Skip to content
OpenAIOpenAI

Security Engineer, Detection and Response - EMEA

Build and operate detection and response systems protecting sensitive infrastructure, products, research environments, and data. The role requires hands-on threat detection or incident response experience, Kubernetes and cloud expertise, threat modeling, automation, and strong cross-functional collaboration.

About the job

Responsibilities

  • Build and evolve Detection & Response capabilities across infrastructure, products, and research environments, emphasizing high-signal detection and reliable operational response.
  • Engineer detection pipelines and tooling, including rule lifecycle management, measurement and quality loops, tuning processes, and safe rollout patterns.
  • Automate response and investigations through workflows for triage, enrichment, containment, and evidence capture.
  • Partner with Security teams and infrastructure owners to define telemetry, threat models, and response playbooks for new systems.
  • Define Detection & Response requirements and drive visibility across endpoints, identity, SaaS, cloud, Kubernetes, and related infrastructure.
  • Identify telemetry and control gaps, prioritize improvements, and implement fixes where appropriate.
  • Evaluate and respond to emerging security concerns in a frontier AI lab environment, including agents operating across infrastructure at scale.

Requirements and Qualifications

  • Hands-on threat detection and/or incident response experience, including building detections, conducting investigations, and improving operational playbooks.
  • Understanding of modern adversary tradecraft and the ability to translate it into practical detection strategies and response actions.
  • Threat modeling experience, including evaluating infrastructure and features, identifying Detection & Response implications, and defining concrete requirements.
  • Experience with Kubernetes and containerized environments, including building detections from cluster telemetry and understanding workload, node, control-plane, and networking risks.
  • Knowledge of lower-level infrastructure and datacenter risks, including firmware/BMC surfaces, network segmentation and telemetry, and difficult-to-observe control paths.
  • Experience with major cloud platforms, including Azure, AWS, Google Cloud, and Oracle Cloud Infrastructure, with the ability to design cloud-agnostic detection approaches.
  • Scripting experience and interest in using AI or agent tooling to accelerate investigations and automation.
  • Strong communication and collaboration skills across technical and non-technical teams.
  • Ability to translate Detection & Response needs into clear requirements, align stakeholders, and drive follow-through.

Nice-to-Haves

  • Experience designing detection and response strategies for agents operating across systems at scale.
  • Experience building measurable, auditable, and safe agent-style workflows that reduce operational toil.

Skills

Threat Detection, Incident Response, Threat Modeling, Kubernetes, AWS, Microsoft Azure, GCP, Oracle Cloud Infrastructure, Scripting, Cloud Security, Network Segmentation, Security Automation, Telemetry, Detection Engineering, Adversary Tradecraft

Writer

Writer

London, United Kingdom

Security Engineer, Application Security
No salary listedHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.

Stripe

Stripe

Dublin, Ireland

Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.

Stripe

Stripe

Seattle, WA
Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Kodex

Kodex

Sydney, Australia

Threat Intelligence Specialist – EMEA
No salary listedRemote3+ YOESecurity Engineering

The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.