Detection Engineer

Tempus AI Tempus AI · Vertical AI · Chicago, IL

This role focuses on building and maintaining data pipelines for security events, with a future goal of developing agentic SOC workflows. The engineer will integrate APIs, test work, and contribute to AI-assisted triage and enrichment, emphasizing human-in-the-loop guardrails and automation based on evidence.

What you'd actually do

  1. Build and maintain log ingestion pipelines that collect security events from internal and third-party sources and deliver them to our SIEM platform.
  2. Normalize and forward events using existing patterns for batching, sizing, and failure handling.
  3. Build tests and fix bugs using mocked APIs and team CI standards (lint, format, coverage).
  4. Operate pipelines reliably—monitor failures, tune ingestion windows and rate limits, and document configuration.
  5. Support detection engineering with guidance—validate that new data is queryable in the SIEM; assist with simple parser or field fixes; learn how detections map to adversary behavior.

Skills

Required

  • Python
  • API integration
  • Testing
  • Git
  • Problem-solving
  • Curiosity about security operations

Nice to have

  • Scheduled jobs
  • Docker
  • SIEM exposure (Splunk, Google SecOps, Microsoft Sentinel)
  • Cloud primitives (GCP, Azure, AWS)
  • Infrastructure as code (Terraform)
  • IAM principles in GCP

What the JD emphasized

  • agentic SOC workflows
  • human-in-the-loop guardrails
  • automation only when the data and evidence justify it, not on a hype-driven timeline
  • Build with agentic coding tools (e.g. Claude Code, Cursor) as part of daily development—direct, review, and test what you ship; do not rely on typing every line from scratch.
  • Contribute incrementally to agentic workflows—enrichment scripts, structured handoffs into SOAR automations, and evaluation of AI-assisted summaries or drafts in non-production or human-reviewed paths before any autonomous response.
  • Validate changes on historical data before production trust—rules, parsers, and automation earn approval through evidence, simulation or shadow mode, and defined rollback paths.

Other signals

  • agentic SOC workflows
  • AI-assisted triage
  • enrichment
  • detection support
  • human-in-the-loop guardrails
  • automation