Source Job

US

  • Perform investigations of security incidents using digital forensics and data analytics.
  • Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
  • Build automation and detection models to identify anomalous activity and support response efforts at scale.

Python Incident Response Digital Forensics Threat Hunting AWS

20 jobs similar to Senior Security Engineer, Threat Detection & Response

Jobs ranked by similarity.

Argentina

  • Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
  • Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
  • Develop security automation and workflows to reduce manual toil and improve response speed.

Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.

US

  • Build and scale a world-class insider threat program, including detection logic and automation.
  • Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
  • Participate in on-call rotation and proactively hunt for threats across corporate and production environments.

Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.

Unlimited PTO

  • Lead and execute complex digital forensics and incident response investigations across a range of engagement types.
  • Deliver high-quality analysis, client communication, and tailored deliverables for both technical and managerial audiences.
  • Collaborate with peers to improve methodologies, tooling, and automation to respond to emerging threats.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees and a focus on collaboration and mentorship, the company serves Fortune 500 companies and government agencies.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
  • Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
  • Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.

DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.

$125,560–$173,010/yr
Canada Unlimited PTO

  • Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
  • Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
  • Drive AI security strategy and partner with cross-functional teams to build robust detection controls.

Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.

US

  • Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
  • Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.

$70,000–$100,000/yr
US Unlimited PTO

  • Monitor SIEM, EDR/XDR, and other security platforms for threats and respond to incidents.
  • Engineer and maintain SIEM integrations, detection rules, and security automation.
  • Collaborate with IT, Engineering, and Product teams to embed security into systems.

$75,600–$97,200/yr
Ireland

  • Triage, investigate, and respond to alerts from the Huntress platform daily.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations.
  • Contribute to detection engineering and collaborate with a passionate team dedicated to protecting companies from cyber-attacks.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, providing enterprise-grade cybersecurity to businesses of all sizes. They secure over 5M endpoints and 14M identities worldwide with a 24/7 human-led SOC and a remote-first culture.

US

  • Lead and manage digital forensic and incident response engagements for clients across diverse industries.
  • Conduct advanced forensic analysis including malware analysis and reverse engineering to identify security incident scope.
  • Mentor and provide career development for a forensic team of junior consultants.

Surefire Cyber is a cybersecurity firm specializing in incident response for ransomware, email compromise, and other threats, delivering a client-centric approach designed by industry veterans. The company prioritizes efficiency, predictability, and transparency with a remote workforce and a focus on employee growth.

Mexico

  • Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
  • Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
  • Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.

Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.

$122,500–$175,000/yr
USA

  • Perform investigations into detected threats and leverage security products to analyze, contain, and remediate threats in customer environments.
  • Provide customers with thorough reports of actions taken to ensure clarity on environment cleanup and protection strategies.
  • Collaborate with Detection Engineering, Threat Hunting, Intel, and Product teams to develop innovative methods for timely threat remediation.

Zscaler accelerates digital transformation by providing cloud-based security solutions using its Zero Trust Exchange platform. The company fosters a culture of execution, collaboration, and ownership, with a focus on high-impact work.

$105,000–$115,000/yr
US Unlimited PTO

  • Lead end-to-end incident response for complex security events targeting executives and high-profile individuals.
  • Investigate compromised accounts, mobile threats, and financial fraud across Windows, macOS, iOS, Android, and Linux.
  • Mentor responders, map attacks against the kill chain, and provide white-glove client support during crises.

BlackCloak protects corporate executives and high-profile individuals in their personal lives, mitigating risks to families, companies, reputation, and finances. It is an extremely fast-growing company with a validated product and an impressive Fortune 500 client base across all industries.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

$145,000–$155,000/yr
US

  • Participate in all Incident Response activities with deep expertise in Forensic Analysis, including malware detection and reverse engineering.
  • Manage digital evidence chain of custody and perform forensic analysis across networks, hosts, and cloud environments.
  • Collaborate with security leadership to convert forensic insights into detection rules and support threat hunting operations.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies and a Best Place to Work, Valiant fosters an employee-centric culture with great benefits and career development opportunities.

Portugal 4w PTO

  • Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
  • Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
  • Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.

This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.

Canada

  • Develop processes, tooling and automation to scale incident management response and mitigate risks.
  • Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
  • Maintain security logging platform and stay updated on threats to improve detection mechanisms.

ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.

$123,850–$161,000/yr
US

  • Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • Build and maintain dashboards, visualizations, and KPIs that demonstrate SIEM effectiveness and security visibility.
  • Use frameworks such as MITRE ATT&CK to contextualize detections and identify coverage gaps.

Horizon3.ai is a fast-growing, remote cybersecurity company that provides production-safe autonomous pentests through its NodeZero platform to organizations of all sizes. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

Global

  • Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
  • Develop and automate detection capabilities and incident response processes.
  • Collaborate with engineering and product teams to improve security posture and respond to incidents.

We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.

Australia

  • Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
  • Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
  • Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.

Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.