Detection Engineer
Builds and maintains security detections, monitoring, automation, and incident response capabilities across SaaS, endpoint, identity, and Google Cloud environments. The role requires hands-on Google SecOps experience, scripting ability, and strong knowledge of attack techniques and security frameworks.
About the job
Responsibilities
- Build and maintain security detection and incident response capabilities.
- Triage security alerts, conduct investigations, and lead response efforts.
- Develop, tune, and maintain security detection rules and alerts.
- Onboard data, parse events, create rules, and build dashboards in Google SecOps (Chronicle).
- Monitor security across JAMF MDM for macOS endpoints, Google Workspace, Okta, and SaaS applications.
- Monitor cloud security in Google Cloud, including Google Cloud Security Command Center.
- Automate detection and response tasks, data parsing, and security tooling integrations.
- Translate attack techniques and threat intelligence into actionable detections.
- Continuously improve security practices and posture while reducing manual work.
Requirements
- Proven experience in incident response and security operations.
- Strong detection engineering experience.
- Hands-on experience with SIEM infrastructure, specifically Google SecOps (Chronicle).
- Experience with security monitoring across endpoint, workspace, identity, SaaS, and cloud platforms.
- Experience with Google Cloud and familiarity with Security Command Center.
- Solid scripting skills for security automation and integrations.
- Deep understanding of common attack techniques and threat intelligence.
- Familiarity with MITRE ATT&CK and the NIST Cybersecurity Framework.
- Excellent analytical and problem-solving skills, attention to detail, and investigative reasoning.
Benefits
- Annual discretionary learning and development stipend.
- Annual discretionary social travel stipend.
- Annual company offsite.
- Monthly co-working stipend for employees outside main hubs.
Skills
Incident Response, Security Operations, Detection Engineering, Google Secops, Chronicle, SIEM, Jamf Mdm, Google Workspace, Okta, GCP, Security Command Center, Python, Bash, Mitre Att&Ck, Nist Cybersecurity Framework
Similar jobs
Security Engineering jobsOwn and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.
Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Investigates trust and safety issues while managing legal requests, anti-abuse operations, and sensitive escalations. The role requires 3–5 years of relevant ISP or hosting-provider experience, DNS knowledge, and strong collaboration and communication skills.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.