Skip to content

Security Engineer, Detection and Response

230k – 260kSan Francisco, CANew York, NYHybrid6+ YOE
Summary

Build and operate detection systems for cloud, identity, endpoints, and SaaS. Design high-signal detections, improve detection platforms, and participate in incident response.

About the role

What You'll Achieve

  • Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  • Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, and postmortems that drive long-term security improvements.
  • Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
  • Participate in a shared on-call rotation for incident response.

Skills You'll Need to Bring

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Built and operated production detections with strong signal quality and sustainable tuning processes.
  • Fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
  • Offensive security mindset with experience leading purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
  • Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
  • Hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.

Nice to Have

  • Experience applying LLMs or agent-style tooling to security workflows.
  • Experience securing AI-enabled systems or endpoint tooling.
  • Kubernetes or container detection experience.
  • Background in threat intelligence, malware analysis, or digital forensics.
  • Contributions to the detection engineering community through research, tooling, or talks.
  • Experience at a high-growth startup or AI company.
Skills
SigmaKQLSPLYARA-LEQLPantherSIEMEDRSOARAWSGCPAzurethreat huntingincident responsepurple teaming
Similar roles at this salary range
All Security Engineering jobs →
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Brex

Senior Application Security Engineer

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

192k – 240kUnited StatesSecurity EngineeringRemote5+ YOEAWSgRPC
Rula

Staff Software Engineer - Trust & Safety

Staff-level engineer to found and lead a new Trust & Safety engineering team, architecting systems to detect fraud, billing anomalies, and credential abuse for a mental healthcare platform.

207k – 243kLos Angeles, CASecurity EngineeringRemote8+ YOESQLAWS
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby
Betterment

Sr. Engineering Manager, Application Security

Senior Engineering Manager leading Application Security squad to build secure software by default through threat modeling, design reviews, vulnerability management, and developer tooling. Requires hands-on team leadership and expertise across the AppSec stack.

210k – 250kNew York, NYSecurity EngineeringHybrid7+ YOEAWSCI/CD