Staff Security Engineer - Detection and Response
$205,000–$256,000 year
On-siteReno, Nevada, United States
Job Summary
Shape the Detections and Response roadmap by proactively identifying detection requirements during the design phase of new features and infrastructure. Architect AI-powered detection and triage pipelines that maintain accuracy and reduce manual effort, while eliminating detection gaps through variant analysis. Collaborate as a key architect for SIEM, SOAR, and adjacent security platforms, designing scalable ingestion and alerting frameworks. Own the technical architecture and maturity of the incident response program, guiding responses to complex high-impact events and driving findings to systemic remediation. Set technical direction for DART-owned codebases and establish team standards for responsible AI usage. This role supports the investment management industry's cloud platform, leveraging expertise in AWS ecosystems, detection-as-code, and AI-augmented security workflows.
Required Qualifications
- 8+ years working in detection, security operations, incident response, or software engineering, with a proven track record of leading cross-functional technical initiatives
- Advanced proficiency in Python or another high-level language like Kotlin or TypeScript
- Demonstrated skill engineering AI/LLM-driven systems: it is essential you are capable of building augmented detection, triage, and investigation workflows and rigorously validating their output for correctness and risk
- Expertise authoring detections mapped to attacker TTPs (e.g., MITRE ATT&CK)
- Extensive background building and operating detection-as-code and alerting pipelines, tuned for signal quality and noise reduction
- Strong command of the AWS ecosystem, specifically across logging and telemetry (CloudTrail, VPC Flow Logs, GuardDuty, CloudWatch), investigative tools (Athena, IAM analysis), and compute (Lambda, ECS/EKS)
- Fluency with infrastructure-as-code (e.g., Terraform) and CI/CD practices
- Strong written and verbal communication skills, with the ability to explain detection and response decisions clearly to engineers, product partners, and stakeholders
Desired Qualifications
- History leading complex, high-impact incidents as a technical lead or incident commander
- Hands-on design of AI agents or LLM-based automation in a security operations context
- Contributions to open source detection/security tooling or published security research
- Python (preferred)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.