24 threat detection engineer jobs at 22 companies in Texas

1mo
Save
Mark Applied
Hide
Senior Threat Detection Engineer
Houston, Texas, United States
HybridFull Time
Macquarie Group
Macquarie GroupASX: MQG: Global financial services group specializing in asset management and advisory.
3+ YOE3–5 years in detection engineering or incident response; strong SIEM and threat hunting experience; detection-as-code, Git and CI/CD experience; knowledge of MITRE ATT&CK and cloud/security tooling.
MITRE ATT&CK, Splunk ES, Google SecOps, Sumo Logic, Git, GitHub, Bitbucket, CloudBees, AWS, Azure, GCP, GitHub Copilot, Claude Code
1mo
Save
Mark Applied
Hide
Engineer II, Threat Detection - Windows (Hybrid)
Sunnyvale or New York City or Austin or Redmond
$100k-$145k/yr HybridFull Time
CrowdStrike
CrowdStrikeNASDAQ: CRWD: AI-native platform for cybersecurity and threat protection.
4+ YOEAbility to analyze malware and intrusion telemetry, author behavioral detections for Windows endpoints, use Python/PowerShell for automation, and collaborate with threat intelligence; U.S. citizenship or green card required for CJIS eligibility.
PowerShell, Python, EDR, Regular expressions, MITRE ATT&CK
2w
Save
Mark Applied
Hide
Manager, Threat Detection Engineering
Plano or Malvern or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management firm owned by its client funds.
7+ YOEBachelor's degree preferred; 7+ years in security operations, detection engineering, threat hunting, or incident response; people leadership, SIEM and SOAR experience, MITRE ATT&CK knowledge, and program-building expertise.
SIEM, SOAR, CI/CD, MITRE ATT&CK, Cyber Kill Chain, EDR, CNAPP, ITP, NIDS/NIPS
2w
Save
Mark Applied
Hide
Manager, Threat Detection Engineering
Malvern or Fort Worth or Dallas or United States
HybridFull Time
Vanguard
Vanguard: Global investment management firm owned by its client funds.
7+ YOERequires 7+ years in security operations or related disciplines, security people-management experience, SIEM and SOAR expertise, detection engineering knowledge, and familiarity with MITRE ATT&CK and CI/CD.
SIEM, EDR, CNAPP, ITP, NIDS/NIPS, SaaS, SOAR, CI/CD, MITRE ATT&CK, Cyber Kill Chain, AI
1mo
Save
Mark Applied
Hide
Senior Detection Engineer
New York City or San Francisco or Austin or Seattle
$176k-$218k/yr OnsiteFull Time
Fluidstack
Fluidstack: Building and operating civilization-scale data center infrastructure for AI.
5+ YOE5+ years detection engineering or threat hunting experience; hands-on SIEM/EDR (Splunk, Elastic, CrowdStrike); detection logic mapped to MITRE ATT&CK; Python/SQL scripting; strong writing and incident response skills.
Splunk, Elastic, CrowdStrike, Python, SQL, MITRE ATT&CK, Sigma
1w
Save
Mark Applied
Hide
Threat Hunting Engineer Lead
Carrollton or Conshohocken
OnsiteFull Time
Cencora
CencoraNYSE: COR: Global pharmaceutical solutions and distribution organization.
7+ YOEBachelor's degree or equivalent experience; 7+ years in cybersecurity, including 4+ years in incident response, forensics, threat hunting, or detection; scripting, threat platforms, network, OS, cloud, and communication expertise.
SIEM, EDR, SOAR, Windows, Linux, MacOS, MITRE ATT&CK, Python, Go, Powershell
2mo
Save
Mark Applied
Hide
Senior Research Engineer, Threat Intelligence
Austin or New York City
$140k-$150k/yr HybridFull Time
SecurityScorecard
SecurityScorecard: Private cybersecurity ratings and third-party risk platform serving organizations managing supply-chain risk.
5+ YOE5+ years engineering experience in threat intelligence or detection engineering; production experience with Python and TypeScript/Node; cloud (AWS), containers, CI/CD; proficiency with STIX/TAXII/MISP/MITRE; YARA/Sigma/STIX patterning; applied LLM systems experience.
Python, TypeScript, Node, STIX 2.1, TAXII 2.1, MISP, MITRE ATT&CK, YARA, Sigma, STIX Patterning, AWS, CI/CD, Splunk, Kinesis, NetFlow, CEL, OPA, Golang, SQL
2mo
Save
Mark Applied
Hide
Threat Hunt Senior Associate
Tampa or Jersey City or Coppell
$75k-$150k/yr HybridFull Time
DTCC
DTCC: Global post-trade market infrastructure for the financial services industry.
