Software Detection Engineer - Cloud, Identity Protection (Hybrid, ISR)
Core
Build globally distributed, fault-tolerant, and highly scalable identity threat detection systems analyzing billions of authentication events daily to detect Active Directory attacks, credential theft, and lateral movement.
Role type
Senior IC backend/distributed systems engineer (identity protection)
Builds
Cloud-native, event-streaming microservices for identity threat detection
Domain
Cybersecurity, Identity Protection, Cloud Infrastructure
Deliverable
production ML models | product features
Required skills
Python mastery, distributed systems design, event-streaming architectures, Kafka, relational/document databases, caching
Preferred skills
Go, security/detection background, ML for anomaly detection, applied LLM/GenAI
Technologies
Python, Go, Java, Kafka, PostgreSQL, MongoDB, Redis, Protobuf, gRPC, GraphQL, AWS, LogScale, NG-SIEM, LLM, GenAI
Responsibilities
Design real-time detection rules and pipelines over high-throughput Kafka streams, build pluggable detection engines, develop ML and behavioral-anomaly models, translate security research into production detections, own production observability and incident response, work across polyglot stack
Seniority
Senior, hands-on IC