Senior Threat Detection Engineer

Cribl · Remote - United States · Engineering

Posted 2026-10-07

Apply for this role →

Why You’ll Love This Role

Cribl builds telemetry infrastructure for some of the world's biggest security teams. Now we're looking for someone to protect Cribl itself. You'll join Cribl's internal security team, Team Alpine, to run detection as code. Our team runs a detection as code pipeline where rules live in Git, are tested in CI, and deploy to our SIEM automatically. AI agents watch for coverage gaps and help review every change.

This is a hands-on senior role covering the whole detection lifecycle. You'll hunt for threats nobody has written a rule for yet, turn what you find into detections, and keep the log pipelines behind those detections healthy. For the first [6–12] months you'll also be a core part of our incident response rotation while we build out that function. You'll lead investigations, and what you learn will feed straight back into the detections.

If you want your work to show up in production quickly, and you like owning the data as well as the rules, this role is for you. You will partner closely with Product Security, IT, and Legal teams, and report to the Sr. Director, Security Engineering and Operations under the CISO.

As An Active Member Of Our Team, You Will…

Detection Engineering

Design, build, test, and tune detections as code (KQL) through a GitOps workflow: issue, pull request, unit and back-testing, then automated deployment

Map detections to MITRE ATT&CK, find coverage gaps, and decide where to invest next based on our threat model

Review new community and vendor rule releases, such as Sigma, and decide what to adopt, adapt, or skip

Cut alert noise by tuning, retiring rules that no longer earn their place, and tracking detection quality metrics

Threat Hunting

Plan and run hypothesis-driven hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry

Use adversary emulation to generate test events for detections that have nothing to fire on yet

Turn hunt findings into durable detections, documentation, and backlog items

Incident Response (initial [6–12] months)

Take part in the IR rotation: triage, scope, contain, and investigate security incidents from first alert to closure

Run retrospectives and turn the lessons into new detections, playbook updates, and fixes to visibility gaps

Write and maintain runbooks so others on the team can respond consistently

Detection Infrastructure & Log Pipelines

Assist in ownership of the health of security log flow: onboard new sources, maintain parsing and normalization, and monitor for dropped, delayed, or malformed data

Assist and Build and maintain data pipelines with Cribl Stream to route, enrich, and reduce telemetry before it reaches the SIEM

Maintain the CI/CD and automation behind the detection program, including GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and PR review

Across the Team

Work independently, and design the processes, standards, and tools that help others work well

Mentor teammates through code review, pairing, and clear documentation

Work with IT, Infrastructure, Engineering, and GRC to close visibility gaps and improve detection coverage

This position will require stand-by, on-call, or off-hours duties

If You’ve Got It - We Want It

[5+] years in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response

Experience writing and maintaining detections as code in a modern SIEM

Strong Python skills and comfort with Git-based workflows, code review, and CI/CD

Strong in KQL for writing detection queries

Working knowledge of MITRE ATT&CK and how to use it for coverage analysis, not just labeling

Experience investigating incidents in cloud (AWS, GCP, and/or Azure), SaaS, and identity providers

Hands-on experience with log pipelines: getting data in, parsing it, and fixing it when it breaks

The judgment to separate a real signal from noise, and to know when to escalate

Clear writing for both technical and non-technical audiences: incident summaries, runbooks, detection docs

Uses AI as a routine part of engineering work, with concrete examples of how it has changed how you build, test, or investigate

Bonus: experience with Cribl Stream or other telemetry pipeline tools

Bonus: experience with Sigma rules, adversary emulation (Atomic Red Team, Caldera, or similar), or purple teaming

Bonus: experience building agentic or AI-assisted workflows for security operations

Bonus: certifications such as GCIH,GCDA, or equivalent experience

#LI-KJ1

#LI-Remote

The salary for this role is dependent on geographic location and will be based on the individual candidate's job-related knowledge, skills, and experience.

In addition to base salary, for sales and some sales-adjacent roles, employees are eligible to earn incentive compensation (commission). For all other roles, employees are eligible to participate in the Cribl Corporate Bonus Program.

In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), and equity.

Base Salary Range

$108,000—$169,000 USD

Apply for this role →

← Back to all jobs