Staff Software Engineer - Detection Platform
Leads modernization and reliability improvements for high-volume detection engines and event pipelines. The role requires deep production distributed-systems experience in Go, cross-team technical leadership, and strong operability practices.
About the job
Responsibilities
- Lead modernization of detection engines and high-volume event pipelines, including support for the Sigma v2 specification and stateful event correlation.
- Rework existing detection pipelines and build new ones on a common platform, replacing bespoke per-product detectors.
- Define validation approaches to prove replacement pipelines behave equivalently before staged cutovers and retirement of legacy paths.
- Improve reliability under load through end-to-end latency measurement, liveness coverage, absence-of-work alerting, and bounded recovery mechanisms.
- Establish coherent event schemas and data contracts across engineering teams.
- Build validation and drift-detection tooling to identify upstream schema changes before they disrupt detections.
- Lead major cross-team technical workstreams, set direction, and write and review production code.
Requirements
- Deep experience designing, building, and operating distributed production systems at scale, primarily in Go.
- Experience working across multiple layers of the stack.
- Experience replacing or substantially re-architecting live, high-throughput systems without breaking consumers.
- Experience with high-volume event or data pipelines and their behavior under load.
- Strong observability and operability practices, including alerting for missing expected work.
- Demonstrated technical leadership across team boundaries without relying on positional authority.
- Strong judgment regarding production quality and release readiness.
- Hands-on experience with AI coding tools and a security-focused approach to correctness.
Nice-to-haves
- Security operations or security engineering experience, including writing or tuning detections or working in a SOC.
- Experience with detection-as-code or rule- and DSL-driven systems, including parsing and evaluation.
- Experience building platform tooling for rule writers, analysts, and researchers.
- Ruby on Rails experience.
Technology
- Go, Kafka, Temporal, Redis, ClickHouse, Elasticsearch, Kubernetes, AWS, Azure, Ruby on Rails, Sigma.
Compensation and Benefits
- Base compensation: $200,000–$220,000, plus bonus and equity.
- 100% remote work environment.
- Paid time off, including vacation, sick time, and holidays.
- 12 weeks of paid parental leave.
- Medical, dental, and vision benefits.
- 401(k) with a 5% contribution regardless of employee contribution.
- Life and disability insurance.
- Stock options for full-time employees.
- $500 one-time home-office reimbursement.
- Annual education and professional-development allowance.
- $75 USD monthly digital reimbursement.
- BetterUp coaching and professional-growth access.
Skills
Go, Kafka, Temporal, Redis, ClickHouse, Elasticsearch, Kubernetes, AWS, Azure, Ruby on Rails, Sigma, Distributed Systems, Event Pipelines, Observability
Similar jobs
Backend Engineering jobsLeads architecture, development, integration, and certification-oriented testing of C++ safety-critical software that monitors autonomous systems and ensures safe operation. Requires substantial experience with real-time systems, software assurance standards, technical leadership, and mentoring.
Build and own the geospatial data foundation behind Radar’s high-throughput geocoding platform, spanning ingestion, enrichment, indexing, and serving. The role requires a generalist engineer comfortable across Scala, Python, and Rust, with experience in large-scale data systems and customer collaboration valued.
Leads the technical vision and architecture for large-scale backend systems powering experimentation, personalization, analytics, and conversion optimization. The role requires 12+ years of software engineering experience, deep distributed-systems expertise, and cross-functional technical leadership.
Develop and operate Go-based, containerized microservices for a distributed cloud security platform processing real-time telemetry and events. The role requires 8+ years building scalable systems, cloud API experience, and strong programming, networking, and operational ownership.
Leads architecture and delivery of secure, highly available backend services for an identity-aware gateway connecting enterprise AI agents to authorized tools and data. Requires 7+ years of distributed backend experience, production Java or Go, and deep OAuth, OIDC, and token-exchange expertise.