Skip to content

Open nowPosted 9 hours ago

Detection Engineering Lead

Aspenview Technology Partners58 open roles

Where
United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDetection Engineering LeadAspenview Technology Partners · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aspenview Technology Partners's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 9 hours ago

The posting

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

The Detection Engineering Lead is a hands-on professional responsible for owning detection engineering for a large US consumer lender whose 24/7 security operations run from a nearshore team in Bogotá and Buenos Aires. Telemetry from CrowdStrike, Microsoft Defender, Okta, Palo Alto, Proofpoint and AWS flows through Abstract Security into Elastic, and alerts become ServiceNow cases. You will be responsible for what gets detected along that chain, and for proving it. As one of two US-based seniors on the service, you will lead two senior detection engineers in Latin America, set their priorities, review their rules and decide what goes to the client for approval. You will report to the SOC / Cyber Operations Lead and present detection coverage directly to the client's security leadership.

What you will do:

Detection Lifecycle & Prioritization

  • Own the detection inventory end to end, including new use cases, tuning, health monitoring and retirement, each with a clear owner.
  • Prioritize detection work based on threat intelligence, hunt findings, incidents and Tier 2 feedback, focusing on the techniques that matter most to a consumer lender.
  • Build identity-centric detections on Okta, custom detections in CrowdStrike and Microsoft Defender, and AWS control-plane coverage.

Pipeline Health & Troubleshooting

  • Troubleshoot the full telemetry chain end to end, from data reaching Abstract but not Elastic to alerts that fire but never become ServiceNow cases.
  • Make sure the data feeding detections is parsed, normalized and enriched correctly.

Detection as Code & Reporting

  • Run detection as code, with version control, peer review, testing against simulated attacks, and change records the client approves before alerting behavior changes.
  • Produce MITRE ATT&CK coverage reporting for the client's security leadership, gaps included.
  • Lead and review the work of two senior detection engineers in Latin America.

Tools & Technologies:

  • SIEM & Detection: Elastic Security (EQL, ES|QL, KQL); Splunk, Sentinel or Chronicle also relevant.
  • Data Pipeline: Abstract Security, or equivalents such as Cribl.
  • Endpoint, Identity & Cloud: CrowdStrike Falcon, Microsoft Defender, Okta System Log, AWS CloudTrail and GuardDuty.
  • Case Management: ServiceNow SecOps integration and alert routing.
  • Testing & Automation (Bonus): Sigma, YARA, Atomic Red Team, Caldera, Python and SOAR playbooks.

What you bring:

  • Experience: A few years writing and tuning detections in production on a SIEM or analytics platform, with the ability to explain the reasoning behind a rule you shipped. Solid understanding of log pipelines, including where data goes missing between source and alert.
  • Engineering Discipline: You treat detections as code, with version control, peer review and testing before release. You can tell a client what a rule catches, what it misses and how you know.
  • Communication / Leadership: Experience leading or mentoring engineers and giving candid reviews of their work across a distance. Comfortable presenting coverage to a client's security leadership, gaps included.
  • Availability: Remote work from the United States on business hours anchored to Eastern Time, with periodic travel to the client and to Bogotá or Buenos Aires. US work authorization is required, and access requires identity, criminal background, employment and education checks, repeated periodically.
  • Bonus Qualifications: Hands-on Elastic Security (the most valuable extra on this stack); Abstract Security or Cribl; custom IOAs in CrowdStrike Falcon and advanced hunting in Microsoft Defender; financial services experience under NYDFS Part 500, SOX or PCI DSS; applying GenAI to detection work with evaluation behind it; and GCDA, GCIA, GCED, SC-200 or Elastic certifications.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aspenview Technology Partners's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aspenview Technology Partners's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aspenview Technology Partners's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.