A focused course, tailored for you
The Security Engineer's Detection Hand-Off Playbook
Turn ad-hoc alert triage into documented detection logic the on-call rotation can run without paging you at 2 a.m.
You are the documented point of escalation for detections you have never written down. The on-call rotation pages you because the runbook says "ask the security engineer." That is a control gap, an availability risk, and a reason you have not taken a real vacation in 18 months.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
A security engineer at a hyperscaler sits at the intersection of three pressures. The detection backlog grows faster than the team. The on-call rotation can only escalate to whoever wrote the query, so escalation defaults to you. And the assurance function has started asking for evidence that detections are reviewed, peer-approved, and operable by anyone in the on-call pool, not just the author. The work that closes all three pressures at once is the same work: take each detection you privately maintain, document the data sources, the threshold logic, the false positive expectations, the severity routing, and the response runbook, then peer-review it into a state where someone else in the rotation can run it cold at 2 a.m. without paging you. Most engineers know they should do this. Almost nobody has the templates, the review cadence, or the evidence pack ready when the auditor asks. This course gives you all three.
What you walk away with
- Document every detection you privately maintain in a peer-reviewable format the on-call rotation can run cold.
- Reduce 2 a.m. pages routed to you by name by at least 60 percent within one quarter.
- Produce an evidence pack a SOC 2 or ISO 27001 auditor can sample without follow-up questions.
- Run a quarterly detection-review cadence with a documented false positive budget per detection.
- Promote one detection per week from private notebook to peer-reviewed, runbook-linked control.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules in the Art of Service learning environment.
- Detection spec template, severity matrix template, false positive budget tracker.
- Runbook skeleton with triage, containment, evidence preservation, and escalation sections.
- Sigma starter pack with three worked examples translated from SPL.
- CI pipeline reference configuration for detection-as-code.
- Backtest and replay notebook with sample telemetry.
- Audit evidence pack template aligned to SOC 2 CC and ISO 27001 Annex A controls.
- Hand-built implementation playbook tailored to your stack, delivered alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours: learning environment access and the hand-built implementation playbook for your stack.
Week one: complete modules one and two, inventory done, first detection spec drafted.
Week two: modules three through five, first peer review meeting scheduled.
Week four: modules six through eight, first detection fully documented end to end with runbook and evidence pack.
Week six to eight: detection-as-code repo live, CI pipeline running, backtest harness in place.
Week ten to twelve: hand-off plan executed, quarterly review meeting on the calendar with leadership.
Before and after
You are the named escalation for every Sev2 detection your team runs. The runbook reads "ask Rafaan." Half your detections live in a private notebook. The audit team asks for evidence and you spend a Saturday compiling screenshots. You have not taken five consecutive days off in 18 months.
Every detection you own has a peer-reviewed spec, a false positive budget, a runbook, and a backtest record. The on-call rotation handles Sev2 without paging you. The audit team pulls evidence from the repo without asking. Your name appears on zero runbooks as the named escalation. You took last week off.
What happens if you do not address this
The detection backlog grows. Your on-call burden grows with it. The next SOC 2 audit cycle asks pointed questions about detection ownership and review cadence and the answers are not ready. A peer with a quieter on-call rotation gets the promotion you wanted because she had time to write the design doc you did not. You leave for a job at a smaller company because the only way out of being the named escalation is to stop being there.
Who it is for
Mid-to-senior security engineer inside a large product organisation. Owns a portfolio of detections across SIEM, EDR, cloud audit logs, and homegrown telemetry. Reports into a security operations or detection engineering manager. Has a strong technical reputation, a packed on-call rotation, and a quiet anxiety about the bus factor of the detections they carry. Familiar with Splunk SPL or Sigma, MITRE ATT&CK mapping, basic Python for log enrichment, and at least one cloud audit-log schema.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Two to three hours per week for twelve weeks. Most of the work is on detections you already own, so the time substitutes for triage time you are already spending.
Why $199 is the right number
SANS detection engineering courses cover the craft but stop at the spec. Vendor certifications cover the product but not the audit evidence layer. Free MITRE ATT&CK material covers the taxonomy but not the peer review cadence. This course assembles the three layers, spec plus operating cadence plus audit pack, into one set of templates and one implementation playbook.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.