yoinka

Security Detection Engineer III

F5

WarsawSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Warsaw
Work model
On-Site
Level
Senior
H-1B history
60 approvals (FY2023)
Posted
Aug 25, 2026

Skills

CI/CDCybersecurityGitPythonSQL

About this role

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive. The Security Engineer III, Detection Engineering is a career-level security engineering professional responsible for developing, testing, deploying, and continuously improving detection capabilities that support Security Operations. As part of the Security Operations Platform Engineering (SOPE) team, this role focuses on transforming threat intelligence, telemetry, and security requirements into reliable, actionable detections that improve visibility and reduce organizational risk. The engineer partners closely with Incident Response, Threat Intelligence, Logging Engineering, and platform engineering teams to build scalable, threat-driven detection capabilities while advancing automation, detection coverage, and operational maturity.

Primary Responsibilities

Develop and   maintain   custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows.   Analyze and improve   detection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework,   identifying   gaps and prioritizing enhancements.   Partner with   Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate emerging threats, investigations, and telemetry into actionable detection content.   Validate and tune   detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives.   Automate and   optimize   detection   engineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability.    Support   onboarding   of   new log sources and security telemetry by collaborating with engineering and infrastructure teams to   establish   detection coverage across new environments and technologies.   Create and   maintain   detection   documentation, runbooks, coverage assessments, and technical standards while   participating   in an engineering on-call rotation.    Help define detection strategy for AI and agentic systems (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs ), and   explore using AI to accelerate detection engineering workflows.   Required Skills / Qualifications   Bachelor's degree in Information Security , Computer Science, Engineering, or related field, or equivalent practical experience.   5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or   a related   discipline.   Experience developing, tuning, or   maintaining   detections within a SIEM, EDR, log analytics, or security monitoring platform.   Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies.   Strong understanding of attacker techniques, detection methodologies, and frameworks such as MITRE ATT&CK.   Strong analytical, problem-solving, communication, and cross-functional collaboration skills.   Preferred Skills / Qualifications   Experience implementing Detection-as-Code practices, including Git-based workflows, automated testing, and CI/CD pipelines.   Experience   with adversary emulation, atomic testing, purple-team exercises, or detection validation frameworks.    Experience performing detection coverage analysis

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Security Detection Engineer III at F5, Warsaw | Yoinka