Detection and Response Engineer

New York FullTime

Posted 27d ago

Job Location

New York

Tech Stack

Remote Work Policy

On-site

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

AI needs a new infrastructure layer, and Modal is building it. We are seeking a Detection & Response Engineer to develop systems for identifying, investigating, and responding to threats across our platform. This is an engineering role focused on automation, where you will build scalable detections, investigation tooling, and response capabilities, leveraging AI to enhance signal, investigation speed, and operational effectiveness. You will collaborate closely with infrastructure, platform, and security engineers to ensure every incident contributes to platform resilience.

Responsibilities

  • Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across infrastructure and production systems.
  • Continuously improve detections based on telemetry, threat intelligence, and incident lessons learned.
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services.
  • Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems.
  • Build playbooks and automation to reduce investigation time and improve response consistency.
  • Drive post-incident improvements to eliminate entire classes of future incidents.
  • Build internal tooling to enhance detection, investigation, and response workflows.
  • Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
  • Improve the collection, quality, and usability of security telemetry across the platform.
  • Partner with engineering teams to ensure new systems are observable and secure by default.
  • Help teams instrument services with the telemetry needed for effective detection and response.
  • Drive security improvements that make the platform easier to defend over time.

Requirements

  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus.
  • Strong software engineering skills with experience building production systems.
  • Experience investigating security incidents in cloud-native or distributed environments.
  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking.
  • Experience building detections using logs, telemetry, behavioral signals, or large-scale event data.
  • Strong SQL skills for investigating security events and developing detections.
  • Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems.
  • Strong written and verbal communication skills.
  • Experience building AI- or LLM-powered security tooling (preferred).
  • Experience with SIEM, SOAR, or EDR platforms (preferred).
  • Experience with Kubernetes security or large-scale cloud infrastructure (preferred).
  • Experience with threat hunting, malware analysis, or digital forensics (preferred).
  • Experience contributing to security operations in a high-growth engineering organization (preferred).

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.