Security Engineer, Detection and Response
Build and operate detection systems for cloud, identity, endpoints, and SaaS. Design high-signal detections, improve detection platforms, and participate in incident response.
About the job
What You'll Achieve
- Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
- Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
- Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
- Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
- Participate in investigations, incident response, and postmortems that drive long-term security improvements.
- Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
- Participate in a shared on-call rotation for incident response.
Skills You'll Need to Bring
- 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
- Built and operated production detections with strong signal quality and sustainable tuning processes.
- Fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
- Offensive security mindset with experience leading purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
- Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
- Hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
- Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.
Nice to Have
- Experience applying LLMs or agent-style tooling to security workflows.
- Experience securing AI-enabled systems or endpoint tooling.
- Kubernetes or container detection experience.
- Background in threat intelligence, malware analysis, or digital forensics.
- Contributions to the detection engineering community through research, tooling, or talks.
- Experience at a high-growth startup or AI company.
Skills
Sigma, Kql, Spl, Yara-L, Eql, Panther, SIEM, Edr, Soar, AWS, GCP, Azure, Threat Hunting, Incident Response, Purple Teaming
Similar jobs
Security Engineering jobsLeads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.