Security Engineer, Detection & Response

Scale AI Scale AI · Data AI · New York, NY +3 · Horizontals EPD

Seeking a Senior Security Engineer specializing in Detection and Incident Response to build systems for detecting, containing, and preventing security incidents. The role involves engineering detection logic, building automation, maturing telemetry pipelines, and performing incident investigations, requiring strong coding skills and security operations experience.

What you'd actually do

  1. Engineer, test, and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance.
  2. Build and maintain incident response automation, runbooks, and tooling that reduce containment timelines without sacrificing developer velocity.
  3. Mature telemetry pipelines through improved schema design, normalization, enrichment, and quality checks that reduce false positives and increase signal fidelity.
  4. Perform digital incident investigations to identify and contain potential security breaches.
  5. Conduct digital forensics and malware analysis to understand attack vectors and adversary methodologies.

Skills

Required

  • 5+ years of experience in Detection Engineering, Incident Response, or Security Operations
  • Proficiency in at least one programming language (e.g., Python, Go)
  • Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments
  • Practical experience with SIEM, EDR, and SOAR tools
  • Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs
  • Experience with cloud-native environments (e.g., AWS, GCP, Azure) and the security telemetry those environments generate

Nice to have

  • building integrations or extended these platforms programmatically
  • digital forensics tools and malware analysis techniques
  • threat intelligence platforms and integrating intel into detection and investigation workflows
  • Relevant security certifications (e.g., GCIH, GCFA, GCIA, CISSP, GDSA)

What the JD emphasized

  • building and shipping security tooling and automation
  • production-grade code
  • detection pipelines
  • alerting workflows
  • cloud-native environments
  • security telemetry