Detection engineering is the systematic process of creating, testing, and maintaining security detections. The architect establishes the detection lifecycle: Hypothesis (based on threat intel or TTP) → Rule Development (SPL/Sigma) → Testing (against known-bad datasets) → Deployment (via CI/CD pipeline) → Monitoring (alert volume, FP rate) → Tuning/Retirement.
Sigma is an open standard for writing SIEM-agnostic detection rules. The architect may use Sigma rules as the source format and compile them to Splunk SPL, enabling portability and community contribution. This approach decouples detection logic from the SIEM platform.