Skip to content
AnyscaleAnyscale

Senior Detection and Response Engineer

Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.

About the job

Responsibilities

  • Build and own detection coverage across cloud, endpoint, and runtime telemetry.
  • Own a centralized correlation and alerting capability that turns telemetry into actionable detections.
  • Lead incident response across corporate and production environments, including runbooks, escalation paths, and live incident coordination.
  • Detect anomalous activity across cloud, endpoint, and Kubernetes environments.
  • Tune detections to maximize signal and minimize noise.
  • Measure detection and response performance, including mean time to detect and respond.
  • Run incident retrospectives and apply lessons to detections and controls.
  • Partner with infrastructure security and IT to close gaps identified during response.

Requirements

  • 6+ years of experience in security, with a strong focus on detection engineering and incident response.
  • Hands-on experience building detections and correlation across AWS, Azure, endpoint detection and response, and preferably container and runtime telemetry.
  • Experience owning incident response end to end, including leading live incidents.
  • Ability to build and scale a detection and response capability.
  • Sound judgment under pressure and clear incident communication.
  • Ability to work effectively with engineering and IT teams.

Nice-to-haves

  • Experience with SIEM or detection platforms and detection-as-code approaches.
  • Familiarity with runtime security tools such as Upwind or similar platforms.
  • Threat hunting or purple-team experience.
  • Background in AI or ML platforms or distributed systems.

Skills

AWS, Azure, Endpoint Detection And Response, Kubernetes, Container Security, Runtime Security, SIEM, Detection-As-Code, Threat Hunting, Purple Teaming

Snowflake

Snowflake

Menlo Park, CA
Senior Software Engineer - Cloud Security
$200k+/yrHybrid5+ YOESecurity Engineering

Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.

Atomicmachines

Atomicmachines

Emeryville, CA
Senior Manager - Network and Information Security
$200k+/yrOn-site10+ YOESecurity Engineering

Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.

Anyscale

Anyscale

San Francisco, CA

Senior Cloud Security Engineer
$200k+/yrHybrid8+ YOESecurity Engineering

Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.

Instacart

Instacart

United States
Senior Detection Engineer II
$192k+/yrRemote6+ YOESecurity Engineering

Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.