Overview

Senior Detection Engineer Jobs in Colombo District, Western Province, Sri Lanka at GSS HR Solutions Private Limted

Title: Senior Detection Engineer

Company: GSS HR Solutions Private Limted

Location: Colombo District, Western Province, Sri Lanka

Senior Detection Engineer

About the Role

We are looking for a highly skilled Senior Detection Engineer to design, develop, and optimize advanced detection capabilities across SIEM, XDR, cloud, endpoint, and identity platforms. You will collaborate with Security Operations, Incident Response, and Threat Research teams to build high-fidelity detections and strengthen our security posture.

Key Responsibilities

  • Design, build, and maintain behavioral detections across SIEM, XDR, cloud, endpoint, and identity platforms.
  • Develop detection rules using KQL, Sigma, SPL, or platform-native query languages.
  • Build and maintain detection-as-code packages with Git, CI/CD, and automated testing.
  • Tune detections to reduce false positives and improve detection accuracy.
  • Map detections to MITRE ATT&CK and other relevant frameworks.
  • Perform threat analysis, gap assessments, and improve detection coverage.
  • Collaborate with SOC, Incident Response, and Platform Engineering teams.
  • Develop cloud detections across AWS, Azure, and GCP environments.

Required Skills

  • 7+ years of experience in Detection Engineering, Threat Hunting, SOC Engineering, or Incident Response.
  • Hands-on experience with SIEM/XDR platforms such as Microsoft Sentinel, Splunk, Elastic, or Stellar Cyber.
  • Strong knowledge of MITRE ATT&CK, adversary TTPs, malware analysis, and attack techniques.
  • Experience writing detection rules using KQL, Sigma, SPL, or similar languages.
  • Strong scripting skills in Python or PowerShell.
  • Experience with SQL and large-scale log analysis.
  • Experience with Git, CI/CD, and Detection-as-Code practices.
  • Strong communication and collaboration skills.

Preferred Skills

  • Experience with SOAR platforms.
  • Cloud security detection experience across AWS, Azure, or GCP.
  • Threat hunting experience.
  • Industry certifications such as GCIH, GCFA, GCIA, or Offensive Security certifications.
  • Contributions to Sigma, YARA, or other open-source detection repositories.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.