Skip to content

Security Engineer, Detection & Response

238k – 297kNew York, NYSan Francisco, CASeattle, WAWashington, DCSecurity EngineeringOnsite5+ YOE
Summary

Senior Security Engineer focused on building detection systems, incident response automation, and maturing telemetry pipelines across cloud environments. Requires 5+ years in detection engineering or security operations and production-grade coding skills.

About the role

Responsibilities

  • Engineer, test, and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance.
  • Build and maintain incident response automation, runbooks, and tooling that reduce containment timelines without sacrificing developer velocity.
  • Mature telemetry pipelines through improved schema design, normalization, enrichment, and quality checks that reduce false positives and increase signal fidelity.
  • Perform digital incident investigations to identify and contain potential security breaches.
  • Conduct digital forensics and malware analysis to understand attack vectors and adversary methodologies.
  • Integrate alerting with messaging and ticketing systems to enable fast, traceable response workflows.
  • Partner cross-functionally with IT, security, and engineering teams to harden identity and access patterns, close logging and forensics gaps, and implement maintainable guardrails that scale with the organization.
  • Utilize threat intelligence platforms to improve hunting, detection, and response workflows.
  • Clearly explain the significance and impact of incidents, providing actionable recommendations to both technical and non-technical stakeholders.

Requirements

  • 5+ years of experience in Detection Engineering, Incident Response, or Security Operations, with a strong emphasis on building and shipping security tooling and automation.
  • Proficiency in at least one programming language (e.g., Python, Go) and comfort writing production-grade code.
  • Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments.
  • Practical experience with SIEM, EDR, and SOAR tools, with a preference for candidates who have built integrations or extended these platforms programmatically.
  • Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs.
  • Familiarity with digital forensics tools and malware analysis techniques.
  • Experience with cloud-native environments (e.g., AWS, GCP, Azure) and the security telemetry those environments generate.
  • Exposure to threat intelligence platforms and integrating intel into detection and investigation workflows.
  • Strong communication skills, with the ability to translate complex security findings into clear business impact.

Nice-to-Haves

  • Relevant security certifications (e.g., GCIH, GCFA, GCIA, CISSP, GDSA).
Skills
PythonGoSIEMEDRSOARAWSGCPAzureDigital ForensicsMalware Analysis
Similar roles at this salary range
All Security Engineering jobs →
DuckDuckGo

Privacy Engineering Director

Lead privacy engineering initiatives across private browsing, search, and agentic products. Own complex privacy projects from definition to delivery, evolve review processes, and grow privacy engineering talent.

244k – 244kUnited StatesSecurity EngineeringRemote10+ YOEPrivacy AuditsPrivacy Reviews
Instacart

Senior Product Security Engineer II

Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.

192k – 243kUnited StatesSecurity EngineeringRemote7+ YOEAI SecurityCloud Security
Crusoe

Staff Software Engineer, Security

Staff Security Software Engineer designing and building scalable security infrastructure, identity systems, and compliance automation platforms. Requires 8+ years software engineering experience with deep Kubernetes, Go/Rust, and cloud platform expertise.

215k – 260kSan Francisco, CASecurity EngineeringOn-site8+ YOEGoGCP
Scale AI

Software Engineer, Identity

Build and maintain identity infrastructure supporting authentication and authorization for enterprise AI systems. Requires 4+ years experience with IAM, ReBAC/ABAC/RBAC, and cloud platforms.

216k – 270kSan Francisco, CA +1Security EngineeringOn-site4+ YOEIAMJWT
Grow Therapy

Staff Engineer, Security

Lead security engineering as the most senior hands-on engineer, shaping multi-year roadmap and building secure-by-default infrastructure including auth, data security, and vulnerability management.

220k – 240kNew York, NY +2Security EngineeringRemote7+ YOEData SecurityAuthorization