NEW JOB OPENING
DETECTION ENGINEER (SPLUNK, CROWDSTRIKE & AWS SECURITY AUTOMATION)
IN REMOTE, USA!

 

Date Posted: 09/10/2026
Hiring Organization: Rose International
Position Number: 507316
Industry: Software/Financial Services/IT Company
Job Title: Detection Engineer (Splunk, CrowdStrike & AWS Security Automation)
Job Location: Remote, USA
Work Model: Remote
Shift: Standard CST Hours
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 12
Min Hourly Rate($): 75.00
Max Hourly Rate($): 85.00
Must Have Skills/Attributes: AWS, Python, Security
Experience Desired: Security engineering/detection engineering experience (4-7 yrs); Exposure to AI agent security/governance platforms (e.g., Onyx Security) (3-5+ yrs); SOAR platform experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar) (3-5+ yrs); Cloud security monitoring experience (AWS/Azure/GCP logging) (3-5+ yrs)
Preferred Education: Bachelor’s Degree
Preferred Certifications/Licenses: GCIA, GCDA, CrowdStrike CCFA/CCFR, Splunk Certified Power User/Admin, or AWS Security certifications

**C2C is not available**

 

Job Description
Preferred Education:
Bachelor's degree in computer science, Information Security, or related field, or equivalent hands-on experience (4+ years in place of degree is common in this field and reasonable to accept)

Preferred Certification:
• GCIA, GCDA, CrowdStrike CCFA/CCFR, Splunk Certified Power User/Admin, or AWS Security certifications

Required Skills:
• 4-7 years total security engineering/detection engineering experience, with at least 2 years touching multi-platform detection work (not single-tool)
• Hands-on detection engineering experience in Splunk (SPL) and CrowdStrike NG-SIEM/LogScale (CQL), including correlation searches, bucket()/groupBy() logic, and multi-source joins
• Working knowledge of Zscaler logging and how to build detections off proxy/DNS/SSL telemetry
• Practical experience with API-based integrations and AWS Lambda for security automation/orchestration (alert routing, enrichment, or automated response)
• Experience with ServiceNow Security Incident Response (SIR): case creation via API, field mapping, and workflow logic
• Familiarity with MITRE ATT&CK and translating adversary behavior into detection logic
• Strong cross-functional communication: able to work shoulder-to-shoulder with IR analysts and platform engineers, not just ship detections over the wall
• Scripting proficiency (Python preferred) for automation and API work

Preferred Skills:
• Exposure to AI agent security/governance platforms (e.g., Onyx Security) or willingness to ramp quickly on the tool - 3-5+ years
• SOAR platform experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)- 3-5+ years
• Experience building or supporting IR playbooks/runbooks in a live SOC
• Familiarity with UEBA or insider-risk detection concepts
• Cloud security monitoring experience (AWS/Azure/GCP logging)- 3-5+ years

Duties:
• Design, build, and tune detection rules and correlation logic across Splunk, CrowdStrike NG-SIEM (LogScale/CQL), Zscaler, and Onyx Security, with an emphasis on reducing false-positive rate and closing coverage gaps
• Build and maintain API- and Lambda-based orchestration pipelines that route alerts from detection platforms into ServiceNow Security Incident Response (SIR), enriching alerts with context before they reach a responder
• Partner with Detection Platform Engineering to align new detections with existing data models, ingestion pipelines, and the broader detection roadmap
• Work directly with Incident Responders (DFIR, Insider Risk) to understand investigative gaps and translate them into new or refined detection logic
• Support playbook development: partnering with responders to codify triage steps, escalation criteria, and containment actions into ServiceNow SIR workflows and SOAR-style automation
• Validate detections against live test data and known TTPs; document tuning decisions and false-positive rationale for audit and hand-off
• Participate in post-incident lessons-learned reviews, converting findings into detection or playbook updates
• Maintain detection-as-code practices: version control, peer review, and change documentation for all production detection logic


  • **Only those lawfully authorized to work in the designated country associated with the position will be considered.**

  • **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**

 

Benefits:
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.

California Pay Equity:
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.

Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

 

Apply Now

 

About Rose

  • Founded in 1993
  • Office Locations Across the U.S.
  • 150+ Clients: Corporations and Government Agencies
  • Employee Oriented Company
  • Challenging Assignments Across the U.S.
  • Continuous Professional Development

I believe the best thing that Rose HR has going for it is the incredible responsiveness. Everyone is very quick to reply to any concerns, and contacts the contracted employees very quickly and efficiently.

Kevin, Consultant

Each time I contacted Rose, I was completely satisfied with the great attention and customer service I received. Each person was extremely knowledgeable and patient with my concerns or questions.

Diana, Consultant

Any time I did have a question and called, the phone was always answered, and my question/concern was immediately resolved.

Sally, Consultant

I have been very pleased with my experience with Rose International. Everyone that I encountered was very helpful and courteous.

Stephanie, Consultant

As a contractor, I have to say that Rose International was by far the best agency I have worked for.

Q'testdalir, Consultant

EMPLOYEE COMMENTS

  • We want you to work with us, but don't take our word for it. Take a look at this sampling of employee comments. They speak for themselves.