Responsibilities
- Design, build, and improve threat detections across infrastructure, products, tools, and environments
- Lead security incident response: investigation, containment, remediation, and post-incident learning
- Apply threat intelligence and attacker TTPs to detection, threat hunting, triage, and prioritization
- Collaborate with Security, Infrastructure, and IT on visibility, logging, and readiness
- Use automation, scripting, and Detection-as-Code to scale workflows
- Own end-to-end security projects
- Participate in on-call rotation for high-severity incidents
- Contribute to playbooks, mentoring, exercises, audits, and initiatives
Requirements
- 5+ years in security engineering, with 3+ years in security operations, detection engineering, or incident response
- Hands-on with SIEMs, SOAR, behavior analytics, Detection-as-Code
- Understanding of attacker techniques in cloud-native, SaaS, identity environments
- Experience with endpoint, runtime, forensic tools across OSes
- Knowledge of AWS, GCP, cloud security best practices
- Proficiency in Python, Bash, Terraform, CI/CD
- Strong communication skills
Compensation
USA: $156,000 - $210,000 USD
Canada: $143,000 - $193,000 CAD
Plus benefits, PTO, equity, incentives.