Detection Engineering & Response Lead
Lead detection engineering, threat intelligence, and incident response across a global AI cloud infrastructure platform. Build the detection and response capability, lead a growing team, and develop scalable security processes, tools, and coverage.
Обязанности
- Lead detection development and maintain effective false-positive and false-negative rates
- Architect and operate detection coverage across cloud and bare-metal environments
- Build internal detection and response tools, pipelines, log integrations, and automated response runbooks
- Integrate threat intelligence and adversary TTPs into detection logic and incident response playbooks
- Lead incident response from scoping and containment through root cause analysis and post-incident reviews
- Own critical remediation actions and drive follow-up changes after incidents
- Build and maintain the security incident response program, including people, processes, and tools
- Define and report metrics including MTTD, MTTR, detection coverage, and false-positive rates
- Develop scalable tools, runbooks, and on-call processes
- Lead and mentor a small, growing team of analysts and engineers
Требования
- 6+ years of experience in security operations, detection engineering, or incident response
- At least 1–2 years of team leadership or mentoring experience
- Hands-on experience with cloud-native environments, Kubernetes, Linux, and container infrastructure
- Strong experience writing and tuning SIEM detections using platforms such as Chronicle, Splunk, or Elastic, plus SQL
- Experience operating SOAR workflows and automating response at scale; Golang and Temporal are advantageous
- Working knowledge of MITRE ATT&CK, Pyramid of Pain, Kill Chain, and threat intelligence operationalization
- Experience with memory forensics, log analysis, network traffic analysis, and post-incident reporting
- Ability to coordinate with engineering, compliance, legal, and executive stakeholders during incidents
Будет плюсом
- Experience with AI/ML and GPU-cluster threats
- Familiarity with eBPF-based detection and runtime security tools such as Falco or Tetragon
- Threat hunting experience
Условия и преимущества
- Competitive compensation with equity upside
- Career growth and learning opportunities
- Flexible, remote-first culture
- Collaborative and innovative environment
- Opportunity to work on impactful AI infrastructure projects