Remote job
Applied Cyber, Email Security (Detection Engineering)
Job details
About this role
Role overview Investigate the hardest email-borne threats and detection failures on an AI-native social engineering defense platform, then turn what you learn into detections, evaluations, model behaviors, and product capabilities that scale across every customer. The work sits at the intersection of security research, applied AI, and product engineering.
Responsibilities - Own detection problems end to end, from emerging attacker techniques or false negatives through investigation, hypothesis, validation, production coverage, and ongoing measurement. - Use AI as a force multiplier: build evaluations, supervise model behavior, lean on coding agents, and automate repetitive investigative work. - Partner with Product and Engineering on signals, detection logic, edge cases, and validation. - Work with customers and go-to-market teams to understand detection gaps, real-world tactics, and platform behavior. - Convert tooling, threat intelligence partnerships, and provider relationships into new signals and detection capabilities.
Requirements - Deep practitioner judgment in one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email and messaging security, with breadth across multiple areas viewed as a major plus. - Ability to take messy detection failures from "something feels off" to a clear root cause backed by data, and turn false positives and false negatives into durable fixes. - Ability to think like both attacker and defender across phishing, business email compromise, impersonation, credential theft, account takeover, and evolving social engineering tactics. - Track record of turning expert judgment into detection logic, evaluations, tests, and requirements that scale beyond a single investigation or customer. - Comfort working across security, AI, product, and customer surfaces, with the willingness to challenge assumptions and move quickly through ambiguity.
Nice to have - Hands-on secure email gateway depth, including SPF, DKIM, DMARC, mail headers, mail flow, and sender identity. - Experience with Microsoft 365/Exchange Online, Google Workspace, or email security APIs. - Detection-as-code, evaluation datasets and labeling, model benchmarks, or LLM/ML security systems. - Experience building agentic security workflows, autonomous triage, or LLM evaluation systems. - Familiarity with agentic SOC concepts, SIEM and threat intelligence tooling, and threat intelligence provider relationships.
Benefits and work setup Remote-first culture with flexible PTO, comprehensive health benefits, parental leave, meaningful equity, and a high-growth environment where work has immediate technical and customer impact. Compensation: $120,000-$180,000 OTE depending on location, experience, and demonstrated expertise.