(Senior OR Staff) Detection & Response Engineer
Core
Own detection and response across endpoints, identity, cloud workloads, SaaS, and AI systems for a legal-tech company, hunting threats and building automated security controls.
Role type
Senior/Staff Detection & Response Engineer (Security)
Builds
Production detection software, telemetry pipelines, threat models, and automated response agents for AI systems.
Domain
Information Security / AI Security / Legal Technology
Deliverable
production ML models | product features
Required skills
detection engineering, incident response, Python, SQL, LLMs and agents, endpoint/identity/cloud/SaaS telemetry analysis, threat hunting, adversary emulation, MITRE ATT&CK mapping, incident command, insider risk investigation.
Preferred skills
modern SIEM/security data lake experience, query languages (SPL, KQL, YARA-L, Sigma), AI system security (prompt injection/exfiltration), response automation, digital forensics, malware analysis, threat intelligence, DLP.
Technologies
Python, SQL, LLMs, agents, MITRE ATT&CK, SPL, KQL, YARA-L, Sigma
Responsibilities
Hunt, triage, investigate, and contain security incidents across all environments; build and maintain detection software via CI/CD; develop threat models and playbooks for AI agents; supervise triage and investigation agents; map coverage to MITRE ATT&CK and validate via emulation; act as incident commander and run post-incident reviews; investigate insider risk and identity abuse; track AI-targeting campaigns and manage digital-risk platform.
Seniority
Senior (5+ years) / Staff (10+ years, strategy setting)