Senior Detection Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
We're hiring a Senior Detection Engineer to be the blue team voice inside the Defensive Agent team. You'll sit between Product and Engineering as the person who defines what 'correct' means. When an attack technique is detected, you decide what remediation that claim requires. Your judgment becomes the ground truth.
This is not a coding role and it is not a product management role. Product owns the roadmap, Engineering owns the implementation, and our AI researchers own how the agents reason. You own the domain truth all three depend on, and you make it concrete enough to build and measure against. If you've spent your career being the person in the room who knows how the tools really behave, this is a seat where that knowledge teaches a system instead of firefighting alerts.
PRODUCT DIRECTION & REQUIREMENTS
- Partner with Product to turn EDR effectiveness and tuning ambitions into concrete, buildable requirements.
- Translate blue team workflows and pain into prioritized product outcomes, and push back when a proposed feature or agent behavior would not hold up in a real SOC.
- Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against them before customers see them.
- Serve as the standing domain reference for Engineering and AI research: available for design reviews, technique questions, and vendor behavior questions.
EDR & DETECTION DOMAIN OWNERSHIP
- Own deep, current knowledge of the major EDR and endpoint platforms at the console, policy, telemetry, and API level.
- Maintain fluency in how detection logic, prevention policy, exclusions, and tuning actually work in each product, including the differences between default and hardened configurations.
- Define the vendor-specific policy semantics, so a recommended change means the same thing across platforms that model it differently.
- Track platform changes, new detection capabilities, and vendor guidance, and keep our coverage model current as vendors ship.
- Define what a correct tuning recommendation looks like and grade agent output against that standard.
- Partner with the Attack team so technique coverage and detection expectations stay grounded in current adversary tradecraft.
WHAT YOU'LL BRING
EDR & BLUE TEAM EXPERTISE
- 6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time spent as a practitioner rather than an advisor.
- Hands-on operational experience administering and tuning EDR platforms in production — writing detections, managing policy and exclusions, and investigating real alerts.
- Deep understanding of what a SOC actually does with EDR output.
- Fluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurement.
- Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, and a clear view of where they help and where they mislead.
- Solid understanding of post-compromise attacker behavior and how each surfaces in endpoint and identity telemetry.
PRODUCT & COLLABORATION
- Demonstrated experience shaping a product or platform as a domain expert, whether in a security vendor, an internal tooling team, or a detection engineering function.
- Ability to influence without authority. You will not manage the engineers or own the roadmap, and you will still be expected to move both.
- Exceptional technical writing. Most of your leverage here comes from written artifacts — requirements, methodology docs, labeling guides, tuning content.
- Comfort translating between audiences: engineers, AI researchers, product managers, SOC analysts, and executives.
TECHNICAL FLUENCY
- Enough scripting ability, ideally in Python, to query APIs, inspect telemetry, and prototype an analysis.
- Comfort with SQL and with reasoning over large volumes of event and telemetry data.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Horizon3 ai
Explore Top Companies in this Space
Keeper Security
Cybersecurity / Information Technology / Enterprise Software
Sprinto
Information Technology / Cybersecurity / Enterprise Software
Spinnaker Support
Enterprise Software / IT Services / Cloud Solutions / Database Management
General Legal
Legal Services / Artificial Intelligence / Startup Support / Contract Management
Horizon3 ai
View Company ProfileHorizon3.ai is a leading cybersecurity firm that revolutionized the industry with NodeZero, the world's first fully autonomous penetration testing platform. Founded in 2019 by former US Special Operations and national security experts, the company shifts the paradigm from reactive defense to proactive offense. Under the hood, NodeZero acts as an automated ethical hacker, continuously discovering, exploiting, and providing remediation paths for critical vulnerabilities across on-premise, cloud, and hybrid environments. Their primary target audience includes enterprise CISOs, IT directors, and managed service providers (MSPs) who need to rigorously validate their security posture without the massive cost and infrequent cadence of traditional human pentesting. What sets Horizon3.ai apart in the crowded InfoSec market is its ability to safely execute real-world attack vectors in production environments at scale, allowing security teams to fix exploitable weaknesses before threat actors can weaponize them.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
