SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 180,000 / annual
Doppel is building an AI-native platform to defend against social engineering threats including phishing, impersonation, fraud, and AI-powered attacks. The company unifies Digital Risk Protection, Human Risk Management, and Email Security into a real-time intelligence graph. Backed by Andreessen Horowitz and Bessemer Venture Partners, Doppel is a Series C startup trusted by leading enterprises.
In this role, you will investigate complex email threats and detection failures, then translate findings into detections, evaluations, AI behaviors, and product capabilities that scale across all Doppel customers. You'll own detection problems end-to-end: from emerging tactics/techniques/procedures (TTPs) or false negatives through investigation, hypothesis formation, validation, production deployment, and measurement.
Key responsibilities:
- Own detection problems end-to-end, moving from emerging TTP or false negative to investigation to detection hypothesis to validation to production coverage to measurement
- Use AI as a force multiplier by building evaluations, supervising model behavior, using coding agents aggressively, and automating repetitive investigative work
- Partner with Product and Engineering teams on signals, detection logic, edge cases, and validation
- Work with customers and go-to-market teams on detection gaps, real-world TTPs, and platform behavior
- Turn tooling, threat-intelligence partnerships, and provider relationships into new signals and detection capabilities
You will shape the product rather than just operate it, working on real emerging attacks and turning practitioner judgment into detections, AI behavior, and product capabilities alongside Product, Engineering, AI/ML, customers, and ecosystem partners.
REQUIREMENTS:
- Deep practitioner judgment from one or more of: detection engineering, SOC/incident response, threat intelligence/OSINT, or email/messaging security (range across multiple areas is a major plus)
- Ability to take messy detection failures from "something's off" to root cause; prove what matters in the data and turn false positive/false negative cases into durable fixes
- Think like both attacker and defender across phishing, business email compromise (BEC), impersonation, credential theft, account takeover (ATO), and evolving social-engineering TTPs
- Turn expert judgment into detection logic, evaluations, tests, requirements, and systems that scale beyond a single investigation or customer
- Thrive at the intersection of security, AI, product, and customers; challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity
NICE TO HAVE:
- Email security depth: SPF, DKIM, DMARC, headers, mail flow, and sender identity
- Experience with Microsoft 365/Exchange Online, Google Workspace, or email-security APIs
- Detection-as-code, evaluation datasets/labeling, model benchmarks, or LLM/ML security systems
- Built agentic security workflows, autonomous triage, or LLM evaluation systems
- Experience with Agentic SOC, SIEM/threat intelligence tooling, and threat-intelligence provider/vendor partnerships