Detection & Response Engineer

atRunwayRemoteUS flagUnited StatesFull-timeEngineerMid-levelSenior$240k – $290k/year

Posted 3 days ago

This is a fully remote position, open to applicants in United States.

πŸ“‹ Description

β€’ Take ownership of the end-to-end detection and response process, encompassing logging, alerting, triage, and recovery.

β€’ Develop and refine detections as code across various cloud environments, Kubernetes, identity systems, endpoints, and SaaS applications.

β€’ Evaluate detections based on coverage and precision instead of alert volume.

β€’ Lead the incident response process from the initial alert to containment and forensics.

β€’ Compose post-incident reviews.

β€’ Create automation for triage enrichment, correlation, containment actions, and evidence collection.

β€’ Utilize LLM-based tools where they can withstand auditing.

β€’ Monitor AI agents and developer tools while developing telemetry and controls.

β€’ Collaborate with platform and research engineers to establish logging and response playbooks in new systems.

β€’ Conduct threat hunts and tabletop exercises, addressing any findings.

β€’ Transform incident and detection metrics into evidence for SOC 2, ISO 27001, and enterprise customer security assessments.

β€’ Work alongside the GRC team.

β€’ Engage in a security incident on-call rotation.

β€’ Report to the head of security and collaborate with platform and research engineers.


⛳️ Requirements

β€’ Practical experience in incident response, including triaging real-time alerts, leading investigations, and preparing post-incident reports.

β€’ Proficiency in building and tuning detections within a modern SIEM, preferably managed as code.

β€’ Solid understanding of attacker movements in cloud and Kubernetes environments, encompassing IAM abuse, container escape, credential theft, and supply chain compromises.

β€’ Capability to program in Python, TypeScript, Rust, or other languages to automate response tasks and integrate security tools.

β€’ Familiarity with at least one major cloud platform.

β€’ Knowledge of Kubernetes, including audit logs, RBAC, and workload identity.

β€’ Strong writing skills for incident timelines, detection documentation, and updates for leadership.

β€’ Sound judgment regarding alerting, automation, and escalation decisions.

β€’ Participation in an on-call rotation for security incidents is required.

β€’ Experience in monitoring GPU or HPC-style infrastructure, research environments with large datasets, AI agents, LLM tooling, or MCP servers is a plus.

β€’ Cloud forensics experience, covering disk and memory acquisition, reconstruction of cloud audit trails, and chain of custody, is advantageous.

β€’ Having published open-source detection content is a plus.


🏝️ Benefits

β€’ Competitive salary and performance-based bonuses.

β€’ Comprehensive health, dental, and vision insurance.

β€’ Opportunities for professional development and growth.

β€’ Flexible work hours and remote working options.

β€’ Supportive and inclusive company culture.

People also viewed

Mercor11 hours ago

Industrial Engineer

US flagUnited States OnlyFreelanceEngineer$70 – $110/hour
ApplyView job
RTX20 hours ago

Principal Equipment Engineer, Adhesion & Assembly

US flagFlorida OnlyFull-timeEngineer$107.5k – $204.5k/year
ApplyView job
Expel21 hours ago

Senior Detection & Response Engineer

US flagVirginia OnlyFull-timeEngineer$142.9k – $207.2k/year
ApplyView job
Qualus1 day ago

Engineer II – Relay Settings, System Protection

US flagFlorida, +2 more statesFull-timeEngineer
ApplyView job
General Dynamics Information Technology1 day ago

Senior VDI / Citrix Engineer

US flagUnited States OnlyFull-timeEngineer$149.5k – $195.5k/year
ApplyView job
ARCOS LLC1 day ago

Configuration Engineer

PL flagPoland, +4 more countriesFreelanceEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers