San FranciscoFull TimeEngineering
Remotely
gopythonincident responseci/cdsplunkdetectionelasticpanther
Job Description
📋 Description
- Detection engineering: Build and tune detections across endpoint, identity, SaaS, and cloud; treat
- Telemetry and threat visibility: Define telemetry requirements for new systems and perform threat
- Response and automation: Own incident response, triage, containment, remediation, and create
- Collaboration: Work with infrastructure and product teams to close visibility gaps and ensure
- Incident detection quality: Track coverage against MITRE ATT&CK, precision, and time-to-detect
- Team/work style: Follow follow-the-sun pager rotation and engage with global security team to
🎯 Requirements
- Typically 5–8 years in detection engineering, incident response, or threat hunting with hands-on
- Proficiency in at least one programming language (Python, Go, or similar) and production-grade
- Experience with modern SIEM or detection pipelines (Panther, Elastic, Splunk, or similar) and
- Practical incident response experience leading or significant contribution to real security
🎁 Benefits
- Relocation support available for the right candidate.
- We provide modern hardware and infrastructure, including frontier AI models; a collaborative, agile
- Global team with presence in multiple continents and asynchronous collaboration through Slack/docs.
Back to all jobs