Skip to content
xAIxAI

Security Engineer - Detection & Response

Leads day-to-day threat management through detection engineering, threat hunting, incident response, security automation, and vulnerability analysis. Requires at least two years of information security experience, strong Python skills, and knowledge of operating systems, networking, and cloud security.

About the job

Responsibilities

  • Drive continual improvement in processes, procedures, and automations to improve team quality and effectiveness.
  • Participate in a 24/7 on-call rotation for security incident response.
  • Commandeer security incidents and update stakeholders.
  • Identify and develop new detection use cases and optimize existing detections.
  • Collaborate on technical directions and solutions with other teams.
  • Research and analyze patterns in security events across global infrastructure.
  • Identify, design, and lead threat-hunting missions to quantify and reduce threats.
  • Manage and support log collection, security scanning, intrusion detection, and other security-related systems.
  • Design and assist in developing automation to reduce false positives and handle events automatically.
  • Analyze system security posture through testing and vulnerability-impact analysis.

Requirements

  • 2+ years of relevant information security experience.
  • Self-starter able to execute tasks with minimal supervision.
  • Strong Python scripting skills for security automation.
  • Knowledge of networking and macOS, Windows, or Linux operating systems.
  • Knowledge of vendor-agnostic cloud security fundamentals and practices.
  • Experience managing or deploying security technology.
  • Experience building queries and dashboards for security monitoring.
  • Knowledge of current threats and techniques, with a desire to research and learn more.
  • Experience with malware analysis, forensics, or penetration testing.
  • Strong problem-solving and troubleshooting skills.

Preferred Qualifications

  • Certifications such as CISA, CRISC, CGEIT, Security+, CASP+, or similar.
  • Experience with Elastic, OpenSearch, or similar platforms.
  • Experience with open-source security automation tooling.

Skills

Python, Networking, macOS, Windows, Linux, Cloud Security, Incident Response, Threat Intelligence, Threat Hunting, Intrusion Detection, Malware Analysis, Digital Forensics, Penetration Testing, Elastic, Opensearch

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.