Company Overview
KLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. No laptop, smartphone, wearable device, voice-controlled gadget, flexible screen, VR device or smart car would have made it into your hands without us. KLA invents systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards and flat panel displays. The innovative ideas and devices that are advancing humanity all begin with inspiration, research and development. KLA focuses more than average on innovation and we invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists and problem-solvers work together with the world’s leading technology providers to accelerate the delivery of tomorrow’s electronic devices. Life here is exciting and our teams thrive on tackling really hard problems. There is never a dull moment with us.
Job Description/Preferred Qualifications
This position will be responsible for developing the strategy for the Detection Engineering program and establishing metrics to demonstrate continuous improvement. The ideal candidate will possess expert-level knowledge in SIEM implementation and log ingestion, SOAR, along with leveraging Threat Intelligence to enable enhanced detection and Incident Response capabilities. Utilization of data-driven strategies, strong verbal and written communication, and leadership skills are a must for this role.
- Define detection engineering strategy, roadmap, and objectives, aligning priorities with the Security Operations Center.
- Manage and inspire a global team of cybersecurity engineers focused on supporting our Global Cyber Operations Team to monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness.
- Analyze historical and current KLA security data and red team/purple team activities to determine opportunities for custom rule creation or tuning of existing detections.
- Collaborates with Security Operations Center (SOC) team to continuously build and tune detection capabilities to detect across identity, network, and endpoint monitoring platforms to drive down Mean Time to Detect and Respond (MTTD / MTTR).
- Experience with supporting multiple security related technologies, such as SIEM, SOAR, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint solutions, data loss prevention (DLP), or other cyber security tools.
- Design and implement advanced threat detection techniques using tools such as SIEM, EDR, NDR, and SOAR platforms.
- Manages and maintains SIEM/Data Lake data management and log ingestion infrastructure in collaboration with IT partners.
- Partner with the Cyber Threat Intelligence team and leverage industry standard MITRE frameworks to identify detection coverage and close gaps.
- Maintains operational guidelines, diagrams, and documentation.
- Lead continuous process improvement and ensure the team is identifying opportunities for automation and fusion of disparate sources of security findings.
Minimum Qualifications
- Minimum seven (7) years in cybersecurity, including at least 2 years in a leadership or managerial role
- Proven track record in incident detection, response, and threat hunting across complex, global environments.
- Deep understanding of security technologies such as SIEM, SOAR, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint solutions, data loss prevention (DLP), or other cyber security tools.
- Excellent leadership and interpersonal skills with the ability to influence and partner across both technical and non-technical teams.
- Willingness to travel up to 25% domestically and internationally as business needs require.
Interns are eligible for some of the benefits listed. Our pay ranges are determined by role, level, and location. The range displayed reflects the pay for this position in the primary location identified in this posting. Actual pay depends on several factors, including state minimum pay wage rates, location, job-related skills, experience, and relevant education level or training. We are committed to complying with all applicable federal and state minimum wage requirements where applicable. If applicable, your recruiter can share more about the specific pay range for your preferred location during the hiring process.
KLA is proud to be an Equal Opportunity Employer. We will ensure that qualified individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us at or at +1-408-352-2808 to request accommodation.
Be aware of potentially fraudulent job postings or suspicious recruiting activity by persons that are currently posing as KLA employees. KLA never asks for any financial compensation to be considered for an interview, to become an employee, or for equipment. Further, KLA does not work with any recruiters or third parties who charge such fees either directly or on behalf of KLA. Please ensure that you have searched
KLA’s Careers website
for legitimate job postings. KLA follows a recruiting process that involves multiple interviews in person or on video conferencing with our hiring managers. If you are concerned that a communication, an interview, an offer of employment, or that an employee is not legitimate, please send an email to to confirm the person you are communicating with is an employee. We take your privacy very seriously and confidentially handle your information.
Report job