Tempus AI Logo

Tempus AI

Detection Engineer

Posted 19 Days Ago
Hybrid
Chicago, IL
100K-140K Annually
Entry level
Hybrid
Chicago, IL
100K-140K Annually
Entry level
Build and maintain reliable log ingestion pipelines to deliver security events to a SIEM. Implement batching, sizing, failure handling, tests, and CI standards. Integrate systems via APIs, assist detection engineering with parser/field fixes, manage detection-as-code in git, and contribute to agentic SOC workflows and SOAR automations with human-in-the-loop validation.
The summary above was generated by AI

Passionate about precision medicine and advancing the healthcare industry?

Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.

**About our teams:** With a mission to use data and AI to power precision medicine and improve patient care, our teams blend deep healthcare expertise with modern product development practices. Tempus products are owned and developed by small, autonomous teams made up of software engineers, designers, scientists, and product managers. These teams set goals, build the software, deploy the code, and contribute to a growing platform that is transforming healthcare.

**Detection Engineer:** The Security Operations Center is building the data foundation for threat detection—reliable pipelines that land security events in our SIEM platform. This is a software engineering role inside security: you will build in Python, integrate APIs, and test your work, with mentorship on SIEM usage, detection logic, and alert quality. Over time, you will help us grow **agentic SOC workflows** (AI-assisted triage, enrichment, and detection support) with human-in-the-loop guardrails—adding automation only when the data and evidence justify it, not on a hype-driven timeline.

Responsibilities:

  • Build and maintain log ingestion pipelines that collect security events from internal and third-party sources and deliver them to our SIEM platform.

  • Normalize and forward events using existing patterns for batching, sizing, and failure handling.

  • Build tests and fix bugs using mocked APIs and team CI standards (lint, format, coverage).

  • Operate pipelines reliably—monitor failures, tune ingestion windows and rate limits, and document configuration.

  • Support detection engineering with guidance—validate that new data is queryable in the SIEM; assist with simple parser or field fixes; learn how detections map to adversary behavior.

  • Help manage and improve our detection-as-code pipeline—versioned detection content in git, automated checks in CI, and review before changes reach production.

  • Participate in code review.

Agentic SOC (incremental; human-in-the-loop):

  • Build with agentic coding tools (e.g. Claude Code, Cursor) as part of daily development—direct, review, and test what you ship; do not rely on typing every line from scratch.

  • Contribute incrementally to agentic workflows—enrichment scripts, structured handoffs into SOAR automations, and evaluation of AI-assisted summaries or drafts in non-production or human-reviewed paths before any autonomous response.

  • Validate changes on historical data before production trust—rules, parsers, and automation earn approval through evidence, simulation or shadow mode, and defined rollback paths.

  • Assist in building and maintaining SOAR automations (enrichment, triage steps, and documentation—with review before production changes).

Requirements:

  • Comfortable building Python—APIs and JSON, basic error handling, and tests in a managed project (Poetry or similar).

  • Ability to integrate systems via APIs—OAuth or API keys, retries, and handling partial failures.

  • Testing discipline—unit tests, readable failures, and fixing regressions you introduce before merge.

  • Git and collaborative development—small, reviewable changes with clear descriptions of risk and rollout.

  • Temperament for long-horizon work—you can focus on incremental pipeline quality while understanding it enables agentic SOC capabilities over time, not instead of them.

  • Strong problem-solving skills and curiosity about security operations; willingness to learn detection concepts with mentorship.

Bonus points for:

  • Experience with scheduled jobs or Docker.

  • Hands-on SIEM exposure from coursework, CTFs, labs, or internships (e.g. Splunk, Google SecOps, Microsoft Sentinel).

  • Can navigate cloud primitives on GCP, Azure, or AWS (S3/GCS/Blob, Key Vault/Secret Manager/Secrets Manager, IAM roles and service principals).

  • Experience with infrastructure as code (e.g. Terraform).

  • Strong understanding of IAM principles in GCP (least privilege, service accounts, workload identity, and role bindings).

#LI-Hybrid#LI-BL1

Chicago Base salary: $100,000-$140,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. 

Tempus AI New York, New York, USA Office

Tempus AI New York City - Tempus Office Office

Our New York City office sits in the iconic Helmsley Building in Midtown Manhattan. Just steps from Grand Central Terminal, you’re surrounded by world-class dining, luxury boutiques, landmark architecture, and seamless transit options.

Similar Jobs at Tempus AI

14 Hours Ago
Hybrid
New York City, NY, USA
100K-160K Annually
Senior level
100K-160K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
The Machine Learning Scientist will develop AI frameworks for predictive modeling in oncology, collaborating with teams to enhance drug R&D efforts through advanced machine learning techniques and multimodal data integration.
Top Skills: AIGenerative AiLanggraphPython
Yesterday
Hybrid
New York City, NY, USA
90K-150K Annually
Mid level
90K-150K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Partner with biopharma clients to design and execute computational translational research using large clinical and molecular datasets. Drive account strategy, co-architect solutions on the Tempus platform, communicate technical results to non-technical stakeholders, author whitepapers, and collaborate with Product and Engineering. Travel ~25%.
Top Skills: AWSCSS3D3DaskDockerFlaskGgplotGitHTML5JavaScriptJupyter NotebooksMatplotlibNumpyPandasPlot.LyPythonRRstudioScikit-LearnScipySeabornSQLTidyverse
Yesterday
Hybrid
New York City, NY, USA
90K-150K Annually
Mid level
90K-150K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Partner with biopharma clients to design and execute computational translational research using large clinical and molecular datasets. Drive account strategy, co‑architect client solutions on the Tempus platform, communicate technical results to nontechnical stakeholders, author thought leadership, and collaborate with Product and Engineering. Travel ~25%.
Top Skills: PythonRSQL

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account