
Sr Detection Engineer
Chicago, ILJobSeen 1 day agoSeen in employer's feed 1 day ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Chicago, IL, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Senior Detection Engineer at Cboe writes and validates production detection logic across multiple telemetry sources, builds testing infrastructure, and collaborates with threat hunting and incident response teams.
Skills & qualifications
Skills
Qualifications
Full job description
Job Description
At Cboe, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
We’re building inclusive ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. Our Associate Resource Groups champion diversity, equity and inclusion, giving associates a safe space to network, share ideas and create opportunities.
Sound like the place for you? Join us!
The Security Operations team is hiring a Senior Detection Engineer.
The Senior Detection Engineer is a hands-on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role authors the rules, then executes the techniques those rules are meant to catch, building the tooling, sandboxes, and reusable test content required to demonstrate coverage rather than assume it. A detection is not finished when it is written. It is finished when someone has run the attack against it, confirmed it fired, confirmed it stayed quiet on benign activity, and left behind a test case that will re-confirm both after the next platform change.
The work spans endpoint, identity, cloud, SaaS, network, and application telemetry. The role requires fluency in attacker tradecraft at a mechanical level: how a technique actually executes, what artifacts it produces, and which of those artifacts are reliable enough to build durable detection logic on. This position partners closely with Threat Hunting, Incident Response, and Security Engineering to ensure detection coverage is measured continuously rather than assumed.
To set expectations clearly, this is a detection authoring and validation role, not a data pipeline role. Log source onboarding, parser development, and ingestion engineering are owned elsewhere. You will need to understand our telemetry well enough to know what is and is not detectable with it, and you will be expected to raise gaps when the data cannot support a detection, but building the pipes is not the job.
In this role you’ll be responsible for:
Writing, tuning, and maintaining production detection logic across SIEM, EDR, identity, and cloud platforms, with explicit attention to fidelity and false positive cost
Validating every detection by executing the technique it targets, so that no rule reaches production unproven
Building and maintaining internal tooling that simulates adversary behavior on demand, making detection testing repeatable rather than manual
Building reusable validation packages and automated regression testing so coverage is re-verified continuously and after every agent, platform, or configuration change
Building and operating sandbox and detonation infrastructure, including disposable, instrumented environments for exploit triage, malware analysis, and safe technique development
Evaluating newly published proof-of-concept exploit code to determine whether it functions, what telemetry it generates, and whether Cboe is exposed, then converting the answer into detection or hunting content
Producing threat hunting validation content, including seeded artifacts, known-truth datasets, and repeatable test cases that establish whether a hypothesis is testable with the data we hold
Automating the repeatable work: scheduled technique execution, telemetry collection, coverage reporting, and detection performance measurement
Applying AI and LLM tooling where it measurably shortens cycle time, including agentic workflows for triage and enrichment, automated analysis of exploit and malware code, detection and test-case drafting, and hunt hypothesis generation
Conducting security testing of internally built web applications and APIs, and translating findings into detection requirements as well as remediation guidance
Supporting Incident Response during complex investigations with concrete attacker tradecraft insight, and closing the loop by building detections for what the investigation surfaces
Documenting and handing off work so that tooling, environments, and test content can be operated by others independently
Skills and Requirements
The ideal candidate has:
5+ years of hands-on security engineering experience with substantial detection authoring content, and the ability to speak concretely about detections you built, how you validated them, and how they performed in production
Strong command of at least one detection query language (KQL, Sigma, YARA-L, or equivalent) and the judgment to recognize when logic is too brittle or too broad to ship
Practical knowledge of attacker techniques across Windows and Active Directory, Entra ID, cloud platforms (AWS, Azure), SaaS, and containerized workloads, at the level of execution mechanics rather than technique names
The ability to read unfamiliar exploit or malware code and identify the observable artifacts worth detecting on
Real fluency in at least one language used to write tooling (Python, Go, C#, PowerShell, bash, or equivalent
Working knowledge of the telemetry itself, including Windows event logs, EDR process and network events, cloud audit logs, and identity sign-in data, and where each is unreliable, incomplete, or trivially evaded
Comfort building and tearing down test infrastructure using virtualization, containers, infrastructure-as-code, and CI/CD
A disciplined approach to false positives, alert quality, and the operational burden that detections place on analysts
Clear technical writing aimed at engineers, including detection documentation and analyst-facing response guidance
High ethical standards and demonstrated discipline around authorization, scope, blast radius, and handling of sensitive data
Bachelor’s degree or equivalent practical experience You’ll really stand out with:
Public detection content, tooling, or research that we can review
Hands-on experience with atomic testing frameworks or continuous control validation at scale
Use of MITRE ATT&CK as a coverage and gap-analysis instrument rather than a reporting label
Concrete AI engineering experience, such as agentic workflows, tool and MCP integration, or testing LLM-application abuse cases including prompt injection
Reverse engineering, Windows internals, or EDR telemetry and evasion research
Experience operating in regulated or large enterprise environments, especially financial services
A track record of mentoring engineers or building internal training material
Curiosity, adaptability, and a continuous improvement mindset
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Senior AI / Machine Learning Engineer — Fraud DetectionAdobe · San Jose, CA (Hybrid) · $152–265K/yrPosted 3w agoPosted 3w ago
Senior Data Scientist, ML— Fraud Detection & EffectivenessAdobe · San Jose, CA (Hybrid) · $133–236K/yrPosted 3w agoPosted 3w ago
Senior Solution Engineer - NonprofitsSalesforce · Chicago, IL · $113–152K/yrPosted 6 days agoPosted 6 days ago
Senior Technical Support EngineerLangChain · Remote · US · $130–195K/yrPosted 1w agoPosted 1w ago
Senior Partner Solution EngineerSalesforce · Remote · US · $123–273K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.