Detection & Response Engineer
Core
Own detection and response across endpoints, identity, cloud workloads, SaaS, and AI systems, including hunting, triage, investigation, containment, and incident resolution.
Role type
Senior IC detection and response engineer (AI security focus)
Builds
Production detection software, threat models, telemetry pipelines, and response playbooks for AI agents
Domain
Cybersecurity, AI security, Cloud security
Deliverable
production ML models | product features
Required skills
Python, SQL, LLMs and agents in security, MITRE ATT&CK mapping, threat hunting, incident command, insider risk investigation, digital forensics, malware analysis, threat intelligence
Preferred skills
Modern SIEM or security data lake, SPL/KQL/YARA-L/Sigma, response automation, DLP, prompt injection defense
Technologies
Python, SQL, MITRE ATT&CK, SPL, KQL, YARA-L, Sigma
Responsibilities
Build, test, deploy, and tune production detection software using telemetry pipelines; Develop threat models and response playbooks for AI systems; Map detection coverage to MITRE ATT&CK and validate via threat hunting; Serve as incident commander and lead post-incident reviews; Investigate insider risk and identity abuse; Track threat actors targeting AI companies and own digital-risk platform takedowns
Seniority
Senior, hands-on IC