Abnormal Security Logo

Abnormal Security

Sr. Detection Engineer

Sorry, this job was removed at 06:53 p.m. (IST) on Monday, Jun 23, 2025
Be an Early Applicant
In-Office
Bangalore, Bengaluru, Karnataka
In-Office
Bangalore, Bengaluru, Karnataka

Similar Jobs

6 Hours Ago
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Big Data • Cloud • Digital Media • Machine Learning • Mobile • Software • Industrial
The role involves threat hunting, detection engineering, collaborating with teams, and supporting cybersecurity initiatives to improve defenses against threats.
Top Skills: AWSAzureEdrGCPGoPowershellPythonSIEMSoar
3 Days Ago
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Security • Software • Cybersecurity
The Senior Security Developer role involves enhancing detection capabilities, maintaining code quality in Python and YAML, and researching threat analysis to improve security operations. Responsibilities include developing reliable detection systems and collaborating within the team to innovate detection methods.
Top Skills: GitKibanaPythonSigmaWazuhYaml
15 Minutes Ago
In-Office
Industrial Area SSI, Rajaji Nagar, Bangalore, Karnataka, IND
Senior level
Senior level
Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
The Senior Architect - BMS will design and implement software for battery management systems, lead cross-functional teams, manage design patterns, mentor junior engineers, and ensure compliance with industry standards.
Top Skills: Azure DevopsBattery Management SystemsCloudDevOpsEmbedded CMatlabReal-Time Operating SystemsSimulink
About the Role

Abnormal Security is looking for a Senior Detection Engineer to join our Security & Privacy team. As a cybersecurity leader, we continuously adapt to threat actor behaviors by building resilient detection logic and automated response mechanisms. In this role, you’ll take ownership of the SIEM platform(s) by administering, optimizing, and building high-fidelity detection content. You will also drive automation initiatives using SOAR platforms, working closely with Cyber Defense analysts, Security Engineering, and broader infrastructure teams to improve detection efficacy and incident response at scale.

What you will do
  • SIEM Engineering & Administration: Own the administration and optimization of our SIEM platform. Ensure ingestion, normalization, parsing, correlation, and search performance are tuned for security use cases.
  • Detection Engineering: Create and maintain detection content to identify malicious behaviors, suspicious activities, and policy violations. Continuously tune rules and logic to reduce false positives and improve fidelity.
  • SOAR & Security Automation: Design and implement automation playbooks to streamline incident triage, enrichment, response, and escalation workflows using SOAR platforms.
  • Threat-Informed Detection: Collaborate with Threat Intelligence and Incident Response teams to operationalize attacker TTPs into automated detections mapped to frameworks like MITRE ATT&CK.
  • Content Development: Build custom queries, dashboards, and visualizations in the SIEM to provide insights to stakeholders and measure security control efficacy.
  • Detection Lifecycle Management: Define and implement processes to govern the full lifecycle of detections — from ideation and development to validation, deployment, and tuning.
  • Cross-Team Collaboration: Work with Infrastructure, Application Security, and IT teams to ensure comprehensive coverage of logs and telemetry and to support response automation.
  • Documentation & Enablement: Maintain documentation for detection rules, automation workflows, and SOPs. Train analysts on how to use and improve detection content.
Must Haves
  • Bachelor’s Degree in Information Security, Computer Science, Engineering, or equivalent practical experience.
  • 5+ years of experience in cybersecurity, with a focus on SIEM and detection engineering.
  • Hands-on experience administering one or more SIEM platforms (e.g., Splunk, Sentinel, Chronicle, QRadar, Sumo Logic, ELK).
  • Strong knowledge of query languages (e.g., SPL, KQL, SQL) and ability to write performant and accurate detection logic.
  • Experience with SOAR platforms (e.g., Tines, Torq, Cortex XSOAR, or Splunk SOAR) and automation playbook development.
  • Deep understanding of attacker TTPs, detection use cases, and incident response workflows.
  • Good scripting skills (e.g., Python, PowerShell, Bash) to support data parsing, enrichment, or automation.
  • Excellent communication skills and a team-oriented mindset.
Nice to Haves
  • Security certifications such as GCIH, GCDA, GCTI, OSCP, or Splunk Certified Admin/User.
  • Experience with threat detection in cloud environments (AWS, Azure, GCP).
  • Familiarity with EDR tools, log forwarding agents, cloud-native logging pipelines, and enrichment platforms.
  • Understanding of CI/CD pipelines and how to integrate detection logic testing and deployment into them.
  • Exposure to machine learning or behavior-based detection strategies.

#LI-UC1

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account