Procter & Gamble Logo

Procter & Gamble

Senior Detection Engineer (AI-ML Focus)

Posted One Month Ago
Be an Early Applicant
In-Office
Cincinnati, OH
110K-165K Annually
Senior level
In-Office
Cincinnati, OH
110K-165K Annually
Senior level
Build, test, tune, and scale SIEM and data-lake detection rules mapped to MITRE ATT&CK. Manage detection-as-code through Git, pull requests, and CI/CD pipelines; reduce false positives and improve alert fidelity. Collaborate with threat intelligence, threat hunting, SOC, and data engineering teams. Use AI agents, LLM-assisted workflows, and AI/ML techniques to accelerate validation, coverage analysis, anomaly detection, and behavioral analytics. Monitor emerging threats and document detection logic and tuning decisions.
The summary above was generated by AI

Job Location

CINCINNATI GENERAL OFFICES

Job Description

At P&G, we believe that diverse experiences help build strong leaders. Mobility is a key component of many management careers, providing opportunities to grow through different assignments, locations, and business challenges. Candidates should be prepared to consider relocation opportunities throughout their career as business needs and development opportunities arise. 

The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI — using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.

You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands-on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.

Key Success Metrics

Your success would be based on operational and project deliverables, which would be reviewed on a quarterly basis. Your manager would provide full-support though continuous mentoring and coaching

  • Detection rules you write catch real threats and generate minimal noise
  • You measurably improve alert fidelity (TP rate) and reduce SOC case volume
  • You operate independently within the detection-as-code workflow (branch → validate → deploy)
  • You leverage AI tooling to work faster — not as a research project, but as a daily force multiplier
  • Quarterly deliverables reviewed with your manager through continuous mentoring and coaching

Job Responsibilities

Detection Engineering:
  • Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk
  • Write detection logic across the SIEM and data lake platforms
  • Manage detection content as code — Git-based workflows, PR reviews, CI/CD deployment pipelines
  • Investigate and suppress false positives systematically using lookup-based architectures
  • Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI→TH→DE pipeline)
  • Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns
AI-Augmented Detection (Differentiator):
  • Leverage AI agents and LLM-assisted workflows to accelerate detection rule development, validation, and coverage analysis
  • Use and contribute to MCP (Model Context Protocol) tooling that enables AI-assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps)
  • Operate agentic pipelines that triage large rule libraries against live telemetry at scale
  • Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets
  • Stay current on frontier AI threats (agentic attacks, LLM-assisted exploitation, AI-generated phishing) and translate them into detection opportunities
Collaboration & Operations:
  • Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements
  • Collaborate with data engineers on telemetry availability, data quality, and log source onboarding
  • Contribute to detection coverage reporting and MITRE ATT&CK posture measurement
  • Document detection logic, tuning rationale, and suppression decisions

    Job Qualifications

    Technical Competencies and Experience:

    Required:

    • Bachelor’s degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience in detection engineering, security operations, or threat detection roles
    • Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real-time alerts)
    • Strong understanding of MITRE ATT&CK framework and its application to detection coverage
    • Proficiency in Python for automation, scripting, and tooling
    • Experience with git-based workflows (branching, PRs, CI/CD) for managing security content
    • Familiarity with security log sources: EDR, identity, cloud, network, proxy
    • Strong analytical skills and ability to distinguish true threats from noise in large datasets

    Preferred:

    • Certifications CISSP, CCSP, OSCP, GIAC Certified Detection Analyst (GCDA), GCIA, Relevant certifications in cloud & ML/AIExperience with multiple query languages are helpful but not required
    • Experience with detection-as-code practices and YAML-based rule formats (Sigma, custom schemas)
    • Working knowledge of AI/LLM capabilities and their security implications — both as detection targets and as engineering tools
    • Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows
    • Familiarity with SOAR platforms and their integration with detection pipelines
    • Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments

    Compensation for roles at P&G varies depending on a wide array of non-discriminatory factors including but not limited to the specific office location, role, degree/credentials, relevant skill set, and level of relevant experience. At P&G compensation decisions are dependent on the facts and circumstances of each case. Total rewards at P&G include salary + bonus (if applicable) + benefits.  Your recruiter may be able to share more about our total rewards offerings and the specific salary range for the relevant location(s) during the hiring process.

    We are committed to providing equal opportunities in employment. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

    Immigration Sponsorship is not available for this role. For more information regarding who is eligible for hire at P&G along with other work authorization FAQ’s, please click HERE.

    Procter & Gamble participates in E-Verify.

    Qualified individuals will not be disadvantaged based on being unemployed.

    P&G is dedicated to meeting the needs of applicants requesting an accommodation/adjustment due to a disability in order to complete the online application process.  If you have a disability that affects your ability to complete our online application process, please visit our Disability Accommodation Page.

    Job Schedule

    Full time

    Job Number

    R000155624

    Job Segmentation

    Experienced Professionals

    Starting Pay / Salary Range

    $110,000.00 - $165,300.00 / year

    Procter & Gamble Rosemont, Illinois, USA Office

    10255 W Higgins Rd, Rosemont, IL, United States, 60018

    Similar Jobs

    16 Minutes Ago
    Remote or Hybrid
    United States
    111K-180K Annually
    Senior level
    111K-180K Annually
    Senior level
    Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
    Leads architecture, modernization, optimization, and reliability initiatives for mainframe CICS, MQ, and z/OS Connect environments. Provides technical direction across development and operations teams, establishes governance and change processes, tunes performance using telemetry, resolves incidents, and develops modernization roadmaps. Collaborates with stakeholders and enterprise architects to deliver secure, scalable, high-availability solutions while evaluating automation, cloud integration, and AI technologies.
    Top Skills: AnsibleCicsCobolDevOpsIbm MqIbm Z/OsOpenshiftPythonRed Hat Ansible Automation PlatformZ/Os ConnectZlinux
    16 Minutes Ago
    Remote or Hybrid
    United States
    111K-180K Annually
    Senior level
    111K-180K Annually
    Senior level
    Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
    Leads the architecture, modernization, resilience, security, and performance optimization of enterprise mainframe environments. Responsibilities include z/OS performance tuning, WLM and RACF administration, business continuity planning, automation, technical governance, incident resolution, stakeholder collaboration, and guidance of cross-functional engineering and operations teams. The role also evaluates cloud, DevOps, AI, and hybrid IT technologies for mainframe transformation.
    Top Skills: AnsibleCsmGlobal MirrorIbm Z/OsMetro MirrorOpenshiftPr/SmPythonRacfRed Hat Ansible For Ibm Z CollectionsRmfSmfWlmZlinux
    16 Minutes Ago
    Hybrid
    215K-355K Annually
    Expert/Leader
    215K-355K Annually
    Expert/Leader
    Fintech • Financial Services
    Leads the Application Network Services organization, overseeing engineering managers and teams delivering load balancing, firewall, DNS, application security, DDoS protection, and bot detection services. Sets strategic roadmaps, manages financial and staffing resources, drives engineering quality, resilience, risk management, compliance, innovation, and continuous improvement, and collaborates with senior technology and business stakeholders.
    Top Skills: Application SecurityApplication-Layer Ddos ProtectionBot DetectionCloud-Based SecurityDnsFirewallsLoad BalancingNetwork Security

    What you need to know about the Chicago Tech Scene

    With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

    Key Facts About Chicago Tech

    • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
    • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
    • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
    • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
    • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
    • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account