← Back to results

detection-engineering jobs in San Diego

$118,500 – $207,750 · Posted 6 days ago

Lead the design and implementation of enterprise security enforcement technologies, including SIEM platforms, endpoint security, threat detection, and incident response systems. Develop and maintain a forward-looking cybersecurity technology roadmap aligned with NIST frameworks and business objectives, evaluating emerging threats and technologies to strengthen organizational security capabilities.… Conduct threat hunting, penetration testing, and detection engineering activities while driving automation of security controls, policy enforcement, and response across complex technology environments. Mentor cybersecurity teams and influence enterprise security strategy across large organizations, with demonstrated experience securing AI-enabled solutions and understanding AI-specific security considerations.

San DiegoLast seen 4 days ago
$117,000 – $130,000 · Posted 17 days ago

The Cybersecurity Analyst leads Bumble Bee's day-to-day cybersecurity operations, investigating and responding to security incidents, hunting threats, and tuning detection tooling. The role owns the full incident response lifecycle, manages vulnerability remediation, optimizes SIEM platforms, conducts security risk assessments for platforms and vendors, and maintains compliance through access control reviews and policy development.… The analyst builds incident response playbooks, monitors threat intelligence and CVE disclosures, and advises on third-party cyber risk. The position requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management, MITRE ATT&CK framework, and knowledge of NIST, SOC, and ISO standards.

San DiegoLast seen 15 days ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
Posted 1 month ago

This is a hands-on security engineering role focused on running Saronic's cyber threat intelligence program. The engineer will track nation-state and advanced criminal adversaries targeting the defense industrial base, operationalize indicators and TTPs into detections and hunts, produce finished intelligence products, and fuse external threat feeds with internal telemetry to prioritize real exposures.… The role requires 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis with demonstrable experience tracking sophisticated or state-sponsored adversaries.

San DiegoLast seen 29 days ago