Define and drive LinkedIn's detection strategy across endpoint, identity, cloud, and SaaS environments.
Architect and operate high-signal detection capabilities using detections-as-code, telemetry modeling, and data-driven effectiveness measures.
Provide technical leadership, mentor engineers, and drive strategic investments to improve detection fidelity, scalability, and operational efficiency.
We are the world's largest professional network, built to create economic opportunity for every member of the global workforce. We're committed to providing transformational opportunities for our own employees by investing in their growth, cultivating a culture built on trust, care, inclusion, and fun.
Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.
DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.
Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.
This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.
Build and scale a world-class insider threat program, including detection logic and automation.
Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
Participate in on-call rotation and proactively hunt for threats across corporate and production environments.
Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.
Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.
Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.
Perform investigations of security incidents using digital forensics and data analytics.
Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
Build automation and detection models to identify anomalous activity and support response efforts at scale.
Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.
Log source onboarding and telemetry analysis for SIEM integration in live client environments.
Write and tune detection logic to reduce false positives and address coverage gaps.
Turn vulnerability scanner output into prioritized findings using exploitability and asset criticality.
EVOCS is an IT consulting firm helping businesses operate effectively and solve complex challenges through technology solutions. The company serves a loyal customer base with a focus on quality, consistency, and building lasting client relationships based on trust and mutual success.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS domains.
Publish and review threats for customers using concisely written communication to convey key indicators and remediation context.
Improve and innovate Detection Operations workflows through orchestration and automation to manage high volumes of telemetry.
Zscaler accelerates digital transformation to make customers more agile, efficient, resilient, and secure. They are an AI-forward enterprise using the world's largest security data lake, with a culture of execution centered on customer obsession, collaboration, and accountability.
Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
Develop security automation and workflows to reduce manual toil and improve response speed.
Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.
Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.
Second Front Systems is a public-benefit software company that accelerates secure software development and deployment for government and regulated networks. Founded by national security veterans, the company is a high-growth startup backed by top-tier venture capital with a culture of accountability and technical craft.
Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
Drive AI security strategy and partner with cross-functional teams to build robust detection controls.
Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Execute day-to-day implementation, monitoring, and optimization of cybersecurity systems and data pipelines.
Support log onboarding, normalization, and validation, as well as detection engineering and SIEM platform operations.
Assist in client engagements, security architecture reviews, and automation of response workflows.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and maintains a culture of collaboration and mentorship.
Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
Develop and automate detection capabilities and incident response processes.
Collaborate with engineering and product teams to improve security posture and respond to incidents.
We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.
Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.
Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.
Lead the design, implementation, and continuous improvement of Insider Threat and DLP programs.
Monitor and investigate DLP technologies across endpoints, network, cloud, and email systems.
Conduct root cause analysis and recommend remediation actions to prevent future risk.
Target is a leading American retailer offering value, innovation, and an exceptional guest experience. It is a large corporation with a commitment to community support and ethical business practices.
Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.
SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. Headquartered in New York City, the company has been recognized as a Best Workplace by Inc Magazine and a Best Place to Work in NYC, with a culture that values innovation and employee engagement.
Monitor, detect, and respond to security events across enterprise environments using the SIEM.
Build and maintain dashboards, visualizations, and KPIs that demonstrate SIEM effectiveness and security visibility.
Use frameworks such as MITRE ATT&CK to contextualize detections and identify coverage gaps.
Horizon3.ai is a fast-growing, remote cybersecurity company that provides production-safe autonomous pentests through its NodeZero platform to organizations of all sizes. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.