1,434,312open jobs
83,785companies
217,826added this week
Browse all
Salary
≈ $51k – $89k per year (Estimated)
Location
Hybrid (Warsaw, Poland, Hyderabad, Pakistan, Guadalajara, Mexico)
Seniority
Middle
Employment
Full-Time

First seen by Alion on Sep 22, 2026.

Overview
Company
Impact
Profile match

F5

Your session could not be established. BIG-IP can not find session information in the request.
About F5

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Role Overview

The Security Engineer III, Detection Engineering is a career-level security engineering professional responsible for developing, testing, deploying, and continuously improving detection capabilities that support Security Operations. As part of the Security Operations Platform Engineering (SOPE) team, this role focuses on transforming threat intelligence, telemetry, and security requirements into reliable, actionable detections that improve visibility and reduce organizational risk. The engineer partners closely with Incident Response, Threat Intelligence, Logging Engineering, and platform engineering teams to build scalable, threat-driven detection capabilities while advancing automation, detection coverage, and operational maturity.

Primary Responsibilities
  • Develop and maintain custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows.
  • Analyze and improve detection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework, identifying gaps and prioritizing enhancements.
  • Partner with Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate emerging threats, investigations, and telemetry into actionable detection content.
  • Validate and tune detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives.
  • Automate and optimize detection engineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability.
  • Support onboarding of new log sources and security telemetry by collaborating with engineering and infrastructure teams to establish detection coverage across new environments and technologies.
  • Create and maintain detection documentation, runbooks, coverage assessments, and technical standards while participating in an engineering on-call rotation.
  • Help define detection strategy for AI and agentic systems (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs), and explore using AI to accelerate detection engineering workflows.

Wymagania

Required Skills / Qualifications
  • Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience.
  • 5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or a related discipline.
  • Experience developing, tuning, or maintaining detections within a SIEM, EDR, log analytics, or security monitoring platform.
  • Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies.
  • Strong understanding of attacker techniques, detection methodologies, and frameworks such as MITRE ATT&CK.
  • Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
Preferred Skills / Qualifications
  • Experience implementing Detection-as-Code practices, including Git-based workflows, automated testing, and CI/CD pipelines.
  • Experience with adversary emulation, atomic testing, purple-team exercises, or detection validation frameworks.
  • Experience performing detection coverage analysis and developing ATT&CK-based coverage roadmaps.
  • Experience onboarding log sources and building detections across cloud, endpoint, network, identity, or SaaS environments.
  • Experience with platforms such as CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic, or similar security technologies.
  • Familiarity with AI/LLM threat models (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs) or frameworks such as MITRE ATLAS and the OWASP LLM Top 10 — and interest in applying AI to accelerate detection engineering workflows.

Oferujemy

This is a full-time engineering role and is not a shift-based position. Participation in an engineering on-call rotation is required and may occasionally require support outside normal business hours during critical incidents, platform outages, or detection-related operational events. The Security Engineer III may be engaged as a subject matter expert during security incidents but is not responsible for primary incident response or SOC operations. Travel may be required up to 5%, including occasional international travel.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,434,312 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Warsaw
≈ $56k – $126k per year (Estimated) • In office • Full-Time • Amsterdam
Apply
≈ $50k – $114k per year (Estimated) • Hybrid • Full-Time • Rotterdam
AI/ML
Galileo
Apply
≈ $54k – $122k per year (Estimated) • In office • Full-Time • Noordwijk
Apply
≈ $71k – $180k per year (Estimated) • In office • Full-Time • Amsterdam
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
Agile
Apply
≈ $55k – $125k per year (Estimated) • Hybrid • Full-Time • Amsterdam
DevOps
CI/CD
Kubernetes
IAM
Windows
Cybersecurity
CyberArk
LDAP
Apply
$46k – $56k per year (net) • In office • Warsaw
Kotlin
QA
Appium
Apply
Business Analyst 10 hours ago
$54k – $68k per year • Remote (Poland) • Warsaw
SQL
DevOps
Rest API
Management
Agile
Scrum
UML
BPMN
Apply
System Analyst 10 hours ago
≈ $29k – $69k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Warsaw
SQL
DevOps
Rest API
SOAP
Management
Confluence
Jira
Agile
UML
BPMN
Apply
≈ $26k – $72k per year (Estimated) • In office • Full-Time • Warsaw
Apply
≈ $38k – $73k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Warsaw
SQL
DevOps
Rest API
SOAP
Management
UML
QA
Swagger
Postman
Apply
See all jobs
This is one of many
1,434,312 more open roles from verified company boards, updated every day.