# Detection Engineer II

**Company:** [Instacart](https://hotfix.jobs/companies/instacart)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $142k – $181k/yr
**Experience:** 2+ years
**Skills:** detection engineering, Incident Response, offensive security, AWS, Azure, GCP, macOS, detection-as-code, Python, Go, soar, threat hunting
**Posted:** 2026-07-22

> Detection Engineer building and operating high-fidelity detection systems, threat hunting, and automated response across endpoint, cloud, container, and SaaS environments at Instacart. Requires 2+ years in detection/IR/offensive security, cloud experience, deep attacker TTP knowledge, macOS internals, and detection-as-code practices.

## Job Description

## Responsibilities
- Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
- Assist in cyber forensic investigations across a variety of log sources.
- Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost.
- Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions.
- Mentor/knowledge share with other detection engineers on threat hunting methodologies, detection logic development, and investigation techniques.

## Requirements
- 2+ years of experience in a detection engineering, incident response, or offensive security role.
- Experience with 1 or more public cloud platforms (AWS, Azure, GCP).
- Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries.
- Proficient understanding of macOS internals and telemetry available to identify macOS specific threats.
- Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines.
- Basic proficiency with Python, Golang, or other programming/scripting languages.
- Relevant certifications such as GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar.

## Nice-to-Haves
- Background in offensive security or red teaming.
- Knowledge of machine learning for threat detection.

## Similar roles

- [Software Engineer](https://hotfix.jobs/jobs/2516092c-420d-4916-beab-00533e9ad1a2) - Illumio - Sunnyvale, CA - $141k – $162k/yr
- [Security Operations Engineer II](https://hotfix.jobs/jobs/4114c108-d299-4430-a46f-375cf70b17a8) - Upstart - Remote - $134k – $186k/yr
- [Enterprise Security Engineer](https://hotfix.jobs/jobs/c5835d39-47f3-430b-bff2-a31818d37d3e) - Applied Intuition - Sunnyvale, CA - $133k – $180k/yr
- [Product Security Engineer](https://hotfix.jobs/jobs/01e68ca7-3894-424c-81d4-c697b10ba519) - Chime - San Francisco, CA - $130k – $180k/yr
- [Security Engineer IC](https://hotfix.jobs/jobs/318213bd-c101-4018-8a88-3b26a3cb3a1f) - Stripe - Seattle, WA - $159k – $238k/yr

**Apply:** https://hotfix.jobs/jobs/bd254448-d347-417b-a32b-42ef4f1eff89
**Canonical:** https://hotfix.jobs/jobs/bd254448-d347-417b-a32b-42ef4f1eff89