Senior Detection Creation Engineer
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
About the role
As a Detection Creation Engineer on the ASE Detection Team, you will: Develop security detections that identify active malicious activity across Apple's services and infrastructure, implementing detection logic in Scala Spark (Databricks) and on-host detection frameworks (Falco rules) Analyze attacker behaviors and translate them into observable patterns across diverse telemetry sources including system call events, network logs, database access logs, endpoint security telemetry, Kubernetes audit logs, and other security-relevant data sources Collaborate with engineering teams to understand system architectures, identify detection opportunities, and develop detections that are both high-fidelity and operationally sustainable Tune and optimize detections based on real-world alert data, reducing false positives while maintaining coverage of malicious behaviors Operationalize detections by working with security operations teams to ensure alerts are actionable, triaged efficiently, and integrated into incident response workflows Document detection logic and rationale to enable knowledge sharing across the security organization