Detection & Corpsec Engineer (remote)

Quora Quora · Consumer · Multiple · Remote · Engineering

Quora is seeking a Detection & Corporate Security Engineer to enhance security capabilities for both their Quora and Poe products. This role involves building and maintaining SIEM systems, developing detection rules, investigating security incidents, and implementing corporate security controls like endpoint protection and Zero-Trust VPNs. The engineer will also provide security guidance to non-technical teams. The position requires strong Python skills and experience with SIEM infrastructure and incident response.

What you'd actually do

  1. Build and maintain a SIEM to collect and analyze logs from across corporate and production systems; write and deploy detections and alerts to identify malicious behavior
  2. Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets
  3. Investigate security incidents end-to-end — including malware analysis, exfiltration assessment, and timeline reconstruction — and build runbooks to scale response capabilities
  4. Partner with IT to define and enforce security standards across the employee device fleet, including endpoint protection, managed device requirements, OS compliance, and VPN access controls
  5. Drive the PoC and implementation of Zero-Trust VPN and other corporate security infrastructure

Skills

Required

  • security engineering
  • detection engineering
  • SIEM infrastructure
  • detection rules
  • endpoint security tools
  • Python
  • security incident investigations
  • malware analysis
  • log review
  • timeline reconstruction
  • threat modeling
  • corporate security controls
  • identity management
  • endpoint protection
  • access control enforcement

Nice to have

  • SIEM/SOAR
  • Elastic/Splunk
  • Okta
  • OAuth
  • Yubikey
  • Passkey
  • Zero-Trust network architecture
  • VPN implementation
  • AI coding tools
  • small security team
  • fast-paced startup environment
  • AWS
  • cloud-native security tooling

What the JD emphasized

  • 5+ years of experience in security engineering, detection engineering, or a closely related field
  • Hands-on experience building or maintaining SIEM infrastructure and writing detection rules
  • Strong Python engineering skills with a track record of writing production code reviewed and shipped alongside software engineering teams
  • Experience conducting security incident investigations, including malware analysis, log review, and timeline reconstruction and threat modeling
  • Experience with corporate security controls, identity management, endpoint protection, and access control enforcement