SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Serval is an AI-native automation platform that builds intelligent agents to transform enterprise operations. Founded in early 2024 and backed by Sequoia Capital, Redpoint Ventures, and other leading investors, Serval is trusted by companies like Fox, Notion, Perplexity, Vercel, and Brex to automate high-volume operational work across IT, HR, Finance, Security, Legal, and Engineering.
As Detection and Response Lead, you will build and scale the foundations of Serval's cybersecurity detection and response operations. You will set strategy and drive execution for security monitoring, incident response, recovery, and post-incident improvement across Serval's infrastructure and the systems customers trust the company to operate.
You will be a hands-on leader with deep technical credibility and strong operational instincts. Key responsibilities include:
- Design, implement, and operate detection and response operations, including continuous monitoring, triage, investigation, containment, and remediation of security events across diverse networks and infrastructure.
- Build, lead, and directly mentor a team spanning observability, detection and response, and threat intelligence, hiring and scaling these functions deliberately as Serval grows.
- Ensure world-class operational rigor and readiness through incident playbooks, on-call and escalation paths, tabletop exercises, and continuous improvement of response quality and speed.
- Improve detection quality and coverage by partnering with engineering teams to ensure critical telemetry is available, reliable, and actionable across cloud, corporate, and production environments.
- Partner deeply across Engineering, Product, and Infrastructure to embed detection and response into Serval's systems by design.
- Build a security program capable of withstanding sophisticated adversaries, including leveraging Serval's own agents to solve frontier security and security-operations problems.
REQUIREMENTS:
- 10+ years in cybersecurity with deep expertise in detection engineering, incident response, and security operations.
- Deep experience building and leading detection and response, instrumentation/observability, and threat intelligence teams.
- Stellar leadership skills and demonstrated history of driving durable, continuous improvements to programs, processes, and people.
- Exceptional written and verbal communication skills; ability to remain calm under pressure and effectively run command of security incidents involving numerous stakeholders across diverse teams, expertise, and seniority.
- Deep expertise in modern observability stacks (e.g., SIEM, data lakes, EDR, cloud telemetry, logging) and detection primitives.
- Understanding of modern adversary tradecraft (TTPs) and demonstrated experience translating it into practical detection strategies and response actions.
- Mission-oriented with unimpeachable integrity and passion for detecting and responding to adversaries in a highly complex, fast-paced environment.