SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
HappyRobot is building infrastructure for enterprises to deploy and orchestrate AI workforces at scale. The company, backed by a16z and Y Combinator (S23), has raised over $150M and operates in demanding environments where AI systems make real decisions and take autonomous action across enterprise systems.
You will build and own the detection and response capability from the ground up, establishing real monitoring across the cloud and identity stack. This is a detection engineering role requiring deep technical expertise, not an analyst position.
Key responsibilities include:
**Detection Engineering**: Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive tuning loop, track noise per detection, and systematically grow coverage across prioritized techniques. Detections should be high-signal from inception.
**Log Pipeline Engineering**: Onboard, parse, and normalize log sources into the SIEM reliably. Get tier-1 sources (CloudTrail, GuardDuty, Kubernetes audit logs, Okta) live within the first two quarters. Maintain pipeline cleanliness as new sources are added.
**Incident Triage & Response**: Investigate alerts end-to-end with clear severity reasoning, complete timelines, and actionable context. Own triage through to disposition rather than handing off incomplete investigations.
**Automation**: Script enrichment, response actions, and repetitive SOC tasks in Python or Go. Systematically reduce toil by automating anything done manually more than twice.
**Runbooks & Documentation**: Write triage runbooks for high and critical alert types, documented clearly enough for analysts to execute independently. Keep runbooks current as infrastructure evolves.
**SOC Foundation**: Build the monitoring capability that enables an informed in-house vs. hybrid SOC decision by end of September. The architecture and processes you establish directly shape the future SOC model.
Required: 3–5 years in detection engineering, SOC engineering, or blue team roles. Hands-on experience building detections in modern SIEMs (RunReveal, Panther, Elastic, Splunk, Sentinel). Deep familiarity with cloud and identity log sources. Scripting proficiency in Python or Go. MITRE ATT&CK mapping experience. B2+ English proficiency.
Nice-to-have: Detections-as-code with Git and CI/CD, EDR experience (SentinelOne, CrowdStrike), incident response beyond triage, CNAPP exposure, relevant certifications (GCIA, GCDA, GCIH, BTL2), prior startup experience building monitoring from scratch.