SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer, Detection and Response

HackerOne - Remote - Remote - posted 2026-09-07

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

HackerOne is rebuilding its Detection & Response function with an AI-first approach, and this Senior Security Engineer role sits at the center of that effort. You will design and deliver detection and response capabilities that protect a modern, cloud-native environment by writing code, building AI-powered tooling, and automating workflows end-to-end. You'll operate across the full detection lifecycle—from identifying gaps in observability to shipping high-signal detections and leading incident response. The role emphasizes scaling team capacity through automation, intelligence, and AI rather than headcount. Key responsibilities include: - Design, build, and maintain detection-as-code capabilities across cloud infrastructure, SaaS applications, endpoints, and identity systems - Build automated investigation and response workflows that replace manual runbooks, leveraging AI and LLMs to scale triage, enrichment, containment, and remediation - Develop and deploy AI/LLM-powered tooling to accelerate investigations, reduce alert fatigue, and extend team capacity - Lead and participate in incident response, including detection, investigation, containment, and retrospectives - Partner cross-functionally with engineering and platform teams to expand logging, improve observability, and embed detection capabilities into the development lifecycle - Continuously improve detection quality by analyzing alert performance, tuning for signal, and building feedback loops between incidents and detections - Proactively identify gaps in visibility or coverage and translate ambiguous problem spaces into concrete detection and response solutions - Adapt quickly to evolving threats, tools, and priorities HackerOne is a global leader in Continuous Threat Exposure Management (CTEM), uniting agentic AI solutions with the world's largest community of security researchers. The company serves industry leaders including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense. The role is remote but targeted for candidates within approximately 50 miles of Austin TX, Seattle WA, Washington DC, San Francisco CA, or Boston MA, allowing for occasional in-person collaboration while preserving remote work benefits. REQUIREMENTS: Minimum Qualifications: - 5+ years of experience in detection and response, security engineering, or software engineering with a security focus - Strong software engineering fundamentals with proficiency in Python, Go, Ruby, or similar languages, and experience working in production codebases - Hands-on experience with cloud environments (AWS preferred), including services such as CloudTrail, GuardDuty, and VPC flow logs - Experience with log aggregation and analysis platforms (e.g., Datadog, Splunk, ELK) and endpoint detection tools (e.g., SentinelOne, CrowdStrike) Preferred Qualifications: - Experience building AI/LLM-powered security tooling or applying AI to detection, triage, or investigation workflows - Experience with detection-as-code frameworks or building custom detection pipelines - Familiarity with containerized environments (Docker, Kubernetes, ECS/EKS) - Experience with threat intelligence, threat hunting, forensics, or attacker tradecraft frameworks such as MITRE ATT&CK

Similar roles