Security Software Engineer, Detection & Response
- Location
- Hybrid - San Francisco, New York City, London
- Track
- AI Security
- Salary
- $208K–$312K / yr
- Posted
- July 8, 2026
- Source
- Greenhouse
Job description
About the role
We are looking for a Security Software Engineer, Detection & Response, to build the telemetry, logging, and response systems for our Detection & Response team, as a builder, not a queue-triage role. You will build detection and response as software across a multi-cloud fleet of servers, containers, and endpoints, and test where AI and agents can safely take work off responders. This is a hybrid role based in San Francisco, New York City, or London, with three days a week in the office.
What you’ll do
- Deploy and operate telemetry at fleet scale with osquery and extended Berkeley Packet Filter (eBPF) sensors across servers, containers, and endpoints, and own performance overhead, staged rollouts, canaries, and rollbacks
- Build and maintain the logging and security information and event management (SIEM) pipeline behind detection, including ingestion, normalization, enrichment, storage, and cost, with detections written as code with tests, code review, and continuous integration and continuous delivery (CI/CD)
- Automate response with tooling for host isolation, credential revocation, evidence collection, and enrichment, and test where AI and agents can safely take work off responders
- Strengthen the corporate security stack, including endpoint detection and response (EDR) and fleet management across Mac, Windows, and Linux, email security, and GitHub controls
- Join the on-call rotation, work with the managed security operations center (SOC) on escalations, and automate evidence collection for System and Organization Controls 2 (SOC 2), Payment Card Industry Data Security Standard (PCI DSS), and ISO audits
What you need
- 5+ years in security, infrastructure, or platform engineering, writing production code in a compiled language (Go or Rust preferred) and a scripting language (Python or Bash)
- Deployed and operated agents, sensors, or telemetry collectors at fleet scale, such as osquery or eBPF-based tooling
- Operated AWS infrastructure, including networking, identity and access management (IAM), logging, and container workloads, with infrastructure as code in Terraform
- Built and run a data or logging pipeline, including SIEM operations and SQL for investigation
Bonus if you
- Worked with managed SOC providers or security orchestration, automation, and response (SOAR) platforms
- Built or contributed to open source security or observability tooling
- Know serverless platforms and API security
- Flexible Time Off.
The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.