Responsibilities
- Build, tune, and deploy high-quality detections across our platform
- Develop and refine detections using telemetry from EDR, threat intel, endpoint & cloud posture platforms and native AWS cloud services
- Conduct proactive threat hunting to uncover threat actor behaviors and detection gaps
- Lead security event & incident handling, including triage, investigation, containment guidance, and post-incident improvements
- Build automation and tooling to reduce manual effort and improve detection accuracy
- Drive process improvements across detection engineering, incident response, and telemetry workflows
- Collaborate with Engineering to ensure high-quality logging and visibility across AWS environments
- Explore and prototype AI-assisted detection and response capabilities
- Contribute to internal playbooks, documentation, and detection engineering best practices
- Design and conduct table-top exercises to validate readiness and strengthen response processes
- Participate in an on-call rotation
Qualifications
- 5+ years of hands-on experience in detection engineering, threat hunting, security event analysis, and incident response
- Strong understanding of attacker behaviors, malware techniques, and modern threat landscapes
- Hands-on experience with EDR platforms (event analysis, detections, hunting)
- Proficiency with AWS security and logging services (CloudTrail, GuardDuty, IAM, VPC Flow Logs, Lambda, etc.)
- Experience designing and conducting attack & defend (table-top) exercises
- Demonstrated ability to improve processes, reduce friction, and automate repetitive tasks
- Interest in how AI/ML can enhance detection, hunting, and response workflows
- Strong communication skills and comfort working cross-functionally in a fast-paced environment
Compensation
Base wage range: $167,500 - $235,000 annually