Threat Detection Security Engineer

CoStar Group

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Arlington, VARichmond, VA
Salary
$90,000–$154,000 / yr
Posted
72 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $179k
This role $122k
$74k most similar roles pay here $236k

This role pays less than 97% of similar roles. Most pay $151,106–$206,925 — the shaded band above. At the midpoint, this role pays about $122k versus about $179k for comparable roles.

Based on 240 similar postings.

Employer

About CoStar Group

CoStar Group is the leading provider of commercial real estate information, analytics, and online marketplaces, including CoStar, Apartments.com, and LoopNet platforms. Industry: Commercial Real Estate Data & Analytics

CoStar Group currently has 65 open roles on FindRole.

Listed pay typically runs $133,000–$190,000 across 63 roles with salary data.

Most-posted roles

View all roles at CoStar Group

At a glance

TL;DR · Threat Detection Security Engineer

The Threat Detection Security Engineer joins the global cyber threat center team to provide continuous security coverage. This role involves owning cyber security incidents from identification to resolution, ensuring artifacts are accurately recorded, and collaborating with threat intelligence and detection engineering teams to build a holistic lifecycle for incident preparedness. The engineer will serve as an escalation point for alert triage, maintain the Incident Response Plan, perform threat hunts across the enterprise, and design quarterly tabletop exercises. Key technical requirements include experience with Microsoft and Azure security tooling, including Defender and Sentinel, along with scripting skills in Python or low-code automation solutions. The role focuses on defending against attacker techniques using the Mitre ATT&CK framework while identifying opportunities for automation to improve detection efficacy within a complex enterprise environment involving cloud and Kubernetes systems.

What you'll do

  • Manage cyber security incidents from initial identification through final resolution.
  • Record all incident artifacts and evidence accurately in the tracking system.
  • Serve as a point of escalation for alert triage and provide expert investigation guidance.
  • Maintain and improve the Incident Response Plan and associated procedures.
  • Utilize MITRE ATT&CK frameworks to drive the overall strategy of the incident response team.
  • Execute proactive threat hunts across the enterprise environment.
  • Design and deliver quarterly tabletop exercises and security training.
  • Identify opportunities for automation to increase detection and response efficacy.

What we're looking for

  • Bachelor's Degree from an accredited, not-for-profit, in-person university or college.
  • 4+ years of hands-on security engineering experience.
  • Experience with Microsoft/Azure security tooling including Defender and Sentinel.
  • Proficiency in scripting with a language such as Python or a low-code automation solution.
  • Ability to identify opportunities for automation to increase detection and response efficacy.
  • Expertise in Mitre ATT&CK, tools, techniques, and practices of cyber attackers.
  • Experience performing incident response in cloud environments and Kubernetes environments.
  • Excellent documentation and communication skills to convey risk to leadership.

More like this

Similar roles

Security Engineer (Detection Engineering)

SpaceX

Redmond, WA 49 days ago $130,000$155,000
Python Go C++ Rust Kubernetes SIEM ETL Incident Response Automation Linux Windows macOS Security Operations Detection Engineering

Detection Engineer, Cloud Security

Global Payments (TSYS)

Alpharetta, GA 44 days ago
AWS Azure GCP Splunk KQL CNAPP Wiz Kubernetes Git CI/CD MITRE ATT&CK Detection-as-Code Cloud Security Security Engineering

Security Engineer, Threat Intelligence

Snap Inc.

Sydney, Australia 96 days ago
Threat Intelligence Python Go Kubernetes Google Cloud Platform Incident Response Malware Analysis Digital Forensics Detection Engineering Automation Linux macOS Windows Network Intrusion Detection Cloud Infrastructure TTPs
3+ yrs exp

Senior Security Engineer, Cloud Threat Detection

The Hartford

Hartford, CT +3 23 days ago $128,400$192,600
AWS GCP Splunk SIEM Python PowerShell Bash MITRE ATT&CK SOAR CloudTrail GuardDuty CrowdStrike Wiz Orca SentinelOne Microsoft Defender XDR Identity and Access Management (IAM)
5+ yrs exp Hybrid

Staff Security Detection Engineer, Machine Learning

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Machine Learning Anomaly Detection Python SQL Spark Snowflake Databricks PyTorch TensorFlow Scikit-learn Pandas AWS GCP Azure Kafka Kinesis Flink MLOps CI/CD MITRE ATT&CK
7+ yrs exp