3+ YOE3+ years threat hunting/detection/IR experience, Bachelor's or equivalent, hands-on log analysis across endpoint/identity/network/cloud, experience with KQL/SPL/EQL, scripting (Python/PowerShell/Bash), familiarity with MITRE ATT&CK and detection engineering.
Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Microsoft Sentinel, Splunk, Splunk SPL, Elastic, EQL, KQL, Lucene, Chronicle/Google SecOps, Microsoft Azure, AWS, Microsoft Entra ID, Microsoft Azure AD, Okta, CloudTrail, Kubernetes, Sigma, YARA, ATT&CK, SOAR, Python, PowerShell, Bash, jq, osquery, CyberChef, EDR/XDR, SIEM
1mo
Save
Mark Applied
Hide
Security Engineer, Cyber Threat Intelligence
Austin or San Diego
OnsiteFull Time
Saronic
Saronic: Developing autonomous surface vessels for defense and maritime applications.
4+ YOE4+ years in CTI/threat hunting/detection engineering, intelligence lifecycle fluency, software engineering for automation, MITREATT&CK/STIX/TAXII familiarity, ability to obtain U.S. security clearance.
MITRE ATT&CK, STIX, TAXII, Sigma, YARA, SIEM, MISP, LLMs
17h
Save
Mark Applied
Hide
Detection Engineering Technical Leader
Denver or Saint Paul or Boulder or Houston or Knoxville or Chicago or Philadelphia or Birmingham or Portland or Minneapolis or Elk Grove Village or Dallas or Atlanta or Little Rock or Hillsboro or Colorado Springs
$151k-$191k/yr RemoteFull Time
Splunk
SplunkNASDAQ: CSCO: Global leader in networking, cybersecurity, and cloud-native technology solutions.
8+ YOEBachelor’s with 8+ years, master’s with 6+ years, or PhD with 3+ years in security operations; Splunk Enterprise Security, SPL, AI/ML, threat intelligence, and ATT&CK experience required.
Splunk Enterprise Security, SPL, GitHub, GitLab, Bitbucket, CI/CD, AWS, GCP, Azure, CloudTrail, GCS, Azure Monitor, Python, ATT&CK
1w
Save
Mark Applied
Hide
Sr. Engineer, Cybersecurity - Threat Response Strategic Execution
Bellevue or Downers Grove or Frisco or Overland Park
$103k-$186k/yr OnsiteFull Time
T-Mobile
T-MobileNASDAQ: TMUS: The Un-carrier providing wireless and home internet services.
3+ YOEBachelor's degree plus 5 years or advanced degree plus 3 years required; Computer Science or Information Technology. Preferred experience in security software, technical project management, SOC/IR, SIEM, SOAR, EDR, and detection engineering.
SIEM, SOAR, EDR
2mo
Save
Mark Applied
Hide
SecOps IR Engineer
Tel Aviv-Yafo or Dallas
OnsiteFull Time
Island
Island: Enterprise browser helping organizations secure web work, control access, and improve employee productivity.
3+ YOE3+ years in security operations/incident response; hands-on with SIEM, EDR, cloud security (Wiz, Coralogix), scripting and automation (Torq/Tines/SOAR); strong IR, detection engineering, and threat-hunting skills.
SIEM, EDR, Wiz, Coralogix, Torq, Tines, SOAR, AWS CloudTrail, Jira, incident.io
1w
Save
Mark Applied
Hide
Senior Security Engineer, IAM
Illinois or Kentucky or Kansas or Idaho or Delaware or Colorado or Nevada or Nebraska or Montana or Michigan or Maryland or Iowa or Florida or California or Utah or Ohio or New Jersey or Minnesota or Massachusetts or Indiana or Georgia or Arizona or Alabama or Wisconsin or Washington or Virginia or West Virginia or Oklahoma or Texas or Tennessee or Pennsylvania or North Carolina or New Mexico or New York or Missouri or Louisiana or Connecticut or Washington, D.C. or South Carolina or Oregon or New Hampshire
$130k-$195k/yr RemoteFull Time
Relativity
Relativity: Private legal data intelligence providing AI-powered e-discovery software to law firms, corporations, and government agencies.
8+ YOEBachelor's degree or equivalent experience; 8+ years in enterprise IAM/security engineering, or master's degree with 6+ years; expert identity platforms, protocols, threat detection, automation, and security frameworks.
Okta, Microsoft Entra ID, Ping, SailPoint, Saviynt, CyberArk, BeyondTrust, SAML, OpenID Connect (OIDC), OAuth 2.0, SCIM, LDAP, Kerberos, Python, Bash, PowerShell, AWS, Microsoft Azure, GCP, MITRE, NIST 800-63, Zero Trust, CISSP, CISM, GCIH, GCFA, CCSP, AWS Security Specialty, SC-300, AZ-500, SIEM, SOAR, UEBA, FIDO2, ZTNA, CIS Benchmarks, DISA STIGs, CI/CD, IaC, MFA, SSO
2mo
Save
Mark Applied
Hide
Sr Cybersecurity Engineer
Austin, Texas, United States
$131k-$222k/yr HybridFull Time
PayPal
PayPalNASDAQ: PYPL: Global digital payment platform for consumers and businesses.
