Senior Information Security Engineer - Detection Engineering

  • Full-time
  • Workplace Type: Hybrid or Remote
  • Career Track & Grade: IC3/8
  • Department: Engineering

Company Description

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

Job Description

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. This role may be remote or hybrid. At LinkedIn, hybrid roles are performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. Remote roles are performed from the designated home work location upon time of hire, and any changes to this home work location requires a review of remote status and approval.

This role can be remote anywhere in the United States or be hybrid in LinkedIn’s Mountain View office location.

About the Team

LinkedIn’s Information Security organization protects our members, data, and platforms by building resilient security controls, detecting threats early, and partnering across engineering to reduce risk at scale.

The Detection Engineering team is responsible for building and scaling LinkedIn’s threat detection capabilities. We partner closely with Incident Response, Threat Intelligence, Red and Purple Teams, Product Security, Identity & Access Management, and Cloud Security to identify, contextualize, and detect adversary activity across the enterprise. Our team develops and maintains high-fidelity detections while advancing the underlying security telemetry ecosystem through log ingestion, schema design, data normalization, automation, threat hunting, incident response support, and audit enablement.

About the Role

As a senior individual contributor, you will design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code practices, telemetry modeling, and data-driven efficacy measurements to continuously improve detection coverage and quality. Working from adversary TTPs and threat hypotheses, you will develop resilient, low-noise detections validated through purple-team exercises, adversary emulation, and real-world incident learnings. This is a hands-on engineering role focused on technical leadership, execution, and cross-functional collaboration

Responsibilities:

  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry; measure precision/recall, latency, lift, and signal-to-noise ratio.

  • Build detections-as-code with version control, CI/CD, unit/integration tests, staged canary rollouts, and safe rollback.

  • Author and maintain SIGMA rules; translate SIGMA to KQL/SQL as needed.

  • Integrate multi-cloud telemetry: Azure (Activity/Diagnostics), AWS (CloudTrail, GuardDuty), GCP (Cloud Audit Logs, SCC).

  • Operationalize Microsoft Defender XDR and Sentinel signals; leverage Entra ID controls (Conditional Access, sign-in risk).

  • Proactive threat hunting; create hunt playbooks and convert findings into detections.

  • Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow; integrate with ticketing/chat ops.

  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and turn reports into testable hypotheses.

  • Own telemetry quality for assigned pipelines: schemas/normalization (e.g., ASIM/OCSF-like), enrichment, data contracts, reliability SLIs/SLOs.

  • Participate in incident retros; add post-incident detections and suppress noisy patterns.

  • Participate in on-call for critical detection pipelines and high-severity investigations.

Qualifications

Basic Qualifications

  • BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience.

  • 3+ years in security, detection engineering or incident response.

  • Experience building detection content and analytics for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP).

  • Experience programming for detections/automation (e.g., Python) and query languages (e.g., KQL/SQL/SPL).

  • Experience with detections-as-code (tests, CI/CD, canary/rollback) at scale.

  • Experience with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics.

  • Experience with schemas/data models (e.g., OSSEM/ASIM-like) and telemetry pipelines.

Preferred Qualifications

  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience. 

  • Operating detections over large-scale, multi-region pipelines.

  • Detection testing harnesses, synthetic signal, and adversary emulation at scale.

  • Identity/security signals (Entra ID/Okta/SSO), endpoint internals (Windows/Linux/macOS), SaaS logs.

  • Applied analytics/ML for anomaly detection or risk scoring with robust evaluation.

  • Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection workflows.

  • Hands-on SIGMA authoring/translation; experience with adversary emulation/purple-team validation.

  • Experience with Microsoft Sentinel, Defender XDR, Entra ID; KQL, Python; GitHub Actions/Azure DevOps; Logic Apps; Azure Data Explorer/Kusto

  • Experience with Azure Activity/Diagnostics; AWS CloudTrail/GuardDuty; GCP Cloud Audit Logs/SCC

 

Suggested Skills:

  • Information Security

  • Detection Engineering

  • Detection as code

  • KQL

 

You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices.

The pay range for this role is $129,000 to $212,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Additional Information

Equal Opportunity Statement 

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.
Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance ​

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement ​

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates 

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice