Senior Detection and Response Engineer

Anduril Anduril · Defense · Costa Mesa, CA · Corporate Technology : Information Security : Security Engineering

This role is for a Senior Detection and Response Engineer at Anduril, a defense technology company. The primary focus is on building defensive controls, developing detection signatures, and automating responses to protect infrastructure. The role involves threat modeling, data analysis in large-scale data lakes, and designing UEBA capabilities. While the company uses AI and advanced technologies, this specific role is centered on information security and defensive engineering, not direct AI/ML model development.

What you'd actually do

  1. Collaborate with Counter Intelligence and Insider Threat teams to develop key signals and capabilities to identify nefarious activity
  2. Support internal tooling that surfaces detections to partner teams in real time, including API integrations, audit-trail instrumentation, and data-source health
  3. Collaborate with Counter Intelligence, SecOps, Insider Threat and other key stakeholders to architect and implement detection and response frameworks for Anduril’s products, assets, and other custom applications
  4. Build and optimize tailored detection signatures and response automation using detection-as-code principles
  5. Lead threat modeling scenarios with cross-functional partners to understand weaknesses across OT, Cloud, Network, Endpoints, and other key worlds incorporating findings into security controls and/or detection signatures

Skills

Required

  • Experience programming in one or more general purpose languages (Python, Go, Rust, SQL, etc.)
  • Experience conducting data analysis in large-scale data lake environments
  • Experience deploying infrastructure as code (Terraform, CDK, CloudFormation, etc)
  • Experience working in a traditional software development lifecycle (i.e. Github, CI/CD, unit testing)
  • Extensive experience utilizing AWS / Azure security controls and services
  • Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure
  • Deep understanding of adversarial tradecraft with an emphasis on counterintelligence and insider threat tactics, techniques, and procedures (TTPs)
  • Strong communication skills, both written and verbal, and experience collaborating with internal and external stakeholders

Nice to have

  • Experience working directly with counterintelligence, insider threat, or special investigations teams in a cleared environment
  • Experience deploying infrastructure using Kubernetes (EKS) and/or Docker containers (ECS)
  • Experience proactively threat hunting using threat and counter intelligence signals to identify potential risks and weaknesses in telemetry

What the JD emphasized

  • Must be able to obtain and hold a U.S. Top Secret security clearance