ForgeApply
Try it free

ForgeApply · Job listing

Sr. Detection Engineer

Cboe

Chicago, IL, US$131k – $169konsite

See all 61 open roles at Cboe

Tailor your resume for this Cboe job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Cboe's site. Free trial, no card required.

About this role

Job Description: At Cboe, w e inspire our people to solve complex challenges together because what we do matters. We provide   the financial   infrastructure that powers the global economy.   As a leading provider of market infrastructure and tradable products, Cboe delivers   cutting-edge   trading, clearing and investment solutions to market participants around the world.  

We’re   building inclusive ways to support professional and personal development   while strengthening the trust   we’ve   earned as a global market leader.   Our teams are empowered to share ideas, actively pursue   them   and bring on a challenge.   As champions of internal mobility and access to   opportunity, we encourage our   people   to “go for it” and equip our managers with the training to coach their teams to the next level.   Our Associate Resour ce Groups   champion diversity,   equity   and inclusion,   giv ing   associates a safe space to network, share ideas and create opportunities.   

Sound   like   the   place for you? Join us!  

The Security Operations team is hiring a Senior Detection Engineer.  

The Senior Detection Engineer is a hands-on individual contributor within the Security Operations organization, responsible for writing production detection logic and proving that it works. This role authors the rules, then executes the techniques those rules are meant to catch, building the tooling, sandboxes, and reusable test content   required   to   demonstrate   coverage rather than assume it. A detection is not finished when it is written. It is finished when someone has run the attack against it, confirmed it fired, confirmed it stayed quiet on benign activity, and left behind a test case that will re-confirm both after the next platform change.  

The work spans endpoint, identity, cloud, SaaS, network, and   application   telemetry. The role requires fluency in attacker tradecraft at a mechanical level: how a technique   actually executes , what artifacts it produces, and which of those artifacts are reliable enough to build durable detection logic on. This position partners closely with Threat Hunting, Incident Response, and Security Engineering to ensure detection coverage is measured continuously rather than assumed.  

To set expectations clearly, this is a detection authoring and validation role, not a data pipeline role. Log source onboarding, parser development, and ingestion engineering are owned elsewhere. You will need to understand our telemetry well enough to know what is and is not detectable with it, and you will be expected to raise gaps when the data cannot support a detection, but building the pipes is not the job.  

In this role   you’ll   be responsible for :  

• Writing, tuning, and maintaining production detection logic across SIEM, EDR, identity, and cloud platforms, with explicit attention to fidelity and false positive cost  

• Validating every detection by executing the technique it targets, so that no rule reaches production unproven  

• Building and   maintaining   internal tooling that simulates adversary behavior on demand, making detection testing repeatable rather than manual  

• Building reusable validation packages and automated regression testing so coverage is re-verified continuously and after every agent, platform, or configuration change  

• Building and operating sandbox and detonation infrastructure, including disposable, instrumented environments for exploit triage, malware analysis, and safe technique development  

• Evaluating newly published proof-of-concept exploit code to   determine   whether it functions, what telemetry it generates, and whether Cboe is exposed, then converting the answer into detection or hunting content  

• Producing threat hunting validation content, including seeded artifacts, known-truth datasets, and repeatable test cases that   establish   whether a hypothesis is testable with the data we hold  

• Automating the repeatable work: scheduled technique execution, telemetry collection, coverage reporting, and detection performance measurement  

• Applying AI and LLM tooling where it measurably shortens cycle time, including agentic workflows for triage and enrichment, automated analysis of exploit and malware code, detection and test-case drafting, and hunt hypothesis generation  

• Conducting security testing of internally built web applications and APIs, and translating findings into detection requirements as well as remediation guidance  

• Supporting Incident Response during complex investigations with concrete attacker tradecraft insight, and closing the loop by building detections for what the investigation surfaces  

• Documenting and handing off work so that tooling, environments, and test content can be   operated   by others independently  

The ideal candidate has :  

• 5+ years of hands-on security engineering experience with substantial detection authoring content, and the ability to speak concretely about detections you built, how you   validated   them, and how they performed in production  

• Strong command of at least one detection query language (KQL, Sigma, YARA-L, or equivalent) and the judgment to recognize when logic is too brittle or too broad to ship  

• Practical knowledge of attacker techniques across Windows and Active Directory, Entra ID, cloud platforms (AWS, Azure), SaaS, and containerized workloads, at the level of execution mechanics rather than technique names  

• The ability to read unfamiliar exploit or malware code and   identify   the observable artifacts worth detecting on  

• Real fluency in at least one language used to write tooling (Python, Go, C#, PowerShell , bash, or equivalent  

• Working knowledge of the telemetry itself, including Windows event logs, EDR process and network events, cloud audit logs, and identity sign-in data, and where each is unreliable, incomplete, or trivially evaded  

• Comfort building and tearing down test infrastr

Salary insight

The midpoint of this range ($150k) is about 15% above the median disclosed salary for Chicago roles listed on ForgeApply ($130k across 2,517 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Cboe role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)