
Senior Security Engineer – Threat Detection
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Design, implement, and consistently enhance detections that align with MITRE ATT&CK across cloud, endpoint, identity, email, and application telemetry.
• Take ownership of the entire detection lifecycle, including hypothesis formulation, data validation, baselining, deployment, tuning, validation, and retirement.
• Enhance the detection-as-code platform by utilizing version control, peer reviews, automated testing, CI/CD, pipeline reliability, and observability.
• Recognize emerging threat surfaces and create integrations for data ingestion, enrichment, and coverage across both internal and external systems.
• Assess AI-driven security capabilities, such as secure MCP integrations, threat hunting, anomaly detection, and response automation.
• Transform threat intelligence into actionable detections and conduct retrospective scanning.
• Collaborate with Security Operations during investigations, incidents, tabletop exercises, detection maintenance, and code pairing.
• Report directly to the Director of Threat Detection and Response.
• Work in close partnership with Security Operations, Application Security, Enterprise Security, and engineering teams throughout the organization.
• Promote Samsara’s cultural principles as the company expands globally and opens new offices.
• Over 6 years of experience in security engineering, detection engineering, or a related technical field.
• Proficient in Python and SQL.
• Experience in analyzing large datasets to construct and validate detections.
• Practical experience with detection-as-code, Git-based workflows, automated testing, and CI/CD deployment.
• Extensive experience with modern SIEM platforms, including data onboarding, advanced queries, dashboards, and threat intelligence enrichment.
• Familiarity with AWS, Linux, containers, and EDR technologies.
• Demonstrated capability to build systems from the ground up, independently lead projects, quickly learn new technologies, and effectively communicate technical concepts through documentation, RFCs, and presentations.
• Experience with data orchestration platforms such as Airflow or Databricks.
• Practical knowledge of LLMs, agentic frameworks, and MCP integrations, including their associated security risks and potential failure modes.
• Experience in behavioral analytics, anomaly detection, feature engineering, and model evaluation.
• Understanding of risk-based alerting, ChatOps, distributed alerting, and attack simulation.
• Additional experience with Go, Terraform, malware analysis, digital forensics, or FedRAMP environments is a plus.
• Initial RSU grant with no vesting cliff.
• Continuous equity refresh opportunities linked to performance.
• Performance-based bonus/variable pay.
• Equity options for eligible roles.
• Flexible, employee-driven remote working model.
• Professional development stipend.
• Comprehensive health insurance plans.
• Parental leave policies.
• Flexible working arrangements.
• Remote work support.
• Option for in-person office work.
• Commitment to equal opportunity employment.
• Reasonable accommodations provided throughout the recruitment process.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.