---
title: "Security Detection Engineer"
company: "WPP"
company_url: "https://www.remjobs.works/companies/wpp"
url: "https://www.remjobs.works/job/wpp-security-detection-engineer-d27d916f-5662-4810-b751-ac1c2e4204c1"
apply_url: "https://job-boards.greenhouse.io/wpp/jobs/8725217002"
workplace: onsite
location: "Chennai, Tamil Nadu, India"
employment_type: unspecified
seniority: mid
role: devops-infrastructure
region: india
skills: ["python"]
date_posted: 2026-08-27T10:40:45.000Z
first_seen_by_remjobs: 2026-09-17T11:38:59.489Z
---

# Security Detection Engineer

**WPP** · Chennai, Tamil Nadu, India

Apply: https://job-boards.greenhouse.io/wpp/jobs/8725217002

## About the role

**WPP is the trusted growth partner for the world’s leading brands. **

**We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. **
** **
**We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.**
** **
**Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. **
** **
**For more information, visit [WPP.com.](https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&reserved=0)**
** **

**Why we're hiring:**

Detection Engineering is responsible for designing, developing, and maintaining high-fidelity detection logic across enterprise security platforms. This role focuses on proactive threat detection, automation-first practices, and continuous improvement of detection coverage and accuracy, supporting the WPP SOC transformation into an Autonomic Security Operations model.

**What you'll be doing:**

- Develop, test, and maintain detection rules and logic across SIEM, EDR, NDR, and cloud-native platforms.

- Regularly review and enhance detection logic to improve accuracy, reduce noise, and align with evolving threats.

- Work with wider WPP engineering teams to ensure high-quality, normalized telemetry for effective detection.

- Automate detection rule deployment, QA, and version control using scripting and CI/CD pipelines.

**Root Cause Analysis (RCA)**

- Conduct RCA on missed detections, delayed responses, and high-severity incidents.

- Identify technical and process-level causes of detection failures or inefficiencies.

- Drive corrective actions based on RCA outcomes (e.g., rule improvements, visibility gaps).

- Continuous Security Improvement (CSI)

- Maintain a CSI backlog (detection gaps, telemetry blind spots, false positives to reduce).

- Analyze detection performance metrics to identify trends and opportunities for improvement.

- Align detection priorities with business risk and the SOC transformation roadmap.

- Cross-Team Collaboration

- Collaborate with SOC, Incident Response, and Threat Hunting teams to operationalize detection improvements.

- Work with Threat Intelligence teams to integrate emerging TTPs into detection logic.

- Contribute to purple team exercises by validating detection logic against simulated attack paths.

**Strategic Alignment to GCAT SOC10x**

- 10X People: Continuous learning and knowledge sharing within the team.

- 10X Process: Embed agile workflows and automation-first principles.

- 10X Technology: Leverage AI/ML for detection tuning and anomaly detectio.

- 10X Visibility: Ensure comprehensive telemetry ingestion and observability.

- 10X Speed: Reduce detection-to-response cycle through orchestration and automation.

**What you'll need:**

**Technical Expertise**

- Strong knowledge of SIEM, SOAR, EDR, and cloud security platforms.

- Proficiency in scripting and automation (Python, PowerShell).

- Familiarity with detection-as-code principles and CI/CD pipelines.

- Understanding of MITRE ATT&CK framework and threat-informed defense.

**Collaboration & Communication**

- Ability to work closely with SOC analysts, threat hunters, and engineers.

- Skilled in documenting detection logic and RCA outcomes.

**Certifications (Preferred)**

- GIAC GCTI, GCFA, or equivalent advanced security certifications.

**Key Attributes**

- Automation-first mindset with focus on scalability and resilience.

- Strong analytical and problem-solving skills.

- Excellent communication and teamwork capabilities.

**Who you are:**

**You're open*:* **we are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.

**You're optimistic*:*** we approach all that we do with confidence: to try the new and to seek the unexpected.

**You're extraordinary:** We are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.

**What we'll give you:**

**Passionate, inspired people** – we champion a culture of people that do extraordinary work

**Scale and opportunity** – we offer the opportunity to create, influence and deliver projects at a scale that is unparalleled in the industry.

**Challenging and stimulating work** – unique work and the opportunity to join a group of creative problem solvers.

#LI-Hybrid

**We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.**

**WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.**

###### Please read our Privacy Notice ([https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment](https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment)) for more information on how we process the information you provide.

---

Source: WPP's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/wpp-security-detection-engineer-d27d916f-5662-4810-b751-ac1c2e4204c1
