Skip to content
EnvoyEnvoy

Member of Technical Staff, SecOps & Threat Detection Engineer

Staff Security Engineer owning threat detection, SIEM architecture, and security operations for cloud, apps, and endpoints. Requires 6+ years in security/SRE/infra engineering with experience building detection-as-code, endpoint monitoring (SentinelOne), and driving MTTD/MTTR improvements in AWS environments.

About the job

Responsibilities

  • Own the design and evolution of our threat detection and security operations capability.
  • Define detection strategy across cloud infrastructure, applications, and endpoints.
  • Establish and improve our SIEM and monitoring architecture, including signal quality, coverage, and scalability.
  • Design and implement detection-as-code practices, setting standards for how detection logic is built, tested, and maintained.
  • Drive visibility across all critical assets, ensuring endpoints, services, and identities are consistently monitored.
  • Take ownership of endpoint security monitoring (e.g., SentinelOne), including integration into centralized detection workflows.
  • Lead the design and rollout of automated security controls, including secrets rotation for high-risk systems.
  • Define alerting strategy, including severity models, escalation paths, and on-call expectations.
  • Lead investigations into complex or ambiguous security signals, setting the standard for root cause analysis and response.
  • Partner with engineering teams to improve instrumentation and ensure systems emit high-quality security signals.
  • Define and track key metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive measurable improvements.
  • Mentor and guide other engineers, raising the overall capability of the team in detection and security operations.

Requirements

  • 6+ years of experience in Security Engineering, SRE, or Infrastructure Engineering with a strong security focus.
  • Proven experience designing or significantly improving security monitoring, detection, or SIEM systems.
  • Strong understanding of cloud environments (ideally AWS), including IAM, networking, and logging at scale.
  • Experience working with endpoint detection and response tools such as SentinelOne or similar.
  • Deep experience working with logs, events, and telemetry to build meaningful, high-signal detections.
  • Strong programming or scripting skills (Python, Go, or similar), with a focus on automation and system design.
  • A strong understanding of attacker behavior and the ability to translate threats into detection strategies.
  • Experience defining alerting models and reducing noise while maintaining strong coverage.
  • Ability to operate in ambiguous environments and define structure where none exists.
  • Strong cross-functional communication skills, with the ability to influence engineering and leadership.
  • A pragmatic, outcome-oriented mindset focused on reducing real risk and improving operational effectiveness.

Nice-to-Haves

  • This is an L5 opportunity. Successful candidates typically come from staff or principal-level roles and are recognized for establishing technical direction, leading large-scale initiatives, and shaping engineering strategy across organizations.

Skills

SIEM, AWS, Sentinelone, Python, Go, Threat Detection, Security Monitoring, Detection As Code, Endpoint Detection, IAM, Logging, Automation

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Imprint

Imprint

San Francisco, CA
Senior Engineering Manager, Security
$220k+/yrHybrid8+ YOESecurity Engineering

Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.