Security Software Engineer II, Detection and Response
Build and improve detection alerts, automation, logging pipelines, and internal tooling to identify and respond to security threats at Pinterest. Requires strong incident response, SIEM, threat hunting, and scripting skills in cloud environments, plus demonstrated responsible use of AI.
About the job
What you'll do
- Build alerts and automation workflows to improve capabilities to detect and respond to external and internal security threats
- Manage logging pipelines and infrastructure and onboard new logging sources to improve detection coverage
- Develop and maintain internal tooling to expand and automate team detection and response capabilities
- Respond to alerts generated from our tooling and run incidents as part of an on-call rotation
- Collaborate with cross-team partners
- Hunt for previously undetected threats in our environment
- Leverage AI to streamline and enhance the efficiency, accuracy, and coverage of security engineering
What we’re looking for
- Bachelor’s degree in Computer Science, Cybersecurity or a related field or equivalent experience
- Strong knowledge of intrusion detection and incident response with an engineering focus in a modern cloud-first environment
- Knowledge of the attacker lifecycle, common attack and detection techniques
- Hands-on experience with writing SIEM queries for alerting, response, and threat hunting
- Experience consuming threat intel and applying it to improve detection capabilities
- Familiarity with using multiple sources of telemetry for threat investigations (e.g. EDR, Osquery, Firewall logs)
- Understanding of networking technologies and/or network security, basic TCP/IP network fundamentals
- Depth in ideally MacOS internals, or alternatively in Linux/UNIX or Windows internals, persistence mechanisms, privilege escalation techniques
- Scripting or automation experience (e.g. Python, Go, Ruby) for tool development or integration
- Demonstrated ability to use AI to improve speed and quality in your day-to-day workflow for relevant outputs
- Strong track record of critical evaluation and verification of AI-assisted work (e.g. testing, source-checking, data validation, peer review)
- High integrity and ownership: protect sensitive data, avoid over-reliance on AI, and remain accountable for final decisions and deliverables
Skills
SIEM, Edr, Osquery, Python, Go, Ruby, macOS, Linux, TCP/IP, Threat Intelligence, Incident Response
Similar jobs
Security Engineering jobsThe Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.