Staff Principal Software Engineer Detection and Response
You build detection engineering platforms, detections-as-code, automated triage, and response playbooks. You design incident response processes, lead high-severity incidents from detection through post-mortem, proactively hunt across corporate, production, and AI-agent surfaces, and develop durable detections.
Responsibilities
- Build the detection engineering platform
- Create detection pipelines and detections-as-code
- Automate triage
- Develop response playbooks
- Design and own the security incident response process with 24/7 coverage
- Lead incidents from detection through containment, eradication, post-mortem, and follow-through
- Hunt across corporate, production, and AI-agent surfaces
- Turn findings into durable detections
- Define and build detection and response capabilities for an AI-native company
Requirements
- 8+ years of experience in detection engineering, incident response, or threat hunting
- At least 3 years at staff or principal level
- Detection-as-code engineering
- Cloud telemetry experience with GCP, AWS, or Cloudflare
- Endpoint EDR
- Identity logs
- SIEM and data-lake stacks
- Incident command experience
- MITRE ATT&CK
- Threat intelligence
- Purple teaming
- Red team collaboration