Security Software Engineer II, Detection and Response
Core
Build and implement detection and response improvements to protect employees and infrastructure from emerging security threats.
Role type
Security Software Engineer (Detection and Response)
Builds
Alerts, automation workflows, logging pipelines, and internal tooling for threat detection and response.
Domain
Cybersecurity, Cloud Security, Threat Intelligence
Deliverable
production ML models | infrastructure
Required skills
Intrusion detection and incident response, SIEM query writing, Threat intelligence analysis, Telemetry source utilization (EDR, Osquery, Firewall logs), Networking fundamentals (TCP/IP), OS internals (MacOS/Linux/Windows), Scripting/automation (Python, Go, Ruby), AI integration and verification
Preferred skills
AI-assisted workflow optimization, Critical evaluation of AI outputs
Technologies
Python, Go, Ruby, SIEM, EDR, Osquery, TCP/IP
Responsibilities
Build alerts and automation workflows for threat detection and response, Manage logging pipelines and onboard new sources, Develop internal tooling for detection and response, Respond to alerts and run incidents, Hunt for previously undetected threats, Leverage AI to enhance security engineering efficiency
Seniority
Mid-Senior, hands-on IC