Source Job

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
  • Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
  • Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.

Detection Engineering Python Cloud Security Threat Intelligence

20 jobs similar to Senior Detection Engineer

Jobs ranked by similarity.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

Portugal 4w PTO

  • Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
  • Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
  • Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.

This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.

$172,279–$249,640/yr
US Canada

  • Build and maintain SIEM for log collection and detection rules across corporate and production environments.
  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
  • Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.

Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.

Argentina

  • Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
  • Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
  • Develop security automation and workflows to reduce manual toil and improve response speed.

Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.

Global

  • Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
  • Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
  • Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.

We are the team behind Chainlink, the industry-standard oracle platform bringing capital markets onchain and powering the majority of DeFi. We have enabled tens of trillions in transaction value and secure the vast majority of DeFi, with a culture of security and innovation.

$96,798–$125,268/yr
Canada

  • Monitor security events and provide technical analysis on alerts
  • Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
  • Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.

$125,560–$173,010/yr
Canada Unlimited PTO

  • Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
  • Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
  • Drive AI security strategy and partner with cross-functional teams to build robust detection controls.

Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.

$205,000–$215,000/yr
US Unlimited PTO

  • Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
  • Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
  • Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.

Second Front Systems is a public-benefit software company that accelerates secure software development and deployment for government and regulated networks. Founded by national security veterans, the company is a high-growth startup backed by top-tier venture capital with a culture of accountability and technical craft.

Costa Rica

  • Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS domains.
  • Publish and review threats for customers using concisely written communication to convey key indicators and remediation context.
  • Improve and innovate Detection Operations workflows through orchestration and automation to manage high volumes of telemetry.

Zscaler accelerates digital transformation to make customers more agile, efficient, resilient, and secure. They are an AI-forward enterprise using the world's largest security data lake, with a culture of execution centered on customer obsession, collaboration, and accountability.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

$104,000–$178,000/yr
US

  • Develop scalable solutions for reliable marketing data ingestion and transformation.
  • Architect integrations with third-party platforms for standardized data pipelines.
  • Collaborate with product managers and engineering teams to define requirements and ensure best practices.

DV is a leader in digital performance solutions, providing unbiased third-party data and analytics to verify, optimize, and prove the effectiveness of digital advertising campaigns. The company has worked with hundreds of Fortune 500 companies since 2008, fostering a culture of innovation and collaboration.

US Unlimited PTO

  • Design, develop, and maintain secure cloud environments for distributed LogRhythm deployments.
  • Act as a technical escalation point for SIEM engineers, solving complex security and infrastructure issues.
  • Build automation and operational tooling using PowerShell, SQL, Bash, or Python.

The company specializes in cybersecurity and managed SIEM services, focusing on protecting and scaling distributed LogRhythm environments. They offer a remote work environment with a collaborative culture and opportunities for professional growth.

US

  • Design and implement data integrations with SIEM platforms such as Sentinel and Splunk.
  • Model complex data sources into performant analytics.
  • Collaborate with product engineering teams to deliver data solutions that enhance customer-facing products.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

Global

  • Deploy, configure, and maintain endpoint detection and response, email security, and network security solutions.
  • Support incident response activities, including containment, remediation, and recovery efforts.
  • Collaborate with infrastructure, applications, and governance teams to implement security best practices.

New Era Technology securely connects people, places, and information with end-to-end technology solutions at scale. With a global team of over 3,000 professionals, they foster a team-oriented culture prioritizing personal and professional development.

Global

  • Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
  • Develop and automate detection capabilities and incident response processes.
  • Collaborate with engineering and product teams to improve security posture and respond to incidents.

We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.

$128,130–$235,287/yr
US 12w maternity 12w paternity

  • Lead DLP incident response, including investigation, containment, and remediation.
  • Deploy and tune DLP controls across endpoints, network, and cloud.
  • Develop DLP policies and automated playbooks.

Included Health is a healthcare company that delivers integrated virtual care and navigation. They have a remote-first culture and offer comprehensive benefits.

$138,677–$182,296/yr
US

  • Integrate security into the SDLC through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.

$202,900–$304,300/yr
US

  • Lead a team of threat intelligence analysts, fraud researchers, and detection engineers to proactively identify and mitigate threats.
  • Set the research agenda across threat actor tracking, fraud investigations, and merchant ecosystem defense.
  • Collaborate with key partners like Risk, Trust & Safety, and Security Engineering to translate research into platform protections.

Stripe is a financial infrastructure platform for businesses that enables millions of companies to accept payments and grow revenue. With a mission to increase the GDP of the internet, Stripe fosters a culture of passion, grit, and integrity, and employs a large, global team.

$160,000–$200,000/yr
US

  • Drive planning, scoping, and delivery of complex implementations, managing customer timelines and ensuring launch readiness.
  • Lead technical discovery calls, translate ambiguous requirements into scoped stories, and build trust with stakeholders.
  • Code hands-on in Python, JavaScript, and SQL to debug integrations and build custom solutions.

Federato is an AI-native platform transforming insurance underwriting by automating workflows and optimizing portfolio decisions. Founded by industry veterans, the company is well-funded by investors behind Salesforce and Zoom, fostering a fast-paced, learning-oriented culture.

Canada Unlimited PTO

  • Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
  • Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
  • Partner with engineering teams to embed security into CI/CD pipelines and product development.

Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.