LinkedIn

LinkedIn

Posted via SmartRecruiters

Staff Information Security Engineer - Detection Engineering

Posted Aug 25, 2026

Role at a glance

Salary
$156K – $255K/yr
Location
Mountain View, California, United States
Work arrangement
Hybrid
Employment
Contract
Experience
5+ years in security engineering, detection engineering, or incident response
Education
BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.

Spotted an issue?

We’ll check it against the original posting.

Log in to report

Role Summary

AI-generated

The Detection Engineering team within LinkedIn’s Information Security organization protects members, data, and infrastructure by developing and maintaining high-quality detections. This Staff Security Engineer role architects, builds, and operates detections across endpoint, identity, cloud, and SaaS while driving detection strategy, validation, telemetry quality, and response automation.

What You'll Do

  • Define detection strategy and roadmap across priority threat scenarios and emerging attacks
  • Partner with Incident Response, Threat Intelligence, Cloud, and IAM teams to develop production detections and lead purple-team validation
  • Design detections-as-code with version control, CI/CD, testing, and staged rollouts
  • Lead adversary emulation and threat hunting, and convert findings into resilient detections
  • Build incident-response automation for triage, enrichment, containment, and case workflows
  • Establish detection quality metrics, maintain telemetry reliability, and mentor engineers

Generated from the employer's posting. Verify important details before applying.

View full posting

Qualifications

5+ years in security engineering, detection engineering, or incident response; 2+ years technical leadership; expertise with SIEM/XDR/EDR and cloud provider telemetry; experience with Python, KQL/SQL, detections-as-code, ATT&CK, schemas, telemetry pipelines, SIGMA, and adversary emulation.

Required

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience
  • 5+ years in security engineering, detection engineering, or incident response
  • 2+ years technical leadership
  • Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP)
  • Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)
  • Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale
  • Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics
  • Experience designing schemas and data models (e.g., ASIM/OSSEM-like) and telemetry pipelines

Preferred

  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience
  • 8+ years of experience in detection engineering, with 3+ years of experience in a technical leadership role
  • Rigorous approach to detection quality (SNR, precision/recall, false-positive rate, latency) and measurement
  • Experience operating detections over billions of events/day and multi-region data pipelines
  • Building detection testing harnesses, synthetic signal, and adversary emulation at scale
  • Familiarity with identity/security signals (AAD/Okta/SSO), endpoint internals (Windows/Linux/macOS), and SaaS logs
  • Applied analytics/ML for anomaly detection, risk scoring, or enrichment (with robust evaluation)
  • Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection engineering workflows

Original job description

Content provided by the employer

Company Description

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

Job Description

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.

This role will be hybrid in LinkedIn’s Mountain View office location.

About the Team


LinkedIn’s Information Security organization protects our members, data, and infrastructure by building robust defenses, detecting attacker activity early, and partnering across engineering to  reduce risk.

The Detection Engineering team within InfoSec automates identification and contextualization of attacker activities at LinkedIn and partners across Incident Response, Threat Intel, Red/Purple Team, Product Security, IAM, and Cloud to develop and maintain high-quality detections. The team also supports log ingestion, schema design and normalization, incident support, tooling and automation, threat hunting, and audit assistance.

About the role

As a Staff Security Engineer in Detection Engineering, you will architect, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS. You’ll drive strategy and technical design through hands-on implementations—detections-as-code, telemetry modeling, and rigorous efficacy metrics (signal-to-noise, precision/recall, latency). You’ll lead purple-team validation and adversary emulation to turn TTP-driven hypotheses into resilient, low-noise production detections, and you mentor peers via standards and code reviews. This is a hands-on, staff-level role owning detection strategy, architecture, and mentoring.
 

Responsibilities

  • Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn

  • Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple-team validation.

  • Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.

  • Lead adversary emulation exercises to validate detection coverage; develop synthetic signal and test harnesses.

  • Proactive threat hunting to discover unknown attacker activity; design hunt playbooks and convert findings into detections.

  • Build IR automation (SOAR/Logic Apps) to orchestrate triage, enrichment, containment, and case workflow.

  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and collaborate with TI to turn reports into testable hypotheses.

  • Build and maintain a SIGMA-based detection content library; translate SIGMA to KQL/SQL where applicable.

  • Own telemetry quality: schemas, enrichment, normalization, and data reliability SLIs/SLOs.

  • Establish and monitor detection quality metrics (signal-to-noise ratio, precision/recall, false-positive rate, alert latency, lift); drive continuous tuning.

  • Lead incident retros to add resilient post-incident detections and suppress noisy patterns.

  • Mentor engineers; establish standards, code reviews, and guidance for detection engineering best practices.

  • Participate in on-call for critical detection pipelines and high-severity investigations.

Qualifications

Basic Qualifications

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience. 

  • 5+ years in security engineering, detection engineering, or incident response

  • 2+ years technical leadership.

  • Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP).

  • Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL)

  • Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.

  • Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.

  • Experience designing schemas and data models (e.g., ASIM/OSSEM-like) and telemetry pipelines.

  • Experience with SIGMA rule authoring and translation; adversary emulation/purple-team experience.

Preferred qualifications

  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience. 

  • 8+ years of experience in detection engineering, with 3+ years of experience in a technical leadership role

  • Rigorous approach to detection quality (SNR, precision/recall, false-positive rate, latency) and measurement.

  • Experience operating detections over billions of events/day and multi-region data pipelines.

  • Building detection testing harnesses, synthetic signal, and adversary emulation at scale.

  • Familiarity with identity/security signals (AAD/Okta/SSO), endpoint internals (Windows/Linux/macOS), and SaaS logs.

  • Applied analytics/ML for anomaly detection, risk scoring, or enrichment (with robust evaluation).

  • Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection engineering workflows.

  • Relevant certifications (e.g., GCTI, GCDA, GCFA, GIAC-blue); publications or open-source contributions in detections.

 

Suggested Skills:

  • Detection Engineering

  • Technical Leadership

  • KQL/SQL

  • Detection-as-code


 

You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices.

The pay range for this role is $156,000 to $255,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Additional Information

Equal Opportunity Statement 

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.
Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance ​

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement ​

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates 

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

LinkedIn

About the company

LinkedIn

Large Enterprise

LinkedIn is a globally recognized social networking platform designed specifically for professionals to connect, share, and grow their careers. Founded in 2002, it enables users to build professional profiles, network with industry peers, and discover job opportunities across various sectors. LinkedIn also offers a suite of tools for companies, including talent recruitment solutions and branding opportunities, helping organizations to engage with potential candidates and promote their corporate identity. With millions of users worldwide, LinkedIn is a vital resource for career development and professional networking.