Threat Detection Engineer
New York City, NY - USA
Job Summary
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.
Job Title:Threat Detection Engineer
Location(s):New York NY or Pittsburgh PA
Description and Location
The Threat Detection Engineer will develop and enhance enterprise threat detection capabilities across security monitoring platforms. This role will focus on creating advanced detection logic threat hunting incident identification security analytics and monitoring of both traditional and AI-enabled environments. The engineer will work closely with SOC cyber defense and threat intelligence teams to improve detection coverage and reduce organizational cyber risk.
Key Responsibilities
- Develop and tune SIEM detection use cases and correlation rules.
- Perform proactive threat hunting and behavioral analytics.
- Create and maintain security monitoring content.
- Investigate emerging threats and map detections to MITRE Telecommunication & CK.
- Improve detection coverage for cloud endpoint and network environments.
- Build automated response workflows and security analytics dashboards.
- Support detection strategies for AI GenAI and LLM-based technologies.
AI / Agentic Systems Development
- Design and implement agentic workflows (ReAct multi-agent orchestration tool-augmented agents).
- Build autonomous or semi-autonomous AI agents to handle development testing and operational workflows.
- Integrate agents with enterprise systems (Jira Git ServiceNow APIs etc.).
RAG & Knowledge
- Build and optimize Retrieval-Augmented Generation (RAG) pipelines.
- Work with vector databases embeddings document chunking indexing and retrieval tuning.
- Enable enterprise knowledge use cases (e.g. FAQ bots nuggets/knowledge artifacts AI copilots).
LLM Evaluation
- Implement evaluation frameworks for LLMs including:
- Functional correctness
- Response quality
- Hallucination detection
- Experience with AI testing frameworks (e.g. RAGAS DeepEval custom evaluation harnesses).
- Build scalable APIs/services (FastAPI Flask etc.).
- Ensure performance observability and reliability of AI systems.
Primary Skills
- Threat Detection Engineering (SIEM/EDR)
- Splunk & Security Analytics
- Threat Hunting & Incident Response
Secondary Skills
- Security Automation (SOAR)
- AI Security & GenAI Monitoring
Experience
- 7 years of cybersecurity and security operations experience.
- Hands-on experience with Splunk Sentinel QRadar or similar SIEM tools.
- Experience building detection content and threat-hunting methodologies.
- Familiarity with cloud security EDR technologies and MITRE Telecommunication & CK framework.
Location:
- New York NY or Pittsburgh PA (ON SITE ROLE LOCAL CANDIDATES PREFERRED) US.
Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age protected veterans or individuals with disabilities.
Required Experience:
IC