Threat Detection Engineer - Security Operations
ID.meUSA3w ago
SecurityOperationsEngineeringremotecurated-jd
Job description
Threat Detection Engineer - Security Operations at ID.me.
About the role
Join our security engineering and operations team to build and refine high-fidelity detection systems. You will focus on scaling our security analytics while integrating advanced AI workflows to identify and mitigate modern threats.
Key facts
What you'll do
- Create and manage detection logic within SIEM and SOAR platforms like Splunk, Google Chronicle, and Elastic.
- Develop detection-as-code using Python and YAML formats such as Sigma or YARA-L.
- Build AI-augmented pipelines for anomaly scoring, embedding-based similarity search, and log analysis.
- Design workflows using LLM APIs to handle alert enrichment, summarization, and classification.
- Identify and defend against AI-specific risks including prompt injection, model abuse, and data exfiltration.
- Query and normalize large datasets using Snowflake and SQL.
- Deploy detection infrastructure via GitOps and Terraform.
- Participate in a 24x7 on-call rotation and perform post-incident reviews.
Requirements
- 2-4 years of experience in security operations or security engineering.
- Proficiency with Python and SQL.
- Hands-on experience with Splunk, Elastic Stack, or Google SecOps.
- Practical knowledge of detection logic formats like Sigma or YARA-L.
- Demonstrated AI literacy, including experience with LLM APIs, RAG, or agentic workflows.
- Understanding of AI/ML failure modes and security threats like model poisoning.
- Familiarity with MITRE ATT&CK frameworks and Infrastructure-as-Code tools.
Nice to have
- Certifications such as GCIH, GCIA, GCFA, or Security+.
- Experience with GCP, GKE, and cloud-native workload monitoring.
- Background in building SOAR integrations or using agentic frameworks like LangChain or LlamaIndex.
- Familiarity with Snowflake Security Data Lake.
- Experience with red teaming or evaluating LLM security weaknesses.
Skills & tools
- Python, SQL, YAML, Terraform, Git.
- Splunk, Elastic, Google Chronicle, Logstash.
- LLM APIs (OpenAI, Anthropic, Google Gemini), LangChain, LlamaIndex.
- MITRE ATT&CK, YARA-L, Sigma.
Practical notes
- Compensation includes base salary, bonus, equity, and a full benefits package (medical, 401k, PTO, parental leave, etc.).
- Candidates must be based in the U.S. and able to work on-site.
- The company provides guidelines regarding the use of AI tools during the application and interview process.