Modal6 days ago

Инженер по обнаружению и реагированию на угрозы

Salary not specified
MARKET
13,534median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьNew York

Responsibilities

  • 01Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
  • 02Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
  • 03Improve visibility across cloud infrastructure, containers, identity systems, and production services
  • 04Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
  • 05Build playbooks and automation that reduce investigation time and improve response consistency
  • 06Drive post-incident improvements that eliminate entire classes of future incidents
  • 07Build internal tooling that improves detection, investigation, and response workflows
  • 08Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry
  • 09Improve the collection, quality, and usability of security telemetry across the platform
  • 10Partner with engineering teams to ensure new systems are observable and secure by default
  • 11Help teams instrument services with the telemetry needed for effective detection and response
  • 12Drive security improvements that make the platform easier to defend over time

Requirements

  • 01Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus
  • 02Strong software engineering skills with experience building production systems
  • 03Experience investigating security incidents in cloud-native or distributed environments
  • 04Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking
  • 05Experience building detections using logs, telemetry, behavioral signals, or large-scale event data
  • 06Strong SQL skills for investigating security events and developing detections
  • 07Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems
  • 08Strong written and verbal communication skills