Saronic Logo

Saronic

Security Engineer, Detection Engineering

Posted One Month Ago
Be an Early Applicant
In-Office
Austin, TX, USA
Mid level
In-Office
Austin, TX, USA
Mid level
Design, develop, and operate high-fidelity detection content and security data pipelines across endpoint, cloud, network, identity, and DLP telemetry. Implement detection-as-code with CI/CD and automated testing, map coverage to MITRE ATT&CK, build SOAR playbooks for automated response, support incident response, and partner across teams to close visibility gaps.
The summary above was generated by AI

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Security at Saronic is a force multiplier. We're seeking a Security Engineer at the senior-level or above on our Security Operations team with strong detection engineering experience. You'll design and develop high-fidelity detection content, build and operate the data pipelines that power our security operations, develop automation playbooks that accelerate response, and work across a uniquely diverse telemetry landscape spanning cloud infrastructure, embedded vessel platforms, corporate systems, and operational technology.

 

This role is heavily weighted toward detection engineering. You should think in terms of adversary behavior and telemetry coverage, not just alert triage. You'll own detections end-to-end: from identifying gaps in coverage, through designing and testing detection logic, to tuning and validating in production.

Key Responsibilities:
  • Design, build, test, and tune high-fidelity detection rules and analytic queries across endpoint, cloud, network, identity, and DLP telemetry sources

  • Develop and maintain detection content using detection-as-code practices including version-controlled logic, automated testing, and CI/CD deployment

  • Map detection coverage to MITRE ATT&CK, identify gaps, and prioritize new detection development based on threat intelligence and business risk

  • Engineer correlation rules, behavioral analytics, and anomaly-based detections that minimize false positives while surfacing real adversary tradecraft

  • Own the detection lifecycle from initial development through production tuning, performance monitoring, and retirement

  • Build and operate pipelines to ingest, normalize, enrich, and manage security telemetry at scale across diverse data sources, using Terraform and infrastructure-as-code practices to deploy and maintain logging and detection infrastructure

  • Design and maintain log collection, parsing, and enrichment configurations that ensure the right telemetry is available at the right fidelity for detection and investigation

  • Evaluate and onboard new telemetry sources as Saronic's infrastructure and threat landscape evolve

  • Monitor pipeline health, data quality, and ingestion reliability to ensure detections operate on complete and accurate data

  • Develop and manage automated response playbooks in SOAR platforms to accelerate containment and reduce analyst toil

  • Build automation that enriches alerts with contextual data, reducing investigation time and improving analyst decision-making

  • Support incident response efforts and translate lessons learned into improved detections and playbooks

  • Partner with SOC analysts, Cloud Security, Product Security, and IT teams to close visibility and detection gaps across environments

  • Collaborate with threat intelligence to ensure detection engineering is informed by current adversary TTPs relevant to defense, maritime, and autonomous systems

Required Qualifications:
  • 3+ years of hands-on experience in detection engineering, security operations, security automation, or a closely related security engineering role

  • Demonstrated experience designing, testing, and tuning detection rules and analytic queries across production security telemetry (endpoint, cloud, network, identity, or DLP)

  • Hands-on experience with SIEM platforms and proficiency with query languages such as SPL, KQL, or equivalent

  • Experience building and operating security data pipelines, including log ingestion, normalization, enrichment, and data quality management

  • Understanding of data engineering concepts including ETL pipelines, data modeling, schema design, and indexing as applied to security telemetry

  • Hands-on coding experience in Python, PowerShell, Go, or Rust for security automation, detection tooling, or pipeline development, and familiarity with Terraform for managing detection and logging infrastructure as code

  • Understanding of MITRE ATT&CK framework and its application to detection coverage and gap analysis

  • Ability to obtain and maintain a security clearance

Preferred Qualifications:
  • Experience in defense, aerospace, robotics, autonomy, or other high-assurance environments

  • Experience with EDR platforms including custom detection rule creation and telemetry analysis

  • Experience with cloud-native detection in AWS and Microsoft 365/Azure

  • Experience using Terraform to deploy and manage security monitoring infrastructure, log pipeline components, or cloud-native security service configurations

  • Hands-on experience with incident response, threat hunting, or adversary emulation

  • Exposure to embedded Linux, operational technology, or ICS telemetry and detection

  • Familiarity with NIST SP 800-171, NIST SP 800-53, or CMMC and their logging and monitoring requirements

  • Relevant certifications such as GCIH, GCIA, GCDA, GSOM, OSDA, or OSCP

Benefits:
  • Medical Insurance: Comprehensive health insurance plans covering a range of services

  • Saronic pays 100% of the premium for employees and 80% for dependents

  • Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care

  • Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

  • Time Off: Generous PTO and Holidays

  • Parental Leave: Paid maternity and paternity leave to support new parents

  • Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

  • Retirement Plan: 401(k) plan

  • Stock Options: Equity options to give employees a stake in the company’s success

  • Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

  • Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline

  • Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

 

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

HQ

Saronic Austin, Texas, USA Office

Austin, TX, United States

Similar Jobs

Junior
Financial Services
Provides comprehensive financial planning and investment advice to individuals and families, builds and manages a client book of business, develops personalized investment solutions, acquires and deepens client relationships, and educates clients on digital banking and investment tools. The role requires bilingual English and Spanish communication, active securities and insurance licenses, strong financial market knowledge, and relationship-focused business development.
An Hour Ago
Remote or Hybrid
United States
66K-89K Annually
Junior
66K-89K Annually
Junior
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Performs cybersecurity consulting engagements including vulnerability assessments, social engineering exercises, penetration testing, risk analysis, remediation recommendations, reporting, and client presentations. Coordinates engagement activities, monitors scope and budgets, documents findings, supports service development and sales opportunities, and mentors junior consultants. The role assesses networks, applications, cloud configurations, infrastructure, and employee awareness while maintaining current cybersecurity knowledge and pursuing relevant certifications.
Top Skills: Burp SuiteCloud ComputingNessus ProfessionalNetwork SecurityNipper StudioNmapOsintPhishing SimulationsSaaSTcp/IpTenable Vulnerability ManagementVirtualizationVulnerability AssessmentWireshark
2 Hours Ago
Hybrid
Senior level
Senior level
Financial Services
Leads telecommunications infrastructure design and delivery across structured cabling projects, managing requirements, drawings, specifications, budgets, contractors, testing, construction milestones, quality assurance, and project closeout. Collaborates with stakeholders, architects, general contractors, integrators, and engineering teams to deliver resilient, secure, auditable infrastructure solutions. Applies authorized AI tools to infrastructure analysis and documentation while validating outputs and protecting sensitive data. Domestic travel of approximately 20% is required.
Top Skills: AutocadBluebeamJIRALlmsuiteMicrosoft CopilotMS OfficeOutlookRevitSmartsheetStructured Cabling SystemsVisio

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account