on experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation.

  • Working knowledge of adversary behavior, common attack techniques, detection lifecycle practices, and methods for validating detection coverage.

  • Experience securing Azure and/or AWS environments and operating Microsoft 365 security capabilities; experience supporting or securing Azure Virtual Desktop is required.

  • Working knowledge of PKI, certificate-based authentication, encryption, enterprise logging architectures, networking, identity and access, endpoint security, and malware fundamentals.

  • Strong PowerShell skills and experience with Linux command-line administration, logs, and services; ability to work independently, exercise sound judgment, and drive complex work to completion.

  • Advanced skill with SIEM query languages, detection-as-code, source control, testing frameworks, SOAR, APIs, and automated response.

  • Experience with threat hunting, attack simulation, purple teaming, adversary emulation, breach-and-attack simulation, or measuring detection coverage and quality.

  • Experience with AI-assisted security analytics and responsible use of AI in detection and response workflows.

  • Relevant certifications such as Security+, GIAC, Microsoft security certifications, ISC2 CC or CISSP, or comparable credentials.

  • Experience in a large enterprise SOC, hybrid or multi-cloud environment, or large-scale security transformation.

Minimum Qualifications Required

  • College Degree or equivalent required
  • 1 year related experience
  • Proficient use of applicable technology
  • Ability to follow technical instructions and guidelines
  • Ability to document daily activities and system functions
  • Able to work in team environment
  • Demonstrated ability to communicate verbally and in writing throughout all levels of organization both internally and externally
  • Ability to travel as required by business and on-call availability
  • Able to lift up to 50 lbs

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
897,836 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Independence
≈ $124k – $258k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • Dallas
DevOps
Azure
AWS
Cybersecurity
ISO 27001
NIST CSF
NIST 800-53
Zero Trust
Defense in Depth
Least Privilege
Threat Modeling
Management
Agile
Apply
≈ $105k – $215k per year (Estimated) • Remote (Canada) • 4+ years exp
AI/ML
Claude
Claude Code
LLM
OpenAI Codex
Human-in-the-Loop
DevOps
Azure
CI/CD
AWS
Kubernetes
GitHub
Cybersecurity
Snyk
Trivy
CodeQL
Wiz
Dependabot
Kyverno
BeyondTrust
Apply
≈ $70k – $194k per year (Estimated) • In office • Internship • Bachelor's Degree • Cincinnati
Python
Apply
≈ $24k – $67k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Tijuana
Python
JavaScript
Ruby
PowerShell
C#
C++
C#
.NET
DevOps
Jenkins
Git
AWS
Docker
Management
Jira
Agile
Apply
≈ $54k – $155k per year (Estimated) • In office • Full-Time • 5+ years exp • Singapore
Python
SQL
PowerShell
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Diamond Model
IBM QRadar
SIEM
Apply
In office • Internship • Bachelor's Degree • Ho Chi Minh City
Python
JavaScript
Java
TypeScript
C#
AI/ML
Copilot
Cursor
Claude
LLM
Frontend
Vue.js
Angular
React.js
DevOps
Azure
AWS
Apply
$48k per year • In office • Bachelor's Degree • Moscow
Python
PowerShell
C++
Bash
AI/ML
Red Teaming
DevOps
Linux
Windows
TCP/IP
DNS
VPN
Cybersecurity
Metasploit
Nmap
Cobalt Strike
BloodHound
Active Directory
SIEM
DLP
Apply
≈ $30k – $54k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
AI/ML
Anomaly Detection
DevOps
Terraform
Ansible
CloudFormation
CI/CD
Jenkins
AWS
AIOps
SLI/SLO/SLA
Management
ITSM
Apply
≈ $24k – $53k per year (Estimated) • In office • Full-Time • Moscow
Python
SQL
Scala
Python
pySpark
Databases
PostgreSQL
Apache Kafka
AI/ML
Hadoop
Spark
AI Agents
NLP
GigaChat
LLM
RAG
DevOps
OpenShift
Prometheus
CI/CD
Jenkins
Docker
Kubernetes
Bitbucket
Apply
≈ $17k – $44k per year (Estimated) • In office • 4+ years exp • Bengaluru
Python
JavaScript
TypeScript
Node JS
Python
FastAPI
Node JS
Nest.JS
Databases
Azure Cosmos DB
Frontend
Vue.js
React.js
DevOps
CI/CD
Apply
≈ $121k – $238k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
≈ $121k – $238k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
≈ $41k – $72k per year (Estimated) • In office • 2+ years exp • High School Diploma • Encino
Apply
Remote (likely United States) • 1+ year exp • High School Diploma
Apply
≈ $90k – $198k per year (Estimated) • Remote (likely United States) • 5+ years exp • Bachelor's Degree
AI/ML
LLM
Apply
≈ $121k – $238k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
≈ $121k – $238k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
≈ $52k – $109k per year (Estimated) • In office • Part-Time • 1+ year exp • High School Diploma • Independence
Apply
≈ $69k – $175k per year (Estimated) • In office • Full-Time • 4+ years exp • High School Diploma • Independence
Apply
≈ $36k – $62k per year (Estimated) • In office • High School Diploma • Independence
Analytics
Microsoft Excel
Apply
See all jobs
This is one of many
897,836 more open roles from verified company boards, updated every day.