Security Engineer, Detection & Response
Security Engineer focused on operating the SIEM, building AI-augmented detection tooling, triaging alerts, and leading incident response for a high-scale mobile adtech platform.
About the job
Responsibilities
- Own day-to-day operation of Liftoff's SIEM (Panther) — log source ingestion, detection content, and the alert investigation pipeline.
- Lead Liftoff's adoption of AI-augmented SOC tooling (e.g. Prophet, Dropzone, or equivalent) as a multi-year modernization investment.
- Triage incoming security alerts and drive timely investigation and remediation with stakeholders across Engineering and IT.
- Lead incident response — investigation, containment, and post-incident review — and mature processes and runbooks so response becomes predictable and repeatable.
- Build tooling and automation that detects active threats, enriches alerts, and reduces manual investigation toil.
- Partner with Engineering and IT to make detection and response self-service where possible — clear log-onboarding paths, documented detection proposals, accessible runbooks.
- Close the feedback loop between the team's offensive and proactive findings and detection coverage.
- Partner across the security team on cloud, infrastructure, and application security work.
- Participate in the Security team's on-call rotation and incident response.
Requirements
- 5+ years in security engineering, security operations, detection engineering, or software engineering with a security focus.
- Hands-on production SIEM operation — onboarding log sources, writing and maintaining detection content, and triaging alerts.
- Write production-quality code for security automation and detection-as-code.
- Experience leading or substantially contributing to security incident response.
- Strong technical writing — design docs, runbooks, and post-incident reviews.
- Demonstrated judgment in prioritizing security work using a risk-based approach.
- Ability to quickly navigate large, unfamiliar codebases and reason about complex engineering systems.
- Excellent verbal communication.
- Willing to participate in an on-call rotation.
Nice-to-Haves
- Hands-on experience with an AI-augmented SOC platform (Prophet Security, Dropzone AI, or equivalent), or with building large language model (LLM) augmented investigation and runbook tooling.
- Experience operating in cloud environments at scale.
- Cloud incident response experience, particularly in AWS.
- Endpoint forensics for incident response on Mac and/or Linux.
- Detection-as-code workflows in continuous integration and deployment (CI/CD) pipelines.
- Mobile adtech or high-volume SaaS background.
Skills
SIEM, Panther, Detection Engineering, Incident Response, Python, Security Automation, AWS, Ai-Augmented Soc, Endpoint Forensics, CI/CD
Similar jobs
Security Engineering jobsDevelops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.
Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.