Senior Detection Engineer II
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.
About the job
Responsibilities
- Develop, tune, document, and maintain detection logic across endpoint, cloud, container, and SaaS log sources.
- Assist with cyber forensic investigations across varied log sources.
- Optimize log ingestion pipelines and telemetry collection for high-quality, actionable security data while managing volume and cost.
- Design and build SOAR playbooks and automation workflows for detection triage, enrichment, and response.
- Mentor junior security analysts and detection engineers on threat hunting, detection logic, and investigation techniques.
Requirements
- 6+ years of experience in detection engineering, incident response, or offensive security.
- Experience with one or more public cloud platforms: AWS, Azure, or Google Cloud.
- Deep understanding of attacker TTPs in modern zero-trust environments, including identity compromise, token theft, and abuse of trust boundaries.
- Proficiency with macOS internals and telemetry for identifying macOS-specific threats.
- Experience implementing detection-as-code workflows with version control, peer review, automated testing, and CI/CD deployment pipelines.
- Basic proficiency with Python, Golang, or other programming languages.
- Relevant certifications such as GCFA, GCFE, GNFA, GREM, OSCP, or GCIA.
Nice-to-haves
- Background in offensive security or red teaming.
- Knowledge of machine learning for threat detection.
Compensation and Benefits
- ATS-listed salary: $192,000–$242,500 USD annually, depending on location.
- Eligible for a new-hire equity grant and annual refresh grants.
- Benefits and compensation may vary based on work location, experience, and required skills.
- Remote work with flexibility to work from home, an office, or another preferred location, alongside regular in-person events.
Skills
AWS, Azure, GCP, macOS, Python, Go, Soar, CI/CD, Threat Hunting, Detection-As-Code, Incident Response, Red Teaming, Machine Learning, Cyber Forensics, Zero Trust
Similar jobs
Security Engineering jobsSenior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.
This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.