Talent.com
Security Detection Engineer I

Security Detection Engineer I

AppFolioChicago, IL, United States
11 hours ago
Job type
  • Full-time
Job description

Overview

Join to apply for the Security Detection Engineer I role at AppFolio

The Security Detection Engineer I will design, develop, and optimize detections that identify and prevent account takeover (ATO) activity across AppFolios platform. This role is responsible for building scalable detection logic and telemetry pipelines that surface suspicious patternssuch as credential stuffing, MFA abuse, session hijacking, or automation-based fraud. The engineer will work closely with Security Analysts, Risk, Fraud, and Engineering teams to operationalize threat intelligence, improve alert fidelity, and reduce attacker dwell time while ensuring detections evolve with emerging ATO tactics.

1 week ago Be among the first 25 applicants

Location : Chicago, IL see location notes on our site.

Responsibilities

  • Design, implement, and maintain detection logic to identify account takeover (ATO) attempts across AppFolio platforms.
  • Develop and tune behavioral analytics and rule-based detections in SIEM and security data platforms to improve signal fidelity.
  • Leverage threat intelligence, internal telemetry, and adversary TTPs to proactively build detection coverage for evolving ATO techniques.
  • Collaborate with security analysts, fraud investigators, and engineering teams to validate alerts, reduce false positives, and ensure timely detection.
  • Perform detection gap assessments and participate in purple team or simulation exercises to evaluate coverage for ATO scenarios.
  • Automate detection engineering workflows using scripting and data pipelines for scale and efficiency.
  • Contribute to threat modeling efforts and define detection use cases aligned with MITRE ATT&CK and real-world ATO patterns.
  • Document detection logic, assumptions, tuning rationale, and testing methodology in standardized playbooks and engineering wikis.

Qualifications

  • Bachelors degree in Computer Science, Cybersecurity, Engineering, or equivalent work experience.
  • 35 years of experience in detection engineering, security operations, or threat detection.
  • Proficient with SIEM technologies (e.g., Splunk, Elastic), query languages (SPL, SQL, Kusto), and detection-as-code practices.
  • Strong understanding of ATO threat landscape including credential stuffing, MFA abuse, session hijacking, and token replay attacks.
  • Experience creating and tuning detection logic to identify anomalies across authentication, identity, and web traffic telemetry.
  • Familiarity with MITRE ATT&CK, OWASP, and identity-based threat modeling frameworks.
  • Hands-on experience with cloud-based environments (AWS preferred) and monitoring their security logs and event sources.
  • Knowledge of version control (e.g., Git), CI / CD pipelines, and detection-as-code workflows (e.g., using Terraform, Python, Jupyter, or YAML).
  • Excellent collaboration and communication skills with the ability to convey detection rationale to technical and non-technical stakeholders.
  • Excellent verbal and written communications skills.
  • Nice to have

  • Experience with identity security tools and telemetry : Okta, Duo, etc.
  • Familiarity with session-based ATO detection techniques, including cookie theft, browser fingerprinting, or geolocation analysis.
  • Certifications such as GCDA, GCIH, AWS Security Specialty, or OSWE.
  • Prior exposure to fraud prevention, customer account protection, or abuse detection platforms.
  • Experience in adversary emulation or purple teaming to test and validate detections.
  • Location

    Find out more about our locations by visiting our site.

    Compensation & Benefits

    The compensation that we reasonably expect to pay for this role is : $104,000-$130,000 base pay. The actual compensation for this role will be determined by a variety of factors, including but not limited to the candidates skills, education, experience, and internal equity.

    Please note that compensation is just one aspect of a comprehensive Total Rewards package. The compensation range listed here does not include additional benefits or any discretionary bonuses you may be eligible for based on your role and / or employment type. Regular full-time employees are eligible for benefits see here.

    About AppFolio

    AppFolio is the technology leader powering the future of the real estate industry. Our innovative platform and trusted partnership enable our customers to connect communities, increase operational efficiency, and grow their business. For more information about AppFolio, visit .

    Why AppFolio

    Grow | We enable a culture of high performance, where delivering results is recognized by opportunities for growth and compelling total rewards. Our challenging and meaningful work drive the growth of our business, and ourselves.

    Learn | We partner with you to realize your potential by investing in you from the start. We''re cultivating a team of big thinkers through coaching and mentorship with our best-in-class leaders, and giving you the time and tools to develop your skills.

    Impact | We are creating a world where living in, investing in, managing, and supporting communities feels magical and effortless, freeing people to thrive. We innovate with purpose while cultivating a culture of impact.

    Connect | We excel at hybrid work by fostering an environment that feels flexible, personal and connected, no matter where we are. We create space to fuel innovation and collaboration, and we come together to celebrate, connect, and succeed.

    Paddle as One.

    Equal Opportunity

    Statement of Equal Opportunity

    At AppFolio, we value diversity in backgrounds and perspectives and depend on it to drive our innovative culture. Thats why were a proud Equal Opportunity Employer. This means that no matter race, color, religion, sex, sexual orientation, gender identification, national origin, age, marital status, ancestry, physical or mental disability, or veteran status, youre welcome at AppFolio.

