
Detection & Response Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
β’ Take ownership of the end-to-end detection and response process, encompassing logging, alerting, triage, and recovery.
β’ Develop and refine detections as code across various cloud environments, Kubernetes, identity systems, endpoints, and SaaS applications.
β’ Evaluate detections based on coverage and precision instead of alert volume.
β’ Lead the incident response process from the initial alert to containment and forensics.
β’ Compose post-incident reviews.
β’ Create automation for triage enrichment, correlation, containment actions, and evidence collection.
β’ Utilize LLM-based tools where they can withstand auditing.
β’ Monitor AI agents and developer tools while developing telemetry and controls.
β’ Collaborate with platform and research engineers to establish logging and response playbooks in new systems.
β’ Conduct threat hunts and tabletop exercises, addressing any findings.
β’ Transform incident and detection metrics into evidence for SOC 2, ISO 27001, and enterprise customer security assessments.
β’ Work alongside the GRC team.
β’ Engage in a security incident on-call rotation.
β’ Report to the head of security and collaborate with platform and research engineers.
β’ Practical experience in incident response, including triaging real-time alerts, leading investigations, and preparing post-incident reports.
β’ Proficiency in building and tuning detections within a modern SIEM, preferably managed as code.
β’ Solid understanding of attacker movements in cloud and Kubernetes environments, encompassing IAM abuse, container escape, credential theft, and supply chain compromises.
β’ Capability to program in Python, TypeScript, Rust, or other languages to automate response tasks and integrate security tools.
β’ Familiarity with at least one major cloud platform.
β’ Knowledge of Kubernetes, including audit logs, RBAC, and workload identity.
β’ Strong writing skills for incident timelines, detection documentation, and updates for leadership.
β’ Sound judgment regarding alerting, automation, and escalation decisions.
β’ Participation in an on-call rotation for security incidents is required.
β’ Experience in monitoring GPU or HPC-style infrastructure, research environments with large datasets, AI agents, LLM tooling, or MCP servers is a plus.
β’ Cloud forensics experience, covering disk and memory acquisition, reconstruction of cloud audit trails, and chain of custody, is advantageous.
β’ Having published open-source detection content is a plus.
β’ Competitive salary and performance-based bonuses.
β’ Comprehensive health, dental, and vision insurance.
β’ Opportunities for professional development and growth.
β’ Flexible work hours and remote working options.
β’ Supportive and inclusive company culture.
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.