Detection Engineer
Build and operate security detection and incident response capabilities, including SIEM engineering, cloud and SaaS monitoring, alert investigations, and automation. The role requires hands-on experience with Google SecOps, Google Cloud security, scripting, threat intelligence, and security frameworks.
About the job
Responsibilities
- Build and maintain security detection and incident response capabilities.
- Develop, tune, and maintain security detection rules and alerts.
- Triage security alerts, conduct investigations, and lead response efforts.
- Onboard and parse data, create rules, and build dashboards in Google SecOps (Chronicle).
- Monitor security across JAMF MDM for macOS endpoints, Google Workspace, Okta, and SaaS applications.
- Monitor cloud security in Google Cloud, including Google Cloud Security Command Center.
- Automate detection and response tasks, data parsing, and security tooling integrations using scripting.
- Translate common attack techniques and threat intelligence into actionable detections.
- Continuously improve security practices and reduce manual work through automation and AI models.
Requirements
- Proven experience in incident response and security operations.
- Strong background in detection engineering.
- Hands-on experience with SIEM infrastructure, specifically Google SecOps (Chronicle).
- Proficiency in security monitoring across endpoint, workspace, identity, SaaS, and cloud platforms.
- Experience with Google Cloud security monitoring and Security Command Center.
- Solid scripting skills for automating security tasks and integrating security tooling.
- Deep understanding of common attack techniques and threat intelligence.
- Familiarity with security frameworks and best practices, including MITRE ATT&CK and the NIST Cybersecurity Framework.
- Excellent analytical and problem-solving skills, attention to detail, and ability to connect disparate information during investigations.
Benefits
- Annual discretionary professional development stipend.
- Annual discretionary social travel stipend.
- Annual company offsite.
- Monthly coworking stipend for employees outside main hubs.
Skills
Google Secops, Chronicle, SIEM, Jamf Mdm, macOS, Google Workspace, Okta, GCP, Security Command Center, Python, Bash, Mitre Att&Ck, Nist Cybersecurity Framework, Threat Intelligence, Incident Response
Similar jobs
Security Engineering jobsBuild and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.