Confirmed on the employer's own hiring board on Sep 28, 2026. First seen by Alion on Sep 23, 2026. CyberGate Defense scores C on the Alion truth index.
Detection Engineer
EXPERIENCE 5-8 years ENVIRONMENT Multi-client MSSP ROLE FAMILY Threat Detection & Security Analytics
Build Detections That Matter
CyberGate is seeking an experienced Detection Engineer to build, validate, and continuously improve threat detection capabilities across managed customer environments. You will turn threat intelligence, adversary behavior, incident findings, threat-hunting results, attack simulation outcomes, and customer risk requirements into reliable and scalable security analytics.
This is a hands-on engineering role at the intersection of SOC Operations, Cyber Threat Intelligence, Threat Hunting, DFIR, security engineering, automation, and security data. You will help evolve an intelligence-led SOC through detection-as-code, automated validation, cloud and identity analytics, measurable coverage engineering, and responsible use of AI-assisted tooling.
What You Will Do
· Design, develop, test, deploy, tune, and maintain detection rules, correlation logic, behavioral analytics, risk-based detections, queries, and enrichment across SIEM, XDR, EDR, NDR, UEBA, and cloud-native security platforms.
· Own the detection lifecycle from intake and prioritization through design, peer review, validation, approval, deployment, monitoring, tuning, periodic review, and retirement.
· Translate adversary tactics, techniques, and procedures, threat intelligence, VAPT findings, incidents, and threat-hunting outcomes into testable detection hypotheses and production use cases.
· Map detections to MITRE ATT&CK and relevant data sources; identify blind spots and develop prioritized, evidence-based coverage improvement plans.
· Create positive, negative, regression, and performance tests, using representative data, controlled attack simulation, purple-team exercises, and adversary emulation where appropriate.
· Use Git-based workflows and contribute to CI/CD pipelines for content review, testing, packaging, deployment, rollback, and post-deployment verification.
· Automate repetitive engineering activities using Python, PowerShell, Bash, REST APIs, platform SDKs, SOAR, or orchestration capabilities.
· Define telemetry requirements and work with engineering teams to improve parsing, normalization, enrichment, retention, latency, and data quality.
· Partner with SOC analysts to ensure detections include clear severity, triage context, investigation guidance, known limitations, and response recommendations.
· Maintain auditable documentation covering requirements, test evidence, approvals, versions, tuning decisions, dependencies, and outcomes.
What You Bring
· 5-8 years of relevant cybersecurity experience, including at least 3 years in detection engineering, SIEM content engineering, security analytics, threat hunting, SOC engineering, or a closely related discipline.
· Strong hands-on experience with one or more enterprise SIEM platforms such as Microsoft Sentinel, IBM QRadar, Splunk Enterprise Security, Stellar Cyber, Elastic Security, ArcSight, or LogRhythm.
· Advanced capability in relevant query or detection languages such as KQL, SPL, AQL, SQL, EQL, Lucene, YARA, or Sigma, with deep practical experience in at least one production ecosystem.
· Strong understanding of MITRE ATT&CK, attacker tradecraft, threat detection, log analysis, detection limitations, rule tuning, and evidence-based validation.
· Experience with security telemetry from endpoint, network, identity, email, firewall, DNS, proxy, WAF, cloud control plane, SaaS, and vulnerability platforms.
· Working proficiency in Python and REST APIs, plus experience with Git, code review, structured testing, JSON/YAML, and CI/CD concepts.
· Ability to troubleshoot complex cross-platform issues and clearly explain technical decisions to both technical and non-technical stakeholders.
· Strong documentation, collaboration, prioritization, and evidence-management skills in a multi-customer environment.
Experience That Will Help You Stand Out
· Detection-as-code, automated detection validation, attack simulation, purple teaming, or adversary emulation.
· Cloud-native and identity-focused detection engineering across Microsoft 365, Entra ID, Azure, AWS, or Google Cloud.
· Risk-based alerting, behavioral or entity analytics, security data lakes, or graph-based detection.
· AI-assisted detection engineering with strong human validation, data protection, and production-control practices.
· Experience with OT/ICS detection, containers, Kubernetes, DevSecOps telemetry, or complex MSSP/MDR environments.
· Exposure to regulatory or sector-specific customer requirements in the UAE or GCC.
Preferred Certifications
Certifications are valued but do not replace demonstrated engineering capability. Relevant examples include:
· Microsoft Certified: Security Operations Analyst Associate, Splunk security credentials, IBM QRadar certifications, or equivalent platform certifications.
· GIAC Certified Detection Analyst (GCDA), GIAC Certified Intrusion Analyst (GCIA), GIAC Cyber Threat Intelligence (GCTI), or comparable technical certifications.
· MITRE ATT&CK Defender training, purple-team credentials, or relevant cloud security certifications.
NICE Framework Alignment
The role aligns primarily with the NICE Defensive Cybersecurity Work Role (PD-WRL-001), with supporting alignment to Threat Analysis (PD-WRL-006) and Incident Response (PD-WRL-003).
What Success Looks Like
· Detections are documented, peer-reviewed, validated, approved, deployed, monitored, and periodically reassessed.
· Detection and telemetry health are visible, with failures and coverage gaps addressed using measurable evidence.
· Alert noise is reduced without creating unassessed loss of coverage.
· Analysts receive practical investigation context, and engineering changes remain fully traceable.
· Reusable content and automation improve delivery speed while preserving customer-specific controls and quality.