3+ YOEBachelor's in a related field and 3+ years cybersecurity experience. Hands-on SIEM/EDR, incident response, detection engineering, threat hunting, scripting (Python/PowerShell/Bash), cloud security (WIZ), and use of tools like Splunk and CrowdStrike.
SIEM, EDR, Splunk, Google SecOps, Falcon CrowdStrike, Microsoft Defender, Python, PowerShell, Bash, WIZ, MITRE ATT&CK, Diamond Model, Sigma, YARA, NIST CSF, NIST 800-53, CIS Controls, CSA CCM, ISO 27001, SOC
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Engineer – Adversary Operations, Innovation & Purple Team Operations
Warren or Austin
HybridFull Time
General Motors
General MotorsNYSE: GM: Designing, building, and selling the world's best vehicles.
Hands-on experience in adversary emulation, purple/red teaming, threat hunting, and detection engineering; experience with endpoint, cloud, network, and logging validation; tooling and scripting for adversary testing.
MSV, AWS, GCP, Azure, ATT&CK
3mo
Save
Mark Applied
Hide
Senior Corporate Security Engineer
Austin or Chicago or New York City or Salt Lake City or San Francisco
$134k-$205k/yr RemoteFull Time
Gong
Gong: AI OS for Revenue Teams
5+ YOERequires 5+ years in security data pipelines, detection, SIEM, threat hunting, or platform engineering; EDR/XDR, CSPM, WAF, zero trust, CI/CD, KQL, SQL, SPL, and MITRE ATT&CK experience.
CrowdStrike, SentinelOne, Microsoft Defender, Wiz, Prisma Cloud, Orca, Cloudflare, Akamai, KQL, SQL, SPL, MITRE ATT&CK, CI/CD, EDR, XDR, WAF, SSPM, ZTNA, DLP, PAM, OAuth, SaaS, macOS, Windows, Linux, Slack, Drive, AI
3w
Save
Mark Applied
Hide
OT Network & Site Infrastructure Engineer
Haskell County or Amarillo or Houston or Dallas or Abilene or Pampa or San Francisco or New York City or Denver or Austin or Calgary or Toronto
$118k-$137k/yr HybridFull Time
Intersect
Intersect: Energy and data center infrastructure-locating industrial demand with dedicated gas and renewable power.
5+ YOEBachelor's degree or equivalent industrial experience; 5+ years in network and infrastructure engineering focused on OT, industrial control, or utilities; expertise with industrial hardware, segmentation, remote access, SCADA, and threat detection.
Palo Alto, Cisco, Hirschmann, Site-to-Site VPNs, Zero Trust Network Access (ZTNA), Nozomi, Claroty, Dragos, CrowdStrike, SCADA Ignition, RTU
3d
Save
Mark Applied
Hide
Cyber Security Engineer
Wichita or Kansas City or Omaha or Sioux Falls or Oklahoma or Texas or Nebraska
OnsiteFull Time
Emprise Bank
Emprise Bank: Family-owned community bank serving personal, business, and embedded-banking customers in the Midwest.
College degree or equivalent education and industry experience; extensive knowledge of SIEM, malware applications, threat detection, patch management, and Active Directory. VMware, hypervisors, Azure/AWS, and Office 365 preferred.
SIEM, Windows Defender, Symantec, Active Directory, VMware, Hypervisor, Azure, AWS, Office 365
1mo
Save
Mark Applied
Hide
Application Security Engineer - ADR
Quincy or Toronto or Austin or Atlanta
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Global financial services and bank holding.
6+ YOEHands-on experience with application security, ADR/RASP/WAAP, SAST/DAST/SCA, cloud (Azure/AWS), DevSecOps, secure SDLC, threat detection, incident response, and relevant security certifications.
Java, .NET, Python, Node.js, Azure, AWS, SAST, DAST, SCA, API Security, Container Security, Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), Ansible, Terraform, Kubernetes, Infrastructure as Code (IaC), Agile, DevOps
1mo
Save
Mark Applied
Hide
Développeur(se) principal(e), Opérations de sécurité et intervention en cas d’incident / Senior Security Operations and Incident Response Engineer
Austin or Montreal
$160k-$272k/yr RemoteFull Time
Unity
UnityNYSE: U: Develops tools for games and interactive experiences.
Hands-on SecOps/Incident Response experience, detection engineering, threat hunting, cloud (AWS/GCP/Azure) knowledge, scripting/APIs for automation, mentoring experience, and strong investigative and communication skills.
AWS, GCP, Azure, APIs