Detection And Response Engineer
Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.
About the job
Responsibilities
Detection Engineering
- Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across infrastructure and production systems.
- Improve detections using telemetry, threat intelligence, and incident lessons learned.
- Improve visibility across cloud infrastructure, containers, identity systems, and production services.
Incident Response
- Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems.
- Build playbooks and automation to reduce investigation time and improve response consistency.
- Drive post-incident improvements that eliminate entire classes of future incidents.
Security Tooling and Automation
- Build internal tooling to improve detection, investigation, and response workflows.
- Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
- Improve the collection, quality, and usability of security telemetry across the platform.
Engineering Partnership
- Partner with engineering teams to ensure new systems are observable and secure by default.
- Help teams instrument services with telemetry needed for effective detection and response.
- Drive security improvements that make the platform easier to defend over time.
Requirements
- Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus.
- Strong software engineering skills and experience building production systems.
- Experience investigating security incidents in cloud-native or distributed environments.
- Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking.
- Experience building detections using logs, telemetry, behavioral signals, or large-scale event data.
- Strong SQL skills for investigating security events and developing detections.
- Interest in applying AI and LLMs to detection, investigation, and response, including emerging threats involving AI-powered systems.
- Strong written and verbal communication skills.
Nice-to-Haves
- Experience building AI- or LLM-powered security tooling.
- Experience with SIEM, SOAR, or EDR platforms.
- Experience with Kubernetes security or large-scale cloud infrastructure.
- Experience with threat hunting, malware analysis, or digital forensics.
- Experience contributing to security operations in a high-growth engineering organization.
Skills
Cloud Infrastructure, Kubernetes, Linux, Networking, SQL, LLMs, SIEM, Soar, Edr, Threat Hunting, Malware Analysis, Digital Forensics, Incident Response, Security Telemetry
Similar jobs
Security Engineering jobsManages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.