Thanks to my iPhone's "on this day" memories, I got a screenshot recently of the acceptance letter from my very first cybersecurity internship, nine years ago. Come next year, I'll be closing in on ten years since I touched my first SIEM. Today, I'm ecstatic to join Nebulock as Head of Detection Strategy alongside Founder and CEO Damien Lewke and the entire Nebulock team.
I joined Nebulock because I was genuinely pulled in by the security-first, hunt-first mindset, and the opportunity to help shape what’s next without dragging along the baggage of legacy software trying to morph into something it was never built to do. It's the same reason you can't bolt attachments onto a dishwasher and expect a good clotheswashing job out of it. You just end up with something fragile. I’ve always thought it was a bit backwards how a decade of bolted-on acquisitions still gets marketed as "modern" or "next-gen."
I've watched SIEM evolve from both sides since, as an end user and as a vendor, across Fortune 500 deployments all the way down to a company procuring its first SIEM. That’s the macro view. Zooming in, I've spent the cycles hammering out detection logic to fit whatever environment I was standing in, babysitting it when it inevitably broke the same handful of ways, over and over, none of it ever written down anywhere. Content libraries growing stale and getting ported from SIEM to SIEM, swap cycle after swap cycle, migration after migration.
Detection engineering was the unsung craft behind all that wrangling closely tied to the SIEM tech it took to wrangle multiple domains and still hold unified visibility across an enterprise. The job is about detecting specific, narrow behaviors that legitimate software or processes almost never do, so when it fires, it’s actually something worth an analyst’s time.
The skill that separates a good detection engineer from someone copying rules off SigmaHQ is knowing which fields actually matter for a given technique, and tuning out the noise before it reaches the SOC queue. That tuning is 80% of the job. Writing the rule is the easy 20%.
My detection POV has been shaped by people I respect in this field: SRE discipline, fraud algorithmic thinking, and red/blue/purple adversarial emulation. It's hard to instill across large organizations inheriting years of legacy SIEM toil fallout.
Data feeds and rules don't break for a concrete, classifiable number of reasons. Cataloging those the same way we do CVEs, as a taxonomy of why detection logic breaks, with a clear record of every specific instance of it happening is how we break out of the tuning toil. Daniel Koifman’s research and work on the ADE framework has been a great foundation for that kind of thinking. Once categorized, markdowned, and embedded into memory, we stop rediscovering the same failure every 18 months like it's a new species. That's why agentic AI, applied to that kind of chaos, feels like the right lens.
Nebulock is built differently underneath. There's a columnar canvas running the whole thing, a better fit for how we query entities across large-scale environments without having to read the full disk every time. It augments instead of forcing a rebuild. In the case of Cribl, a rapidly growing, globally distributed, SaaS-born, cloud-native environment, Nebulock showed its value within a couple of weeks.
Damien built a team that actually cares about that distinction: practitioners who've lived through the work themselves, going after entrenched, well-funded competition with a better answer instead of a bigger budget. Fortune 500 environments taught me that generic doesn't survive contact with a real environment. Nebulock builds like they know that.
I'd be lying if I didn't mention that working alongside good friend and industry peer Sydney Marrone Howard pulled me in, too. As DE<>TH peers, we've talked about the overlap between detection engineering and threat hunting on podcasts and at industry events for a few years. Now we get to help build it together.
There will come a time when hunts graduate into detections. I'm looking forward to cracking that code across our customers down to a science. More to come on that.
Alex Hurtado
Follow my journey on LinkedIn and subscribe to my podcast