Senior Threat Detection Engineer - SIEM and Cloud Security (GenAI)
ElasticSpainPosted 27 February 2026
Job Description
<div class="content-intro"><p>Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.</p></div><h3>What is the Role?</h3>
<p>The Threat Research and Detection Engineering (TRaDE) team is responsible for developing and maintaining the prebuilt detection logic shipped with Elastic Security, researching emerging threats, validating detection efficacy, and engaging with the global community to democratize defensive capabilities.</p>
<p>We’re looking for a <strong>Security Research Engineer II</strong> with strong security fundamentals, hands-on detection engineering experience, and an interest in validating and improving defensive protections. This role focuses on driving threat research and real telemetry into high-quality, reliable, high efficacy, detection content.</p>
<h3>What you’ll be doing:</h3>
<p>This position centers on practical detection development and validation work across multiple data sources and attack surfaces. Responsibilities include writing and refining detection logic, validating rule behavior, and improving detection quality through telemetry analysis and testing.</p>
<p>Key focus areas include:</p>
<ul>
<li>Creating and refining detection logic across multiple domains (endpoint, cloud, identity, network, web, and email) domains using Elastic data sources.</li>
<li>Validating rule behavior through functional testing, false-positive review, and iterative tuning.</li>
<li>Evaluating attack paths across domains and contributing to coverage improvements throughout the kill chain.</li>
<li>Analyzing multi-source telemetry to uncover detection opportunities and strengthen signal-to-noise ratios.</li>
<li>Supporting cloud security validation efforts for AWS, Azure, or GCP detections.</li>
<li>Collaborating with senior researchers to test new detection approaches and incorporate emerging attacker techniques.</li>
<li>Using lightweight simulation tools or scripted tests to generate telemetry and validate detection behavior.</li>
<li>Participating in Elastic Security Labs efforts, detection package updates, documentation, or community knowledge sharing when appropriate!</li>
</ul>
<h3>What you bring:</h3>
<p>We're looking for candidates with experience in Generative AI Security and intimately understand MITRE ATLAS threat techniques and behaviors.</p>
<p>Beneficial strengths include:</p>
<ul>
<li>Experience in detection engineering, threat research, SOC operations, incident response, or related blue-team roles.</li>
<li>Understanding of core concepts across multiple domains.</li>
<li>Ability to write or validate detections using EQL, KQL, SQL, or similar query languages.</li>
<li>Familiarity with MITRE ATTCK, MITRE ATLAS, and its application to mapping detection coverage.</li>
<li>Strong analytical and problem-solving skills, especially around false positives and weak-signal detection logic.</li>
<li>Clear, collaborative communication and willingness to learn from and partner with senior researchers.</li>
</ul>
<h3>Bonus point desired experiences and interests:</h3>
<ul>
<li>Understanding of the Elastic Security Solution, Elastic’s prebuilt rules, Elastic query languages, or the Elastic Common Schema.</li>
<li>Experience with exposure validation, security control testing, or attack path validation platforms.</li>
<li>Ability to generate or script test telemetry using Python, Bash, PowerShell, or simple simulation tools.</li>
<li>Contributions to commun ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
More jobs at Elastic
See all →More Python jobs
See all →[Summer 2026] People Science - PhD Intern
Roblox · San Mateo, CA, United States
Team Lead - Security Platform
Cloudflare · Distributed; Hybrid
Sr. Security Software Engineer, Applied Computing (Starshield)
SpaceX · Hawthorne, CA
Security Software Engineer, Applied Computing (Starshield)
SpaceX · Washington, DC