Senior Detection and Response Engineer
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
About the job
Responsibilities
- Build and own detection coverage across cloud, endpoint, and runtime telemetry.
- Own a centralized correlation and alerting capability that turns telemetry into actionable detections.
- Lead incident response across corporate and production environments, including runbooks, escalation paths, and live incident coordination.
- Detect anomalous activity across cloud, endpoint, and Kubernetes environments.
- Tune detections to maximize signal and minimize noise.
- Measure detection and response performance, including mean time to detect and respond.
- Run incident retrospectives and apply lessons to detections and controls.
- Partner with infrastructure security and IT to close gaps identified during response.
Requirements
- 6+ years of experience in security, with a strong focus on detection engineering and incident response.
- Hands-on experience building detections and correlation across AWS, Azure, endpoint detection and response, and preferably container and runtime telemetry.
- Experience owning incident response end to end, including leading live incidents.
- Ability to build and scale a detection and response capability.
- Sound judgment under pressure and clear incident communication.
- Ability to work effectively with engineering and IT teams.
Nice-to-haves
- Experience with SIEM or detection platforms and detection-as-code approaches.
- Familiarity with runtime security tools such as Upwind or similar platforms.
- Threat hunting or purple-team experience.
- Background in AI or ML platforms or distributed systems.
Skills
AWS, Azure, Endpoint Detection And Response, Kubernetes, Container Security, Runtime Security, SIEM, Detection-As-Code, Threat Hunting, Purple Teaming
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.