Remote job
Senior Security Engineer - Threat Detection
Job details
About this role
Role overview
A senior engineering role focused on building and operating the threat detection platform that protects the organization and its customers. The work combines hands-on detection authoring with platform engineering: shaping the data pipelines, CI/CD, and tooling that let a small team cover a large attack surface. The position partners closely with Security Operations, Application Security, Enterprise Security, and product engineering teams across the company.
Responsibilities
- Design, deploy, and continuously refine detections mapped to MITRE ATT&CK across cloud, endpoint, identity, email, and application telemetry, with explicit false-positive thresholds. - Own the full detection lifecycle, from hypothesis and data validation through baselining, deployment, tuning, validation, and retirement. - Advance the detection-as-code platform through version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability. - Identify emerging threat surfaces and build integrations that strengthen data ingestion, enrichment, and coverage across internal and third-party systems. - Evaluate AI-assisted security capabilities such as secure MCP integrations, threat hunting, anomaly detection, and response automation, including where such tools introduce risk. - Turn threat intelligence into actionable detection content and retrospective scans, and partner with Security Operations during investigations, incidents, tabletop exercises, detection maintenance, and code pairing.
Requirements
- 6+ years of experience in security engineering, detection engineering, or a closely related discipline. - Hands-on track record writing production detections across cloud, endpoint, identity, or email telemetry. - Strong software engineering fundamentals, including detection-as-code, CI/CD, automated testing, and infrastructure-as-code practices. - Working knowledge of MITRE ATT&CK and adversary tactics, techniques, and procedures across major attack surfaces. - Practical experience evaluating or deploying AI-powered security tooling, with a clear-eyed view of its limits. - Comfort taking projects independently from idea to proof-of-concept to production.
Benefits and work setup
- Professional development stipend, comprehensive health coverage, and parental leave plans. - Flexible working model that supports in-person, hybrid, and remote arrangements depending on team and role requirements. - Open to candidates residing in the United States, excluding the San Francisco Bay, New York City, and Washington, D.C. metro areas.