# Senior Detection Engineer

**Company:** [Fluidstack](https://hotfix.jobs/companies/fluidstack)
**Location:** New York, NY, San Francisco, CA, Austin, TX, Seattle, WA
**Role:** Security Engineering
**Salary:** $176k – $218k/yr
**Experience:** 5+ years
**Skills:** detection engineering, threat hunting, SIEM, edr, Splunk, elastic, crowdstrike, mitre att&ck, Python, SQL, detection-as-code, Threat Modeling
**Posted:** 2026-07-21

> Own end-to-end detection engineering program including threat modeling, detection-as-code pipelines, threat hunting, SIEM/EDR tuning, alert triage and incident response for rapidly scaling AI compute infrastructure. Requires 5+ years in detection engineering or threat hunting with deep SIEM/EDR and scripting experience.

## Job Description

## Role Scope
Own the detection engineering program end to end: threat modeling, detection design, deployment, tuning, and retirement, with coverage mapped to MITRE ATT&CK and gaps documented rather than assumed away.

Build detection-as-code pipelines so every rule is version-controlled, tested, and peer-reviewed before it ships, and false-positive rates are measured, not guessed.

Run threat hunts against real adversary behavior in our cloud, SaaS, and data center environments, and convert findings into repeatable detections.

Drive SIEM and EDR pipeline health: log source onboarding, normalization, and alert quality good enough that on-call responders trust what pages them.

Lead triage and response for the alerts you build, and close out incidents with root-cause writeups that change the detection stack, not just the ticket queue.

Build automation that removes manual triage steps, so the team's alert load scales slower than the company does.

## Requirements
- 5+ years in detection engineering or threat hunting inside a mature security operations org (cloud-native infrastructure, SaaS, or fintech).
- Deep hands-on experience with SIEM and EDR tooling: Splunk, Elastic, CrowdStrike, or equivalent, including query languages and pipeline tuning, not just console use.
- Written and maintained detection logic mapped to MITRE ATT&CK against real adversary behavior, and can point to detections that caught something.
- Strong scripting and automation skills (Python, SQL, or similar) and a detection-as-code workflow you'd defend: tests, review, and rollback included.
- Know the difference between a noisy rule and a broken one, and tune or kill detections before responders learn to ignore them.
- Operate well with minimal process: scope your own work, ship without a mature SOC around you, and build the process you need as you go.
- Write clearly enough that your runbooks and incident reports work when you're asleep.

## Nice-to-Haves
- Experience securing physical infrastructure or OT/data center environments.
- Purple team experience.
- Contributions to open-source detection content (Sigma, detection rule repos).

## Similar roles

- [Senior Red Team Engineer](https://hotfix.jobs/jobs/08d37bca-f834-4f3b-8f99-26dfeb5cd8d3) - Snowflake - Remote - $176k – $253k/yr
- [Senior Platform Engineer, Security](https://hotfix.jobs/jobs/66279d2d-a2ec-42c9-8617-3e15e999ebac) - Doxel - San Francisco, CA - $175k – $220k/yr
- [Senior Software Engineer, Security](https://hotfix.jobs/jobs/5ceaaeac-36b0-4169-9a44-fb4df6a5ceb6) - Crusoe - San Francisco, CA - $175k – $210k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/597fe572-d370-4678-b5bb-e0e085fe5586) - Sigma - San Francisco, CA - $175k – $220k/yr
- [Senior Security Engineer - Data Security](https://hotfix.jobs/jobs/4ecc0e54-09f4-4a68-a2b7-2892ff1da3e7) - Sigma - San Francisco, CA - $175k – $220k/yr

**Apply:** https://hotfix.jobs/jobs/6e9f5f26-7b5d-45a6-ad57-701c49e31283
**Canonical:** https://hotfix.jobs/jobs/6e9f5f26-7b5d-45a6-ad57-701c49e31283