
Applied Cyber, Email Security – Detection Engineering
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Take full ownership of detection challenges from identifying emerging TTPs or false negatives to investigation, detection hypothesis development, validation, production coverage, and performance measurement.
• Create evaluations, oversee model performance, utilize coding agents, and automate repetitive investigative tasks.
• Collaborate with Product and Engineering teams on signals, detection logic, edge cases, and validation processes.
• Engage with customers and go-to-market teams to address detection gaps, real-world TTPs, and platform behavior insights.
• Transform tooling, threat-intelligence partnerships, and provider relationships into new signals and enhanced detection capabilities.
• Influence product functionalities in partnership with Product, Engineering, AI/ML teams, customers, and ecosystem collaborators.
• Extensive experience in detection engineering, SOC/IR, threat intelligence/OSINT, or email/messaging security.
• Proficient in investigating detection failures, identifying root causes in data, and converting false positive/negative cases into sustainable solutions.
• Capable of thinking from both attacker and defender perspectives regarding phishing, BEC, impersonation, credential theft, account takeover, and evolving social-engineering TTPs.
• Skilled in translating expert judgment into detection logic, evaluations, tests, requirements, and scalable systems.
• Ability to work at the convergence of security, AI, product development, and customer relations.
• In-depth knowledge of SEG/email security including SPF, DKIM, DMARC, email headers, mail flow, and sender identity.
• Experience with M365/Exchange Online, Google Workspace, or email-security APIs.
• Familiarity with detection-as-code, evaluation datasets/labeling, model benchmarks, or LLM/ML security systems.
• Background in developing agentic security workflows, autonomous triage processes, or LLM evaluation systems.
• Experience working with Agentic SOC, SIEM/TI tools, and threat-intelligence provider/vendor partnerships.
• Significant equity to share in Doppel's success.
• Remote-first work culture.
• Flexible paid time off.
• Comprehensive health benefits.
• Parental leave.
• High-growth environment with immediate technical and customer impact.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.