Start Date
Immediate
Expiry Date
22 Nov, 26
Salary
0.0
Posted On
24 Aug, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive
Engineer High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products' audit events
Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place
Lead Incident Response: Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things
Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn't — including PHI — across applications, endpoints, and SaaS
Manage 24/7 Coverage: Define requirements for and direct our managed detection partners, own escalation procedures, and continuously raise the bar on what "monitored" means
Represents the skills you have
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company
Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content — not just operating one that was handed to you
Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality
Real incident response experience — you've led investigations, written the playbooks, and run the retros
Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs)
Strong programming or automation skills (Python preferred); comfort building integrations and response automation
A builder mentality — you'd rather engineer the alert away than triage it forever
Experience partnering directly with software engineers to instrument applications for security visibility is a strong plus
Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus
Experience working with MDR/MSSP providers — and opinions about what they're good and bad at
Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus, but practical engineering experience matters more
Choice of medical, dental, and vision insurance plans for you and your family.
Additional insurance coverage options for life, accident, or critical illness.
Flexible paid time off, sick leave, short-term and long-term disability.
10 US observed holidays, and Canadian statutory holidays by province.
A home office stipend.
401(k) for US-based employees and RRSP for Canada-based employees.
Paid parental leave.
A local in-person meet-up program.
Hubs in San Francisco and Toronto.