Senior Detection Portfolio Engineer

Microsoft

Confirmed live today High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$119,800–$234,700 / yr
Posted
11 days ago
Freshness
Confirmed live today
Closes
Mar 28, 2027

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $192k
This role $177k
$106k $248k
below market most similar roles pay here above market

This role pays less than 62% of similar roles. Most pay $162,570–$221,000 — the blue band above. At the midpoint, this role pays about $177k versus about $192k for comparable roles.

Based on 240 similar postings.

Employer

About Microsoft

Microsoft Corporation is a global technology leader producing software, hardware, and cloud services including Windows, Office 365, Azure cloud platform, Xbox gaming, and Surface devices. Industry: Software & Cloud Computing

Microsoft currently has 634 open roles on FindRole.

Listed pay typically runs $119,800–$234,700 across 612 roles with salary data.

Most-posted roles

View all roles at Microsoft

At a glance

TL;DR · Senior Detection Portfolio Engineer

The Senior Detection Portfolio Engineer joins the Cyber Defense Operations Detection Engineering team to manage a specific portfolio of threat actors, techniques, and partner platforms. This hands-on role involves owning the end-to-end detection lifecycle, where you will author and optimize high-fidelity detections, gate submissions from partner teams, and manage coverage-versus-noise tradeoffs. You will work directly with investigation and hunt leads to translate findings into production logic while overseeing the onboarding and offboarding of security controls. Key technical requirements include proficiency in Kusto (KQL), Python, and AI-assisted automation frameworks like Jupyter and Synapse. You must demonstrate expertise in threat modeling, MITRE ATT&CK, and security incident and event management to solve the business problem of converting adversary activity into reliable, high-signal cases for rapid investigation.

What you'll do

  • Own an assigned threat actor and partner portfolio including onboarding, offboarding, and tuning decisions.
  • Author and optimize high-fidelity detections using Kusto and the internal detection platform.
  • Translate investigation and hunt findings into production detection logic with hunt leads.
  • Gate and approve detection submissions from partner teams based on priorities and charter.
  • Review detections authored by others for intent fidelity, query performance, and production reliability.
  • Manage the portfolio against an investigator case budget and make coverage-versus-noise tradeoffs.
  • Engineer and tune AI-assisted and automation frameworks for the detection lifecycle.
  • Lead the detection workstream during incidents to establish firing reasons and drive rapid remediation.

What we're looking for

  • Doctorate in Statistics, Mathematics, Computer Science, or related field.
  • Master's Degree in Statistics, Mathematics, Computer Science, or related field and 3+ years of relevant experience.
  • Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field and 4+ years of relevant experience.
  • Equivalent experience to the degree and years of experience requirements.
  • Ability to pass a Microsoft Cloud background check.
  • Proof of citizenship or U.S. permanent residency for export control and government customer access requirements.
  • 3+ years in a security operations role as a SOC analyst, threat hunter, or incident investigator (preferred).
  • Proficiency in Kusto (KQL), threat actor tradecraft, MITRE ATT&CK, and AI-assisted tooling (preferred).

More like this

Similar roles

Senior Detection Engineer

DoorDash, Inc

Remote 51 days ago $159,800–$235,000
Detection Engineering Python Go SQL SPL KQL Snowflake Google SecOps Cortex MITRE ATT&CK D3FEND Detection-as-Code Threat Intelligence Risk-based Analytics Distributed Systems
7+ yrs exp Remote

Senior Detection Engineer, Protective Services

DoorDash, Inc

Remote (Hartford, CT) 4 days ago $159,800–$235,000
Python Go SQL SPL KQL Detection-as-Code Snowflake Cortex Google SecOps MITRE ATT&CK D3FEND Machine Learning OSINT Distributed Systems
7+ yrs exp Remote

Senior Security Engineer, Detection Engineering

Nvidia

Remote (CA) +2 31 days ago
Splunk Microsoft Sentinel Defender CrowdStrike Python SQL KQL SPL Git CI/CD Kubernetes Detection-as-Code SIEM Threat Hunting Incident Response Cloud Security Identity Telemetry Endpoint Data
8+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote (Ontario, Canada) +3 47 days ago $196,000–$207,000
Detection-as-Code SOAR Python Golang AWS Azure GCP CI/CD Threat Hunting TTPs MacOS Version Control Machine Learning Zero Trust
6+ yrs exp Remote

Detection Engineer, Protective Services

DoorDash, Inc

Remote 12 days ago $130,600–$192,000
Python Go SQL Snowflake Google SecOps Cortex Machine Learning LLM Source Control MITRE ATT&CK D3FEND OSINT Data Pipelines Detection Engineering Threat Hunting Incident Response
3+ yrs exp Remote

Senior Detection Engineer, AI-ML Focus

P&G

Cincinnati, OH 48 days ago $110,000–$165,300
Detection Engineering SIEM Python Git CI/CD MITRE ATT&CK LLM AI Detection-as-Code Sigma YAML EDR SOAR Kubernetes Cloud-native ML MCP GitHub Copilot
5+ yrs exp