Skip to content
NotionNotion

Security Engineer, Detection and Response

Build and operate detection systems for cloud, identity, endpoints, and SaaS. Design high-signal detections, improve detection platforms, and participate in incident response.

About the job

What You'll Achieve

  • Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  • Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, and postmortems that drive long-term security improvements.
  • Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
  • Participate in a shared on-call rotation for incident response.

Skills You'll Need to Bring

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Built and operated production detections with strong signal quality and sustainable tuning processes.
  • Fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
  • Offensive security mindset with experience leading purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
  • Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
  • Hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.

Nice to Have

  • Experience applying LLMs or agent-style tooling to security workflows.
  • Experience securing AI-enabled systems or endpoint tooling.
  • Kubernetes or container detection experience.
  • Background in threat intelligence, malware analysis, or digital forensics.
  • Contributions to the detection engineering community through research, tooling, or talks.
  • Experience at a high-growth startup or AI company.

Skills

Sigma, Kql, Spl, Yara-L, Eql, Panther, SIEM, Edr, Soar, AWS, GCP, Azure, Threat Hunting, Incident Response, Purple Teaming

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Imprint

Imprint

San Francisco, CA
Senior Engineering Manager, Security
$220k+/yrHybrid8+ YOESecurity Engineering

Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.

Spade

Spade

United States
Senior Platform Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

Snowflake

Snowflake

Menlo Park, CA
Senior Software Engineer - Cloud Security
$200k+/yrHybrid5+ YOESecurity Engineering

Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.