You have been staring at the same alert queue for eighteen months. Tier 1 triage, escalate, close, repeat. You know the SIEM cold, you can spot a phishing kill chain in your sleep, and you are wondering if this job has a ceiling or a ladder.
It has a ladder. Detection engineering is the natural next rung for SOC analysts who want to build the rules instead of just chasing them. It also happens to be one of the more durable contract security roles right now, because every organization running a SIEM needs someone who can write detections that actually catch things without drowning the team in false positives.
This is the concrete path, not a motivational one: what you need to learn, what you need to prove, and which certs are worth your money.
The real progression, tier by tier
Job titles vary by employer, but the skill progression is consistent across most SOCs and MSSPs.
- SOC Analyst Tier 1 (0-18 months): alert triage, ticket hygiene, basic log review, escalation judgment.
- SOC Analyst Tier 2 (1-3 years): investigation depth, correlation across log sources, incident scoping, tuning noisy rules.
- Detection Engineer (2-4+ years): writing and maintaining detection logic, mapping coverage to adversary behavior, working with threat intel and red/purple teams.
The jump from Tier 2 to detection engineer is not about seniority alone. It is about shifting from reacting to alerts to authoring the logic that generates them. That shift requires four specific skill sets.
SIEM fluency beyond dashboards
Every SOC analyst can click through a SIEM console. Detection engineers write the query language natively: Splunk SPL, Microsoft Sentinel KQL, Elastic Query DSL, or Chronicle YARA-L, depending on the stack. You need to be able to write a detection from a blank query bar, not just tune a template someone else built.
Equally important is log source enrichment. Raw logs from firewalls, EDR, identity providers, and cloud audit trails rarely arrive in a usable shape. Detection engineers normalize fields, join identity context to network events, and enrich alerts with asset criticality so an analyst downstream is not investigating blind. If you have never mapped a raw Windows Event ID to a normalized schema field, that is your next hands-on project.
MITRE ATT&CK mapping, done properly
Every job posting mentions ATT&CK. Few candidates can actually use it as a working framework instead of a poster on the wall.
Detection engineers use ATT&CK to answer three questions on every rule they write:
- Which technique and sub-technique does this detection cover (e.g., T1059.001, PowerShell)?
- What data source is required to see it, and do we actually collect that data source?
- Where are our coverage gaps, and which gap matters most given our threat model?
Build yourself a coverage matrix, even informally in a spreadsheet, mapping your organization's or lab's detections against the ATT&CK Enterprise matrix. That artifact alone, brought to an interview, tells a hiring manager more than any bullet point on a resume.
Writing detections and surviving purple team feedback
A detection is not done when it fires. It is done when it fires accurately, at a rate the SOC can actually triage, with a documented false-positive rationale. Learn to write a detection rule with three components every time: the logic, the expected data source, and a tuning threshold based on observed baseline noise.
Purple team exercises are where this gets tested for real. A red team or pen tester runs a technique, you validate whether your detection caught it, and you tune or write new logic based on the gap. Contract consultants who can say, credibly, that they have sat in a purple team session and shipped a detection improvement afterward stand out immediately from those who only have SOC ticket metrics on their resume.
Certifications: what earns its cost, what does not
Certs help you get past resume screens for contract roles, but not all of them carry equal weight for detection engineering specifically.
| Certification | Value for detection engineering | Approximate cost |
|---|---|---|
| CompTIA Security+ / CySA+ | Good baseline, gets you past ATS filters early career | Roughly $400 per exam |
| Splunk Certified Cybersecurity Defense Analyst | Directly relevant if your target stack is Splunk | Roughly $130-150 exam fee, plus optional training |
| GIAC GCDA (Certified Detection Analyst) | Strong, purpose-built for this exact role; well regarded by hiring managers | Typically $2,000-$8,000 depending on training bundle |
| MITRE ATT&CK Defender (MAD) | Directly maps to the ATT&CK skills above; niche but relevant | Roughly $300-500 per certification track |
| OSCP | Useful for purple team credibility, not required for detection roles alone | Roughly $1,600-$2,500 with training |
| CISSP | Low direct value here; it is a management-track cert, not a hands-on detection cert | Roughly $750 exam fee |
If you can only fund one cert this year, GCDA or a Splunk-specific credential will move a detection engineering resume further than a broad management cert like CISSP, which is better suited to later, leadership-track roles.
What a contract detection engineer resume needs to show
- A named SIEM platform with query language fluency, not just "SIEM experience"
- At least one documented detection rule you wrote from scratch, with the ATT&CK technique it maps to
- Evidence of log source normalization or enrichment work
- Any purple team, tabletop, or red team collaboration, even informal
- A cert that matches your target stack, not a generic one
Contract clients hiring for detection engineering want someone who can walk in and improve coverage in the first sprint. Specificity on your resume is the fastest way to prove you can do that.
If you are mapping out this move and want a second opinion on which contracts and clients actually value this skill set, the team at Josh Pros LLC works with security consultants across SOC and detection engineering roles nationwide. Reach out at contact@joshpros.com or visit https://joshpros.com to talk through your next step.
#DetectionEngineering #SOCAnalyst #CyberSecurityCareers #MITREATTACK #SIEM #SecurityEngineer #ContractIT #ThreatDetection #PurpleTeam #ITStaffing #SecurityCertifications #CyberCareerPath
Talk to a real recruiter, not a bot.
We'll tell you the rate, the client, and the terms before you interview. And if we're not the right fit, we'll say so.
