SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Modal is building the infrastructure layer for AI, serving category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. The company recently raised a $355M Series C at a $4.65B valuation and has crossed $300M+ ARR with fivefold growth since September.
As a Detection and Response Engineer, you'll build systems to identify, investigate, and respond to threats across Modal's serverless cloud platform. This is an engineering-focused role centered on automation, where you'll design high-fidelity detections for attacks, abuse, and anomalous behavior across infrastructure and production systems. You'll continuously improve detections based on telemetry, threat intelligence, and incident learnings while improving visibility across cloud infrastructure, containers, identity systems, and production services.
You'll lead or participate in security investigations spanning production infrastructure, cloud environments, and internal systems. You'll build playbooks and automation that reduce investigation time and improve response consistency, driving post-incident improvements that eliminate entire classes of future incidents. You'll develop internal tooling that improves detection, investigation, and response workflows, leveraging LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
You'll partner closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient. You'll help teams instrument services with the telemetry needed for effective detection and response, and drive security improvements that make the platform easier to defend over time.
Required qualifications include experience in detection engineering, incident response, or security engineering with strong software engineering skills and production systems experience. You'll need experience investigating security incidents in cloud-native or distributed environments, familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking, and the ability to build detections using logs, telemetry, behavioral signals, or large-scale event data. Strong SQL skills for investigating security events and developing detections are essential, along with interest in applying AI and LLMs to detection and response workflows.
About Modal Labs
AI / Data / Infrastructure — serverless cloud platform for AI, data, and compute-intensive applications.