# Security Engineer, Detection and Response - EMEA

**Company:** [OpenAI](https://hotfix.jobs/companies/openai)
**Location:** London, United Kingdom, Zurich, Switzerland, Dublin, Ireland
**Role:** Security Engineering
**Skills:** Threat Detection, Incident Response, Threat Modeling, Kubernetes, AWS, Microsoft Azure, GCP, Oracle Cloud Infrastructure, Scripting, Cloud Security, Network Segmentation, Security Automation, Telemetry, Detection Engineering, Adversary Tradecraft
**Posted:** 2025-05-08

> Build and operate detection and response systems protecting sensitive infrastructure, products, research environments, and data. The role requires hands-on threat detection or incident response experience, Kubernetes and cloud expertise, threat modeling, automation, and strong cross-functional collaboration.

## Job Description

## Responsibilities
- Build and evolve Detection & Response capabilities across infrastructure, products, and research environments, emphasizing high-signal detection and reliable operational response.
- Engineer detection pipelines and tooling, including rule lifecycle management, measurement and quality loops, tuning processes, and safe rollout patterns.
- Automate response and investigations through workflows for triage, enrichment, containment, and evidence capture.
- Partner with Security teams and infrastructure owners to define telemetry, threat models, and response playbooks for new systems.
- Define Detection & Response requirements and drive visibility across endpoints, identity, SaaS, cloud, Kubernetes, and related infrastructure.
- Identify telemetry and control gaps, prioritize improvements, and implement fixes where appropriate.
- Evaluate and respond to emerging security concerns in a frontier AI lab environment, including agents operating across infrastructure at scale.

## Requirements and Qualifications
- Hands-on threat detection and/or incident response experience, including building detections, conducting investigations, and improving operational playbooks.
- Understanding of modern adversary tradecraft and the ability to translate it into practical detection strategies and response actions.
- Threat modeling experience, including evaluating infrastructure and features, identifying Detection & Response implications, and defining concrete requirements.
- Experience with Kubernetes and containerized environments, including building detections from cluster telemetry and understanding workload, node, control-plane, and networking risks.
- Knowledge of lower-level infrastructure and datacenter risks, including firmware/BMC surfaces, network segmentation and telemetry, and difficult-to-observe control paths.
- Experience with major cloud platforms, including Azure, AWS, Google Cloud, and Oracle Cloud Infrastructure, with the ability to design cloud-agnostic detection approaches.
- Scripting experience and interest in using AI or agent tooling to accelerate investigations and automation.
- Strong communication and collaboration skills across technical and non-technical teams.
- Ability to translate Detection & Response needs into clear requirements, align stakeholders, and drive follow-through.

## Nice-to-Haves
- Experience designing detection and response strategies for agents operating across systems at scale.
- Experience building measurable, auditable, and safe agent-style workflows that reduce operational toil.

## Similar jobs

- [Security Engineer, Application Security](https://hotfix.jobs/jobs/8c8a3f77-9f1b-45b4-b825-819dd30e2fb0) - Writer - London, United Kingdom
- [Abuse Investigator](https://hotfix.jobs/jobs/067a3725-8094-47e5-a3a6-ac821e7253c6) - Stripe - Dublin, Ireland
- [Abuse Investigator](https://hotfix.jobs/jobs/ba670c7e-d48c-495b-8f3e-648393a93ed7) - Stripe - Seattle, WA
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Threat Intelligence Specialist – EMEA](https://hotfix.jobs/jobs/ba41592f-9f18-4e57-a7c7-144744386565) - Kodex - Remote

**Apply:** https://hotfix.jobs/jobs/edbf49aa-0294-4c96-a3f2-8dd314c8ae2a
**Canonical:** https://hotfix.jobs/jobs/edbf49aa-0294-4c96-a3f2-8dd314c8ae2a