Source Job

$120,000–$160,000/yr
US

  • Research adversary tradecraft, translate threat intelligence into detection logic
  • Tune and optimize existing detections to reduce alert fatigue while maintaining detection fidelity
  • Document detection logic, response guidance, and follow-on analysis to support SOC and incident responders

Python SQL KQL

15 jobs similar to Detection Engineer

Jobs ranked by similarity.

$150,000–$180,000/yr
US Unlimited PTO

  • Develop network threat detectors by leveraging rule-based and ML-based detection strategies.
  • Reproduce attacks in a lab environment using live tools and recorded PCAP traffic, and perform threat hunts on aggregated log data, in order to identify malicious behaviors and develop techniques to detect them.
  • Collaborate with Threat Research and Data Science teams to gain insight on attacker techniques and take advantage of the latest machine learning models to detect attacker behavior.

ExtraHop reinvents Network Detection and Response (NDR) to help enterprises and organizations stay ahead of emerging threats with unmatched network visibility, context, and control. They are recognized for innovation and a commitment to building a world-class team.

$118,400–$171,700/yr
US Unlimited PTO 24w maternity

  • Continuously improve alert quality, workflow efficiency, and detection capabilities through advanced analytics, machine learning, and Gen AI.
  • Ensure Expel can easily deploy, monitor, and manage all of our machine learning capabilities.
  • Translate data insights into clear, actionable knowledge for the organization.

Expel helps companies improve their cybersecurity. They offer a small, transparent, and collaborative startup environment with a team-focused mindset.

ANZ

  • Play a pivotal role in shaping the architecture, strategic direction and maturity of Canva’s Detection and Response capabilities.
  • Deliver innovative and scalable security solutions yourself as an individual, and also as a mentor of other security builders.
  • Evangelise and lead the adoption and integration of GenAI Workflows to raise the efficiency and scalability of the Detection and Response team’s operations.

Canva is a design platform redefining how the world experiences design. They have campuses in Sydney and Melbourne, and co-working spaces in Brisbane, Perth and Adelaide, with a flexible and fun culture that incorporates empathy, humility, and generosity.

$69,678–$84,350/yr
Global

  • Act as a senior escalation point for SOC investigations, providing guidance aligned to Copperleaf’s security architecture and operational practices.
  • Lead investigations into security alerts across Copperleaf’s Azure‑hosted environments, identity systems, corporate endpoints, and product infrastructure.
  • Track emerging threats relevant to SaaS providers, cloud platforms, Kubernetes, identity infrastructure, and AI‑driven attack techniques.

IFS is a billion-dollar revenue company with 7000+ employees across all continents specialized at AI technology. They enable customers to be their best when it really matters–at the Moment of Service™ and are committed to promoting an inclusive workforce that fully represents diverse cultures, backgrounds, and viewpoints.

$75,375–$125,625/yr
US

  • Research trends and techniques related to unauthorised access and proactively share findings.
  • Aggregate, organize, and analyze data to uncover patterns and vulnerabilities in unauthorized submissions.
  • Create and maintain documentation and reports covering methods, tools, and vulnerabilities.

Turnitin partners with educators and institutions to develop learning integrity solutions. They are a global organization with team members in over 35 countries committed to ensuring the integrity of global education while meaningfully improving learning outcomes.

$180,000–$230,000/yr
US 12w maternity 12w paternity

  • Manage and optimize security tools such as email security, DLP, SIEM, IDS/IPS, EDR, threat intelligence platforms, and other tooling
  • Design and implement AI-enabled workflows to scale enterprise security and threat operations
  • Monitor and manage security alerts and incidents, analyze data, and respond to security events

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.

US

  • Manage event and information intake, including intelligence reports and monitoring ticket queues.
  • Triage alerts and correlate and analyze events to determine the scope of cybersecurity incidents.
  • Provide 24x7 on-call support and monitor and manage security incidents using SIEM, SOAR, and DLP tools.

Brightspeed provides fast, reliable internet connections and an awesome customer experience in twenty states throughout the Midwest and South. Backed by funds managed by Apollo Global Management, they are accelerating the upgrade of copper to fiber optic technologies.

Global

  • Lead and execute security incident response, leveraging your deep expertise to manage and mitigate threats across Ivanti’s global footprint.
  • Uncover both known and unknown threats using advanced incident response techniques, threat hunting, threat intelligence, and a strong understanding of attacker TTPs.
  • Conduct thorough investigations involving external attacks, insider threats, and digital forensics, ensuring stakeholders stay informed with comprehensive reporting.

Ivanti's mission is to elevate human potential within organizations by managing, protecting and automating technology for continuous innovation. It is through diverse and inclusive hiring, decision-making, and commitment to our employees and partners that they will continue to build and deliver world-class solutions for their customers.

$100,000–$130,000/yr
US

  • Monitor client environments performing Incident Detection, Validation, and Reporting.
  • Responsible for the implementation and maintenance of cloud-based SIEM Solutions.
  • Partner with client Security to continuously improve and enhance Managed Security support.

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, they help enterprises deliver on the promise of digital transformation. They prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard.

Mexico

  • Focused on Python-driven automation, building systems integrations between HRIS, Identity Provider, SaaS, and Finance Platform.
  • Transforming operational data into actionable insights and dashboards.
  • You’ll own high-impact projects end-to-end, mentor teammates, and raise the bar on reliability, security, and employee experience.

EarnIn is building products that deliver real-time financial flexibility for those with the unique needs of living paycheck to paycheck. They are growing fast and are excited to continue bringing world-class talent onboard to help shape the next chapter of their growth journey.

$110,000–$160,000/yr
US

  • Overseeing and resolving technical support requests and cybersecurity issues efficiently.
  • Conducting training sessions for new customer team members and providing deep dives into new platform features.
  • Handling the setup and configuration of new features and specialized functionality for existing clients.

MixMode provides AI-powered cybersecurity solutions, pioneering a patented third-wave, context-aware AI approach. They cater to large organizations with big data workloads, including those in enterprise, critical infrastructure, the US Department of War, and the US Intelligence Community.

US 4w PTO

  • Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
  • Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
  • Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues

Aledade, a public benefit corporation, empowers independent primary care practices. Founded in 2014, they've become the largest network of independent primary care in the country with a collaborative, inclusive and remote-first culture.

US

  • Understand the abuse risks faced by customers.
  • Design and deploy the anti-abuse controls for features.
  • Research, plan, and build anti-abuse architectures for products and features

Redapt Inc. is a pioneering world-class data center infrastructure integrator, technology engineering firm, and cloud services provider. They focus on delivering innovative solutions and services that power their customers' most demanding applications and enable them to extract powerful insights from data that drive true business value.

Europe

  • Detection, analysis and management of security incidents
  • Making and evaluating reports
  • Monitoring the customer’s environment

Deutsche Telekom IT Solutions, a subsidiary of the Deutsche Telekom Group, is Hungary’s most attractive employer in 2025, providing a wide portfolio of IT and telecommunications services. With more than 5300 employees, they continuously develop its four sites and is looking for skilled IT professionals to join its team.

Europe Unlimited PTO

  • Design and build scalable backend systems, APIs, and data pipelines
  • Own services end-to-end, including architecture, development, deployment, and operation
  • Lead technical design discussions and contribute to system architecture decisions

VulnCheck is transforming vulnerability intelligence by helping security teams act faster and with more confidence. They were founded in 2021 and strive to have a transparent, collaborative, and supportive culture- with smart, humble, hardworking, and supportive teammates.