Staff Information Security Engineer - Detection Engineering
LinkedIn · Remote
📍 Remote, UNITED STATES, usvia smartrecruitersPosted 2026-08-28
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to LinkedIn.
LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.
Join us to transform the way the world works.
At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. This role may be remote or hybrid. At LinkedIn, hybrid roles are performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. Remote roles are performed from the designated home work location upon time of hire, and any changes to this home work location requires a review of remote status and approval.
This role can be remote anywhere in the United States or can be hybrid in LinkedIn’s Mountain View office location.
About the Team
LinkedIn’s Information Security organization protects our members, data, and platforms by building resilient security controls, detecting threats early, and partnering across engineering to reduce risk at scale.
The Detection Engineering team sits at the center of LinkedIn’s threat detection ecosystem. We partner closely with Incident Response, Threat Intelligence, Red and Purple Teams, Product Security, Identity & Access Management, and Cloud Security to identify, contextualize, and detect adversary activity across the enterprise. Beyond developing and maintaining high-fidelity detections, we drive the security telemetry strategy through log onboarding, schema design and normalization, automation, threat hunting, incident response support, and audit enablement. Our mission is to continuously improve LinkedIn’s ability to detect, investigate, and respond to evolving threats with speed and precision.
About the role
As a Staff Security Engineer on the Detection Engineering team, you will define and drive LinkedIn’s detection strategy across endpoint, identity, cloud, and SaaS environments. You will architect, build, and operate high-signal detection capabilities using modern detections-as-code practices, telemetry modeling, and data-driven effectiveness measures, including precision, recall, signal-to-noise ratio, and detection latency.
You will work from adversary tactics, techniques, and procedures (TTPs) to design resilient detection coverage, partnering with Red and Purple Teams to validate effectiveness through adversary emulation and attack simulation. As a technical leader, you will establish engineering standards, influence security architecture, mentor fellow engineers through design and code reviews, and drive strategic investments that improve detection fidelity, scalability, and operational efficiency. This is a hands-on staff-level role focused on technical leadership, architecture, and execution.
Responsibilities
Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn
Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple-team validation.
Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.
Lead adversary emulation exercises to validate detection coverage; develop synthetic signal and test harnesses.
Proactive threat hunting to discover unknown attacker activity; design hunt playbooks and convert findings into detections.
Build IR automation (SOAR/Logic Apps) to orchestrate triage, enrichment, containment, and case workflow.
Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and collaborate with TI to turn reports into testable hypotheses.
Build and maintain a SIGMA-based detection content library; translate SIGMA to KQL/SQL where applicable.
Own telemetry quality: schemas, enrichment, normalization, and data reliability SLIs/SLOs.
Establish and monitor detection quality metrics (signal-to-noise ratio, precision/recall, false-positive rate, alert latency, lift); drive continuous tuning.
Lead incident retros to add resilient post-incident detections and suppress noisy patterns.
Mentor engineers; establish standards, code reviews, and guidance for detection engineering best practices.
Participate in on-call for critical detection pipelines and high-severity investigations.
Basic Qualifications
BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.
5+ years in security engineering, detection engineering, or incident response
2+ years technical leadership.
Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP).
Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)
Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.
Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.
Experience designing schemas and data models (e.g., ASIM/OSSEM-like) and telemetry pipelines.
Experience with SIGMA rule authoring and translation; adversary emulation/purple-team experience.
Preferred qualifications
BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience.
8+ years of experience in detection engineering, with 3+ years of experience in a technical leadership role
Rigorous approach to detection quality (SNR, precision/recall, false-positive rate, latency) and measurement.
Experience opera
More Remote jobs
Remote jobs · Browse all locations