SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Detection & Response

Scale - San Francisco, CA, United States - Hybrid - posted 2026-04-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 237,600 - 297,000 / annual

Scale is hiring a Senior Security Engineer specializing in Detection and Incident Response to join their Security Engineering team. This role bridges security operations and software engineering, requiring both strong incident investigation skills and production-grade coding ability. You will engineer and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance metrics. You'll build and maintain incident response automation, runbooks, and tooling that reduce containment timelines while preserving developer velocity. A key focus is maturing telemetry pipelines through improved schema design, normalization, enrichment, and quality checks to reduce false positives and increase signal fidelity. Responsibilities include performing digital incident investigations to identify and contain security breaches, conducting digital forensics and malware analysis to understand attack vectors, and integrating alerting with messaging and ticketing systems for fast, traceable response workflows. You'll partner cross-functionally with IT, security, and engineering teams to harden identity and access patterns, close logging gaps, and implement scalable guardrails. You'll also leverage threat intelligence platforms to improve hunting, detection, and response workflows, and clearly communicate incident significance and impact to both technical and non-technical stakeholders. Ideal candidates have 5+ years in Detection Engineering, Incident Response, or Security Operations with strong emphasis on building and shipping security tooling. You should be proficient in at least one programming language (Python, Go preferred) and comfortable writing production-grade code. Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments is essential. Practical experience with SIEM, EDR, and SOAR tools—particularly building integrations or extending platforms programmatically—is highly valued. Strong understanding of modern cyber threats, attack techniques, and adversary TTPs is required. Familiarity with digital forensics tools, malware analysis, cloud-native environments (AWS, GCP, Azure), and threat intelligence platforms is expected. Relevant security certifications (GCIH, GCFA, GCIA, CISSP, GDSA) are a plus.

Similar roles