    #J-18808-Ljbffr

    Create a job alert for this search

    Detection Engineer • Chicago, IL, United States

    Related jobs
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    MorningstarChicago, IL, United States
    Full-time
    We are seeking a Lead Security Engineer to help drive our security detection and response efforts.In this role, you will be responsible for designing, implementing, and improving security monitorin...Show moreLast updated: 4 days ago
    • Promoted
    • New!
    Security Engineer

    Security Engineer

    Solution Partners (IL)Chicago, IL, United States
    Full-time
    This range is provided by Solution Partners, Inc.Your actual pay will be based on your skills and experience talk with your recruiter to learn more. Direct message the job poster from Solution Partn...Show moreLast updated: 13 hours ago
    • Promoted
    • New!
    M&A Security Engineer

    M&A Security Engineer

    HUB InternationalChicago, IL, United States
    Full-time
    At HUB International, we are a team of entrepreneurs.We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and de...Show moreLast updated: 9 hours ago
    • Promoted
    Security Engineer

    Security Engineer

    RAPPChicago, IL, United States
    Full-time
    RAPP Chicago is looking for a Security Engineer to join our award-winning Technology team.We are RAPP - world leaders in activating growth with precision and empathy at scale.As a global, next-gene...Show moreLast updated: 2 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Strata Decision TechnologyChicago, IL, United States
    Full-time
    We're looking for a hands-on Security Engineer to help protect Strata's systems, data, and users.In this individual-contributor role, you'll monitor and triage alerts, investigate and respond to in...Show moreLast updated: 4 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    MorningstarChicago, IL, United States
    Full-time
    We are seeking a Senior Security Engineer to help drive our security detection and response efforts.In this role, you will be responsible for designing, implementing, and improving security monitor...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer III

    Security Engineer III

    NorthShore PC ServiceSkokie, IL, United States
    Full-time
    Position : Security Engineer III.The hourly pay rate offered is determined by a candidate's expertise and years of experience, among other factors. Location : 4901 Searle Parkway, Skokie IL (flexible)...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer (Chicago)

    Security Engineer (Chicago)

    Fitch GroupChicago, IL, United States
    Full-time
    Fitch Group is currently seeking a Security Engineer based out of our Chicago office.As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insight...Show moreLast updated: 4 days ago
    • Promoted
    Security / Vulnerability Engineer

    Security / Vulnerability Engineer

    CyberTecChicago, IL, United States
    Full-time
    One day in Mount Prospect and the other day you can choose to work in the Chicago office or Mount Prospect office.Role : Security / Vulnerability Engineer. Duration : 6 months with extension.Location : C...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer III - Identity and Access Management

    Security Engineer III - Identity and Access Management

    TalentBridgeSkokie, IL, United States
    Full-time
    Salary Range : 115000 to 135000.Work Schedule : Remote 90% with some light travel on-site for meetings and go-live, and 1 week rotations of 24 / 7 support every 8 weeks or so.They are looking for somew...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer III

    Security Engineer III

    NorthShore University HealthSystemSkokie, IL, United States
    Full-time
    Position : Security Engineer III.The hourly pay rate offered is determined by a candidate's expertise and years of experience, among other factors. Location : 4901 Searle Parkway, Skokie IL (flexible)...Show moreLast updated: 4 days ago
    • Promoted
    Sr Lead Security Engineer

    Sr Lead Security Engineer

    JPMorgan Chase Bank, N.A.Chicago, IL, United States
    Full-time
    Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.As a Senior Lead Secur...Show moreLast updated: 4 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    SG360°Wheeling, IL, United States
    Full-time
    Fortune 1000 brands to pursue unmatched direct marketing performance.We leave no stone unturned in our efforts to drive smarter targeting, stronger messaging and improved ROI.Everything we do - aud...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer II

    Security Engineer II

    TalentBridgeSkokie, IL, United States
    Full-time +1
    Job Title : Security Engineer II.Location : Skokie, IL 60077 (Remote - require onsite for meetings or as needed).Salary Range : $100000 to $115000. As the Security Engineer II, you will be responsible ...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer III

    Security Engineer III

    TalentBridgeChicago, IL, United States
    Full-time
    Location : Candidates must be local to Illnois but the role will be primarily performed remotely.However candidates will need to be onsite a couple times a month for team meetings.Step into a senior...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer (Remote)

    Security Engineer (Remote)

    BioSpace, Inc.North Chicago, IL, United States
    Remote
    Full-time
    AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable i...Show moreLast updated: 4 days ago
    • Promoted
    API Security Engineer

    API Security Engineer

    eTeamChicago, IL, United States
    Full-time
    The API Security Engineer is responsible for securing APIs across the organization's systems and services.This role involves identifying and mitigating vulnerabilities, monitoring API activity, and...Show moreLast updated: 4 days ago
    • Promoted
    • New!
    Senior Security Engineer

    Senior Security Engineer

    Solution Partners, Inc.Chicago, IL, United States
    Full-time
    We're seeking a seasoned Senior Security Engineer to help lead our security architecture and engineering efforts.This role will drive strategic and operational leadership in security architecture, ...Show moreLast updated: 17 hours ago