SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 174,500 - 240,000 / annual
Faire is a technology wholesale platform connecting independent retailers globally with suppliers. As the first Detection and Response Engineer, you'll build enterprise security detection and response capabilities from the ground up.
You'll own the complete detection engineering lifecycle: defining monitoring strategy, building telemetry pipelines, creating detection content, routing alerts, and developing response playbooks. This is a zero-to-one role with significant autonomy to shape Faire's security posture.
Key responsibilities include:
- Establishing technical direction for detection and response, defining roadmaps, and making the case for tooling and resources
- Building end-to-end detection engineering for the enterprise environment, including telemetry pipelines, detection content, alert routing, and enrichment
- Adopting a threat-informed approach by tracking adversary tactics against companies like Faire and translating them into detections, hunts, and tabletop exercises
- Owning detections and data pipelines written as Infrastructure as Code
- Automating triage, enrichment, and response to scale alert handling without proportional analyst growth
- Collaborating with IAM, endpoint, network engineering, and IT infrastructure teams to obtain necessary telemetry
- Partnering with Enterprise Security to translate findings into control improvements and ensure root causes reach responsible teams with sufficient context
You'll need deep hands-on experience in detection engineering, incident response, or security operations with a proven track record of building capability. Required expertise includes corporate attack surfaces (identity providers, SSO, endpoint/EDR, email security, SaaS logs, device management, network access), strong Python and SQL proficiency, and the ability to build detection-as-code pipelines independently. Practical experience with SIEM, EDR, and security analytics platforms is essential, along with investigative depth across endpoints, cloud, and SaaS environments.
Bonus qualifications include founding security hire experience, insider threat/data loss detection expertise, offensive security background, incident commander experience, endpoint/cloud forensics depth, or perspective on SIEM versus data warehouse architecture.
Faire offers a hybrid model with 3 days per week in office (Tuesdays, Thursdays, plus one flex day) and up to 4 weeks annual remote flexibility.