Remote job
Detection & Response Lead
Job details
About this role
Role overview
A lead-level engineering position is open to build and operate a Detection and Response function across a large-scale cloud platform serving AI and compute workloads. The role blends hands-on detection engineering, threat intelligence, and incident response leadership, with responsibility for shaping strategy and guiding a small team of analysts and engineers as the environment continues to scale.
Responsibilities
- Lead detection engineering efforts, tuning rules to keep false-positive and false-negative rates low while partnering with more than twenty internal teams that consume alerts. - Architect and maintain detection coverage across cloud and bare-metal environments, including container and Kubernetes-based workloads. - Build and extend internal tooling and pipelines: onboard new log sources, automate response runbooks, and integrate SOAR workflows. - Incorporate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to cloud infrastructure. - Drive end-to-end incident response, including scoping, containment, root cause analysis, post-incident reviews, and ensuring remediation items are closed. - Define and report on operational metrics such as MTTD, MTTR, detection coverage, and false-positive rates.
Requirements
- At least six years in security operations, detection engineering, or incident response, with one to two years leading or mentoring a team. - Deep hands-on experience with cloud-native environments, including Kubernetes, Linux workloads, and container-based infrastructure. - Strong skills writing and tuning detections in SIEM platforms (such as Chronicle, Splunk, or Elastic) and in SQL. - Experience building or operating SOAR workflows and automating response at scale, ideally with Golang and Temporal. - Working knowledge of threat intelligence frameworks such as MITRE ATT&CK, the Pyramid of Pain, and the Kill Chain. - Solid incident response fundamentals including memory forensics, log analysis, network traffic analysis, and post-incident reporting.
Nice to have
- Experience with threats related to AI/ML and GPU clusters. - Familiarity with eBPF-based detection or runtime security tooling such as Falco or Tetragon. - Background in threat hunting.
Benefits and work setup
- Remote-first, flexible working culture with opportunities to influence the long-term direction of a security platform. - Competitive compensation with equity potential, career growth support, and an international team environment.