
Detection Engineer II
Posted Jul 22

Posted Jul 22
This is a fully remote position, open to applicants in California, +18 more states.
β’ Develop, refine, document, and sustain detection logic across various log sources, including endpoint, cloud, container, and SaaS products.
β’ Support cyber forensic investigations utilizing a diverse range of log sources.
β’ Enhance log ingestion pipelines and telemetry collection to ensure the delivery of high-quality, actionable security data while effectively managing volume and costs.
β’ Create and implement SOAR playbooks and automation workflows to improve detection triage, enrichment, and response processes.
β’ Provide mentorship and knowledge sharing with fellow detection engineers regarding threat hunting methodologies, detection logic creation, and investigative techniques.
β’ A minimum of 2 years of experience in detection engineering, incident response, or an offensive security role.
β’ Familiarity with one or more public cloud platforms (AWS, Azure, GCP).
β’ Comprehensive understanding of attacker TTPs in contemporary zero trust environments, including identity compromise, token theft, and trust boundary exploitation.
β’ Strong understanding of macOS internals and the telemetry available for identifying macOS-specific threats.
β’ Experience in implementing detection-as-code workflows that incorporate version control, peer review processes, automated testing, and CI/CD deployment pipelines.
β’ Basic proficiency in Python, Golang, or other programming/scripting languages.
β’ Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar.
β’ Preferred background in offensive security or red teaming.
β’ Preferred knowledge of machine learning applications for threat detection.
β’ Highly competitive market compensation.
β’ Eligibility for a new hire equity grant.
β’ Annual refresh grants.
β’ Flexible work arrangements.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.