# Staff Detection Engineer

**Company:** [Fluidstack](https://hotfix.jobs/companies/fluidstack)
**Location:** New York, NY, San Francisco, CA, Austin, TX, Seattle, WA
**Role:** Security Engineering
**Salary:** $269k – $330k/yr
**Experience:** 8+ years
**Skills:** detection engineering, Incident Response, Python, AWS, GCP, Azure, edr, detection-as-code, Sigma, Threat Modeling
**Posted:** 2026-07-21

> Build and lead the detection engineering function from the ground up for a company building gigawatt-scale AI compute infrastructure. Own detection-as-code pipelines, lead high-severity incident response, automate triage, and partner on security strategy. Requires 8+ years scaling detection/IR programs with deep cloud and endpoint detection experience.

## Job Description

## Role Scope
Build the detection engineering function from the ground up: telemetry pipelines, detection content, alert routing, and response runbooks, with coverage you can defend against a threat model, not just a tool checklist.

Own detection-as-code end to end, writing detections across cloud and endpoint sources with tests, version control, and CI so a bad rule never ships silently.

Lead incident response for high-severity events, driving containment and root cause, and closing out each incident with detections that catch the same class of attack next time.

Drive automation of triage and enrichment in Python (or similar) so alert volume scales without proportional headcount.

Partner directly with leadership on security strategy, translating threat landscape and detection gaps into a prioritized roadmap with clear tradeoffs.

Work across corp IT and infrastructure teams to get the telemetry, logging, and access you need, and to fix the root causes your detections keep surfacing.

## Requirements
- 8+ years in security operations, detection engineering, or incident response, with time spent at a high-growth tech company, cloud-native infrastructure provider, or top-tier MDR/threat intel firm.
- Built or scaled a detection engineering function, not just operated inside one: you can point to the program, the pipeline, and the coverage that exist because of you.
- Deep hands-on experience writing detections against cloud telemetry (AWS, GCP, or Azure control plane and audit logs) and endpoint telemetry (EDR event streams, OS-level signals).
- Strong scripting and automation skills in Python or similar, enough to build and maintain detection-as-code pipelines yourself rather than spec them for someone else.
- Incident response experience at a company operating at significant scale, where you led response under pressure and your postmortems changed how the company operates.
- Operate as a technical lead without heavy management overhead: you set direction, make the calls, and do the work.
- Work well across corp IT and infrastructure teams in a fast-moving environment, and get telemetry and fixes shipped by making the case, not by escalating.

## Nice-to-Haves
- Experience securing GPU clusters, HPC environments, or physical data center infrastructure.
- Contributions to open-source detection content (Sigma, community rule sets).

## Similar roles

- [Member of Technical Staff, SecOps & Threat Detection Engineer](https://hotfix.jobs/jobs/39765d60-0022-4a70-9f23-866a5b6b63e5) - Envoy - San Francisco, CA - $265k – $310k/yr
- [Secure Manufacturing & Stealth Partner, Marketing](https://hotfix.jobs/jobs/01484828-a22c-4b90-bb28-b5355f7afcd6) - OpenAI - San Francisco, CA - $288k – $425k/yr
- [Staff Product Security Engineer](https://hotfix.jobs/jobs/79405bb0-9cc6-4690-8bb5-f9c43867f6f6) - Crusoe - San Francisco, CA - $250k – $285k/yr
- [Software Engineer, Security](https://hotfix.jobs/jobs/e6283f18-9abb-4d55-acf7-cc3220bb1636) - Notion - San Francisco, CA - $290k – $350k/yr
- [Staff Engineer, Identity](https://hotfix.jobs/jobs/17532c43-a1a5-4ac8-ba1e-b0102c2abc9a) - Postman - San Francisco, CA - $245k – $300k/yr

**Apply:** https://hotfix.jobs/jobs/7f41ea31-28ec-4758-b7a9-40c65e9dad92
**Canonical:** https://hotfix.jobs/jobs/7f41ea31-28ec-4758-b7a9-40c65e9dad92