Senior Security Engineer, Detection & Response
Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
About the job
Responsibilities
Detection Engineering
- Build and tune detections across endpoint, identity, SaaS, and cloud environments.
- Treat detections as software using version control, peer review, and CI/CD practices.
- Measure detection quality through MITRE ATT&CK coverage, precision, and time-to-detect.
Response and Automation
- Own incident response, including triage, containment, remediation, and retrospectives.
- Build automation to reduce investigation toil.
- Coordinate with global security teammates to preserve context across time zones.
Telemetry and Threat Hunting
- Define telemetry requirements for new systems before launch.
- Partner with infrastructure and product teams to close visibility gaps.
- Proactively threat hunt and convert hypotheses into detections or documented coverage.
Requirements
- Typically 5–8 years of experience in detection engineering, incident response, or threat hunting.
- Hands-on experience writing and tuning detections.
- Proficiency in Python, Go, or a similar programming language.
- Experience writing production-grade detection and automation code.
- Experience with a modern SIEM or detection pipeline such as Panther, Elastic, or Splunk.
- Practical incident response experience, including major involvement in triaging and closing security incidents.
Nice-to-Haves
- Experience treating detections as code with CI/CD, peer review, and staged rollout.
- Experience defining telemetry contracts before systems ship.
- Experience evaluating and validating AI-assisted work.
- Familiarity with cloud-native and Kubernetes telemetry.
- Experience with fraud or financial-crime detection patterns.
Compensation
- US base salary: $183,272–$229,091 USD.
- Additional compensation may include bonus, equity, and benefits.
Skills
Python, Go, SIEM, Panther, Elastic, Splunk, CI/CD, Mitre Att&Ck, Kubernetes, Threat Hunting, Incident Response, Cloud Telemetry
Similar jobs
Security Engineering jobsThe Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.