San FranciscoFull TimeEngineering
Remotely
gopythonsiemci/cdsplunkmitre att&ckelasticpanther
Job Description
📋 Description
- Build and tune detections across endpoint, identity, SaaS, and cloud, treating them as software
- Track detection quality as measured quantities: coverage against MITRE ATT&CK, precision
- Own incident response: triage, contain, remediate, and write the retrospective that turns the
- Build automation that removes toil from investigations, and partner closely with the US-based team
- Define telemetry requirements for new systems before they ship, working with infrastructure and
- Threat hunt proactively across the estate, converting hypotheses into either new detections or
🎯 Requirements
- Typically 5–8 years of experience in detection engineering, incident response, or threat hunting
- Proficiency in at least one programming language (Python, Go, or similar) and comfort writing
- Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar).
- Practical incident response experience: you've led or played a major role in triaging and closing
🎁 Benefits
- Base salary is just one part of our total rewards package at Flexport, which also includes bonus
- We have the latest hardware and software, including frontier AI models on day one.
- Relocation support is available for the right candidate.
Back to all jobs