Detection Engineer
Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry.
If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest-growing companies in the U.S. – and we have a blast doing it! With the launch of our new India Global Capability Center (GCC) in Bengaluru, we’re expanding our global footprint and building a diverse, high-impact team driving innovation and excellence at scale.
Who We Are
Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business.
Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.
Deepwatch recognition includes:
- 2025, 2024, 2023, 2022 and 2021 Great Place to Work® Certified
- 2024 Military Times Best for Vets Employers
- 2024 US Department of Labor Hire Vets Gold Award
- 2024 Forbes' America's Best Startup Employers
- 2024 Cyber Defense Magazine, Global Infosec Awards
- 2023 and 2022 Fortress Cybersecurity Award
- 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners
- 2022 Cybersecurity Excellence Award for MDR
Position Summary
Deepwatch is seeking a Detection Engineer to join our Threat Detection & Research team and help strengthen detection capabilities across customer environments. Reporting to the Sr. Manager, Threat Detection & Research, this role is responsible for developing, tuning, validating, and optimizing cybersecurity detections that improve visibility into evolving threats and enhance the effectiveness of our MDR operations.
This role is ideal for a cybersecurity professional with strong analytical skills, hands-on SIEM experience, and a passion for threat detection engineering. You will work closely with Security Operations, Threat Research, Customer Success, and Engineering teams to improve alert fidelity, reduce false positives, and ensure high-quality detection coverage aligned to modern attacker behaviors and customer security priorities.
In this role, you’ll get to:
- Develop and document new Detection Capabilities for customer environments
- Work with customers to develop a comprehensive strategy for effective detections
- Leverage industry frameworks, such as MITRE ATT&CK Framework, for customer-facing alert improvement roadmap
- Apply knowledge of common detection tools (Azure logging, command line logging, etc.) to advise customers on logging capabilities to expand applicable detection library
- Confidently prioritize log sources for ingestion and enablement
- Evaluate current monitoring and detection capabilities to identify areas for improvement
- Conduct Detection Gap Analyses
- Manage detection capabilities to ensure appropriate coverage, effective operation, and adherence to Deepwatch standards
- Detection Enablement
- Detection Effectiveness (Tuning, Validation, etc.)
- Detection Creation
- Onboard assigned customers, establishing baseline detection coverage and detection enablement plan post onboarding
- Ensure ingested log sources conform to CIM standards
To be successful in this role, you’ll need:
- 3–5 years of experience in cybersecurity, detection engineering, threat detection, or security operations
- Experience working for a Managed Security Service Provider (MSSP) or similar cybersecurity organization
- Experience working and querying SIEM tools or other log-based data preferably Splunk
- Experience in engineering event detection & response tuning
- Ability to engineer creative, scalable, and out-of-the-box solutions
- Up to date with engineering best practices, security technology trends, tools, and frameworks
- Experience in developing detections for attacker tactics, techniques, and procedures (TTPs)
- Able to both investigate and create security rules in at least 1 SIEM
- Understanding of general enterprise network architecture and security incident response
- Understanding of common enterprise technologies and logging capabilities including Cloud, IDS/IPS, Firewalls, Active Directory, Anti-Virus/EDR, Proxies, and Email Gateway
- Understanding of various attack frameworks such as MITRE ATT&CK and general adversarial / defensive security techniques (e.g. the Cyber Kill Chain, and NIST)
- Ability to communicate and document technical information effectively towards various audiences
Why Deepwatch?
- Mission-driven company focused on protecting customers from threats 24/7
- Hybrid work model in India, with access to collaborative office space in Bangalore
- High-impact leadership role with strong visibility across Product & Engineering
- Competitive compensation, equity, and benefits
- A company recognized as a Great Place to Work® for five consecutive years
- Opportunity to shape the future of cybersecurity and AI-driven platforms
Life at Deepwatch:
For employees, Deepwatch fosters a unique, flexible work environment designed with collaboration in mind. The company emphasizes personal and professional
growth, offering benefits such as professional development programs, comprehensive health coverage, and generous parental leave. Deepwatch is also committed to diversity, equity, inclusion, and belonging, aiming to empower underrepresented groups in tech by connecting them with meaningful opportunities, mentors, and sponsors.
In recognition of its supportive workplace culture, Deepwatch earned the Great Place To Work Certification/(TM) in 2025, underscoring its dedication to creating a positive and inclusive work environment. Deepwatch is a global cybersecurity company with offices in San Francisco Bay Area, CA; Tampa, Florida; and Bengaluru, India.
What We Offer:
At Deepwatch, we are committed to supporting our employees with a comprehensive benefits package designed to enhance your well-being and financial security.
- Group Health Insurance – Comprehensive medical coverage for you and your dependents.
- Group Accidental Insurance – Financial protection in case of accidental injuries.
- Group Term Life Insurance – Security for your loved ones in unforeseen circumstances.
- Comprehensive Wellness, OPD and Gym support program
Job Details
Salary
₹1,800,000 – ₹1,800,000/yr (in)
Experience
Mid · 3–5 yrs