Security Engineer, Detection & Response

$238k - $297k New York, NY; San Francisco, CA; Seattle, WA; Washington, DC

Posted 1mo ago

Job Location

New York, NY; San Francisco, CA; Seattle, WA; Washington, DC

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

We are seeking a Senior Security Engineer specializing in Detection and Incident Response to join our Security Engineering team. This role blends security operations with software engineering, focusing on building systems for detection, containment, and prevention rather than just incident investigation. You will be responsible for designing and implementing high-precision detections across cloud and enterprise SaaS, developing automation to speed up response times, and enhancing telemetry pipelines. Your ability to write production-quality code is as crucial as your incident triage skills. You will analyze root causes, communicate incident significance and impact, and translate findings into engineering improvements like better detections, refined schemas, and smarter automation.

Responsibilities

  • Engineer, test, and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance.
  • Build and maintain incident response automation, runbooks, and tooling to reduce containment timelines.
  • Mature telemetry pipelines through improved schema design, normalization, enrichment, and quality checks.
  • Perform digital incident investigations to identify and contain potential security breaches.
  • Conduct digital forensics and malware analysis to understand attack vectors and adversary methodologies.
  • Integrate alerting with messaging and ticketing systems for fast, traceable response workflows.
  • Partner cross-functionally with IT, security, and engineering teams to harden identity and access patterns, close logging and forensics gaps, and implement scalable guardrails.
  • Utilize threat intelligence platforms to improve hunting, detection, and response workflows.
  • Clearly explain the significance and impact of incidents, providing actionable recommendations to technical and non-technical stakeholders.

Requirements

  • 5+ years of experience in Detection Engineering, Incident Response, or Security Operations, with a strong emphasis on building and shipping security tooling and automation.
  • Proficiency in at least one programming language (e.g., Python, Go) and comfort writing production-grade code.
  • Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments.
  • Practical experience with SIEM, EDR, and SOAR tools, with a preference for candidates who have built integrations or extended these platforms programmatically.
  • Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs.
  • Familiarity with digital forensics tools and malware analysis techniques.
  • Experience with cloud-native environments (e.g., AWS, GCP, Azure) and their security telemetry.
  • Exposure to threat intelligence platforms and integrating intel into detection and investigation workflows.
  • Strong communication skills, with the ability to translate complex security findings into clear business impact.
  • Relevant security certifications (e.g., GCIH, GCFA, GCIA, CISSP, GDSA) are a plus.

Benefits

  • Base salary
  • Equity
  • Comprehensive health, dental and vision coverage
  • Retirement benefits
  • Learning and development stipend
  • Generous PTO
  • Commuter stipend

About Scale AI

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.