TandemTrace
We’re hiring · Detection engineering

Senior AI
Detection Engineer.

We’re looking for a detection engineer who understands attacker behavior, knows how telemetry fails, and can use AI without lowering the standard of proof. You will build high-confidence detections and the evaluation systems that keep them useful.

Level
Senior
Focus
AI detection
Practice
Detection-as-code
Domain
Enterprise SOC
// 01 · The mission

Build detections that survive contact with reality.

TandemTrace is building the autonomous layer for the modern SOC. Our agents investigate alerts, correlate evidence, hunt for threats, and help security teams understand what happened across the tools they already use.

You will help turn adversary behavior and messy enterprise telemetry into reliable detection logic. You will also shape how AI proposes, tests, explains, and improves detections without confusing plausible output with verified security value.

The goal is not more rules. The goal is better security signal: grounded in attacker behavior, validated against evidence, measurable in production, and understandable by defenders.

// 02 · What you’ll build

Detection engineering with a feedback loop.

  • Design and implement detections across endpoint, identity, cloud, network, email, and application telemetry.
  • Develop detection-as-code workflows for versioning, testing, review, deployment, observability, and continuous improvement.
  • Use AI in the engineering loop to accelerate research, query generation, translation, testing, explanation, and tuning while enforcing evidence-based validation.
  • Build evaluation datasets and test harnesses that measure coverage, precision, robustness, drift, and false-positive behavior.
  • Research attacker techniques and translate them into detection opportunities, telemetry requirements, hunt logic, and investigation context.
  • Partner with product and engineering to make high-quality detection knowledge available to autonomous investigations and customer environments.
// 03 · Your toolkit

Behavior, telemetry, code, and models.

Detection logicSigma, YARA, correlation, behavioral analytics, and custom rules.
Query languagesKQL, SPL, ES|QL, SQL, or comparable security search languages.
Security stacksSIEM, EDR/XDR, identity, cloud, CNAPP, network, and email.
EngineeringPython, APIs, Git, CI/CD, testing, data transformation, and automation.
Adversary tradecraftMITRE ATT&CK, intrusion analysis, threat hunting, and validation.
Applied AILLM workflows, structured outputs, evaluation, grounding, and failure analysis.
// 04 · What you bring

Senior judgment. Hands-on execution.

  • Substantial hands-on detection-engineering experience in enterprise security operations, security products, or both.
  • A strong record of shipping and improving detections using real production telemetry and measurable operational feedback.
  • Deep understanding of attacker behavior and the telemetry required to observe it across multiple layers of the environment.
  • Strong coding and automation ability, especially with Python and modern software-development practices.
  • Practical experience applying AI or machine learning to security data, detection workflows, investigations, or engineering productivity.
  • Healthy skepticism and clear writing. You expose assumptions, document tradeoffs, and make technical decisions inspectable.
// 05 · Why this role

Help define how AI improves detection itself.

Most security teams have more detection content than they can validate, maintain, and connect to real investigations. This role is an opportunity to work on that problem at the system level, combining detection craft with autonomous reasoning and continuous operational feedback.

You will work directly with an experienced cybersecurity founder and a compact product team. Your work will influence the product’s detection knowledge, evaluation standards, threat-hunting capabilities, and technical credibility with serious security teams.

// Interested?

Show us what makes a detection trustworthy.

Send your LinkedIn profile or CV and a short note about a detection system, rule set, evaluation method, or engineering workflow you built or materially improved.

Apply by email ↗