Staff / Principal Software Engineer, Detection and Response
Leads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.
About the job
Requirements
- 8+ years in detection engineering, incident response, or threat hunting, including at least 3 years at staff/principal level.
- Strong engineering background with detections-as-code rather than saved SIEM searches.
- Deep experience with cloud telemetry (GCP, AWS, Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks including Panther, Elastic, Snowflake, and ClickHouse.
- Experience leading high-severity incidents from first alert through public post-mortem.
- Familiarity with MITRE ATT&CK, threat intelligence, purple teaming, and red-team collaboration.
Responsibilities
- Build the detection engineering platform, including pipelines, detections-as-code, automated triage, and response playbooks.
- Design and own a security incident response process with 24/7 coverage using a small, high-leverage human and agent team.
- Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
- Proactively hunt across corporate, production, and AI-agent surfaces, turning findings into durable detections.
- Define and build world-class detection and response capabilities for an AI-native company.
Nice to Have
- Experience detecting LLM or agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering organizations.
Technology Stack
- Frontend: React, TypeScript
- Backend: Golang, Rust
- Cloud: Cloudflare, GCP, AWS, and multiple LLM providers
- DevOps and tooling: GitHub Actions, Grafana, OpenTelemetry (OTEL), Terraform
- Data: ClickHouse, Firestore, Spanner, BigQuery
Skills
GCP, AWS, Cloudflare, Endpoint Edr, Panther, Elastic, Snowflake, ClickHouse, Mitre Att&Ck, Threat Intelligence, Purple Teaming, Terraform, Grafana, React, TypeScript
Similar jobs
Security Engineering jobsLeads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.