Skip to content
FluidstackFluidstackNew York, NY

Staff Detection Engineer

Build and lead the detection engineering function from the ground up for a company building gigawatt-scale AI compute infrastructure. Own detection-as-code pipelines, lead high-severity incident response, automate triage, and partner on security strategy. Requires 8+ years scaling detection/IR programs with deep cloud and endpoint detection experience.

269k – 330k/yr
On-site8+ YOESecurity Engineering

About the role

Role Scope

Build the detection engineering function from the ground up: telemetry pipelines, detection content, alert routing, and response runbooks, with coverage you can defend against a threat model, not just a tool checklist.

Own detection-as-code end to end, writing detections across cloud and endpoint sources with tests, version control, and CI so a bad rule never ships silently.

Lead incident response for high-severity events, driving containment and root cause, and closing out each incident with detections that catch the same class of attack next time.

Drive automation of triage and enrichment in Python (or similar) so alert volume scales without proportional headcount.

Partner directly with leadership on security strategy, translating threat landscape and detection gaps into a prioritized roadmap with clear tradeoffs.

Work across corp IT and infrastructure teams to get the telemetry, logging, and access you need, and to fix the root causes your detections keep surfacing.

Requirements

  • 8+ years in security operations, detection engineering, or incident response, with time spent at a high-growth tech company, cloud-native infrastructure provider, or top-tier MDR/threat intel firm.
  • Built or scaled a detection engineering function, not just operated inside one: you can point to the program, the pipeline, and the coverage that exist because of you.
  • Deep hands-on experience writing detections against cloud telemetry (AWS, GCP, or Azure control plane and audit logs) and endpoint telemetry (EDR event streams, OS-level signals).
  • Strong scripting and automation skills in Python or similar, enough to build and maintain detection-as-code pipelines yourself rather than spec them for someone else.
  • Incident response experience at a company operating at significant scale, where you led response under pressure and your postmortems changed how the company operates.
  • Operate as a technical lead without heavy management overhead: you set direction, make the calls, and do the work.
  • Work well across corp IT and infrastructure teams in a fast-moving environment, and get telemetry and fixes shipped by making the case, not by escalating.

Nice-to-Haves

  • Experience securing GPU clusters, HPC environments, or physical data center infrastructure.
  • Contributions to open-source detection content (Sigma, community rule sets).

Skills

detection engineeringIncident ResponsePythonAWSGCPAzureedrdetection-as-codeSigmaThreat Modeling
Envoy

Member of Technical Staff, SecOps & Threat Detection Engineer

EnvoySan Francisco, CA

Staff Security Engineer owning threat detection, SIEM architecture, and security operations for cloud, apps, and endpoints. Requires 6+ years in security/SRE/infra engineering with experience building detection-as-code, endpoint monitoring (SentinelOne), and driving MTTD/MTTR improvements in AWS environments.

265k – 310k/yrOn-site7+ YOESecurity Engineering
OpenAI

Secure Manufacturing & Stealth Partner, Marketing

OpenAISan Francisco, CA

Serve as the dedicated senior security partner to OpenAI's Marketing team, identifying secrecy risks in launches, events, creative production, and external partners while embedding practical controls that protect sensitive information without slowing execution. Requires 12+ years protecting major product launches and building trusted relationships with executives and creative teams.

288k – 425k/yrHybrid12+ YOESecurity Engineering
Crusoe

Staff Product Security Engineer

CrusoeSan Francisco, CA

Leads advanced penetration testing, red team operations, and AI/ML security research to secure applications, infrastructure, and distributed AI systems including LLMs and Kubernetes environments. Requires 8-10 years offensive security experience and strong software engineering in Go/Python/Rust.

250k – 285k/yrOn-site8+ YOESecurity Engineering
Notion

Software Engineer, Security

NotionSan Francisco, CA

Security engineer owning cross-cutting auth, authorization, and AI guardrail programs across product and infrastructure. Requires 10+ years shipping security-critical infrastructure and experience with AI/LLM protections.

290k – 350k/yrHybrid10+ YOESecurity Engineering
Postman

Staff Engineer, Identity

PostmanSan Francisco, CA

Staff Engineer leading Postman's Identity platform architecture, roadmap, and tier 0 services. Requires 10+ years backend experience, identity standards expertise (OAuth, SAML), Master's degree, and hands-on leadership.

245k – 300k/yrHybrid10+ YOESecurity Engineering