About this role
Our vision is to transform how the world uses information to enrich life for all .
Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.
1. Job Title & Role Overview
Senior Detection Engineer — Security Information and Event Management (SIEM) Engineering and Detection Content Engineering. Experience required: 4 to 8 years.
Role Overview
The Senior Detection Engineer is a senior technical contributor accountable for SIEM delivery and detection content engineering across the enterprise. You will design, build, test, deploy, tune, and continuously improve detections that draw on SIEM, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), cloud, identity, network, endpoint, application, and email telemetry.
3. Responsibilities and Tasks
SIEM Engineering and Delivery
- Drive the design, implementation, maintenance, and optimization of the enterprise SIEM platform.
- Define and maintain the SIEM delivery roadmap in line with Global Security Organization strategy and business priorities.
- Onboard security-relevant log sources with appropriate parsing, normalization, enrichment, correlation, retention, and searchability.
- Monitor and improve platform availability, performance, scalability, capacity.
- Keep SIEM components on supported versions and ensure relevant patches and updates are applied.
- Troubleshoot data ingestion, pipeline, parsing, indexing, correlation, and platform performance issues.
- Maintain engineering standards, technical documentation, architecture artifacts, and operating procedures for the SIEM environment.
- Identify security-control and detection-coverage gaps and recommend prioritized improvements.
- Define security key performance indicators and engineering metrics for SIEM and detection capabilities.
- Maintain documented review of detection exceptions, accepted risks, suppressions, exclusions, and rule changes.
- Link engineering outcomes to the Global Security Organization’s strategic roadmap and business needs.
4. Qualifications and Experience
- 4 to 8 years in cybersecurity, security engineering, SIEM engineering, detection engineering, or incident response With a BE/BTech graduation.
- Strong hands-on experience operating and engineering an enterprise SIEM platform.
- Experience integrating and analyzing telemetry from network, endpoint, cloud, identity, application, and email platforms.
- Proven ability to convert threat intelligence, adversary behaviors, and incidents into technical detection content.
5. Required Technical Skills
- Data pipeline fundamentals — log ingestion, parsing, normalization, enrichment, schema mapping, correlation, indexing, retention, and data quality.
- Scripting — Python, PowerShell, Bash, or comparable, applied to automation and content engineering.
- Engineering tooling — hands-on use of APIs, Git or another version-control platform, and structured content-development practices.
- Analysis and documentation — strong analytical, troubleshooting, and technical-writing capabilities.
Detection query and analytics languages — proficiency in one or more of KQL, SPL, EQL, ES|QL, SQL, Lucene, Sigma, or equivalent.
6. Security Technology Knowledge
These technologies matter here as telemetry sources and broader security domain context. Next-generation firewalls such as Cisco or Palo Alto Networks, plus firewall management and monitoring solutions and Endpoint security Tools (EDR, PAM, PKI, DLP).
- Web proxy and Secure Web Gateway technologies; Zscaler familiarity is preferred.
- Remote-access and SSL VPN solutions.
- Intrusion Prevention Systems such as Cisco Firepower or similar platforms.
- IPsec tunnels, site-to-site connectivity, and business-to-business interconnects.
- Stateful inspection, TCP/IP, DNS, HTTP/HTTPS, web protocols, and general networking concepts.
- Network Detection and Response technologies, SSL/TLS certificates, certificate exchange, PKI, and certificate management.
- Endpoint protection and EDR technologies such as SentinelOne, CrowdStrike, Carbon Black, or Cylance.
- Network data loss prevention technologies such as DarkTrace, McAfee
- Access control, data classification, and data-loss-prevention concepts. Cloud, identity, application, email, and endpoint security telemetry.
- Use AI-enabled security tools and automation to improve threat detection, incident response, and operational efficiency across cybersecurity environment.
- Identify opportunities to automate repetitive security tasks, reduce manual effort, and help build smarter, faster, and more scalable cyber operations.
- Apply AI and data-driven insights to analyze security events, correlate signals, and support proactive protection of systems, data, and intellectual property
- Understanding of AI/ML concepts and a strong willingness to learn and apply AI tools to improve cybersecurity operations, threat detection, and response efficiency.
- Automation-first mindset with the ability to identify repetitive manual tasks and leverage scripting, workflow automation, and AI-enabled tools to secure Micron more effectively.
About Micron Technology, Inc.
We are an industry leader in innovative memory and storage solutions transforming how the world uses information to enrich life for all . With a relentless focus on our customers, technology leadership, and manufacturing and operational excellence, Micron delivers a rich portfolio of high-performance DRAM, NAND, and NOR memory and storage products through our Micron® and Crucial® brands. Every day, the innovations that our people create fuel the data economy, enabling advances in artificial intelligence and 5G applications that unleash opportunities — from the data center to the intelligent edge and across the client and mobile user experience.
To learn more, please visit micron.com/careers
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
To request assistance with the application process and/or for reasonable accommodations, please contact [email protected]
Micron Prohibits the use of child labor and complies with all applicable laws, rules, regulations, and other international and industry labor standards.
Micron does not charge candidates any recruitment fees or unlawfully collect any other payment from candidates as consideration for their employment with Micron.
AI alert : Candidates are encouraged to use AI tools to enhance their resume and/or application materials. However, all information provided must be accurate and reflect the candidate's true skills and experiences. Misuse of AI to fabricate or misrepresent qualifications will result in immediate disqualification.
Fraud alert: Micron advises job seekers to be cautious of unsolicited job offers and to verify the authenticity of any communication claiming to be from Micron by checking the official Micron careers website in the About Micron Technology, Inc.