Security Engineer, Detection & Response
Job description
About the role
Scale AI is actively seeking a Senior Security Engineer to join our Security Engineering team where you will play a critical role in shaping the future of security tooling and operations. You will bridge the gap between security operations and software development by building the systems that detect and prevent threats rather than just responding to them. In this capacity, you will own the design and implementation of detection frameworks that operate at the intersection of cloud infrastructure and SaaS ecosystems. The role requires a proactive mindset focused on creating scalable solutions that automate threat detection and streamline response playbooks. You will be responsible for ensuring that security telemetry is not only collected but also transformed into actionable intelligence. This position demands a balance between deep technical execution and strategic thinking to protect our platforms and customers. You will work closely with cross-functional partners to ensure that security capabilities evolve in line with product development and emerging risks.
Key facts
What you'll do
- Develop, test, and deploy detection logic for cloud and SaaS environments using software engineering practices like version control and peer review.
- Create and maintain automation, runbooks, and tools to speed up incident response without slowing down developers.
- Improve telemetry pipelines by refining schema design, normalization, and enrichment to increase signal accuracy.
- Conduct digital investigations to identify and contain potential security breaches.
- Perform malware analysis and digital forensics to map out adversary tactics and attack vectors.
- Connect alerts to ticketing and messaging systems to create traceable response workflows.
- Collaborate with engineering, IT, and security teams to improve identity access patterns and close logging gaps.
- Use threat intelligence platforms to refine hunting and response efforts.
- Explain incident impact and remediation steps to both technical and non-technical stakeholders.
- Design and implement custom dashboards and reporting mechanisms that provide visibility into security posture and trends.
- Evaluate new open source security tools and integrate relevant capabilities into existing detection frameworks.
- Optimize alert fidelity to reduce noise and ensure that critical threats receive immediate attention.
- Build and maintain detection content for SIEM platforms, focusing on cloud logs, network traffic, and SaaS audit trails.
- Lead incident response simulations and red team exercises to validate detection and response effectiveness.
- Document all changes, configurations, and procedures to ensure operational continuity and knowledge sharing.
Requirements
- 5+ years of experience in Incident Response, Detection Engineering, or Security Operations.
- Proficiency in at least one programming language such as Python or Go with the ability to write production-grade code.
- Hands-on experience building or upgrading detection pipelines, SIEM content, and alerting workflows in cloud-native environments.
- Practical experience using and programmatically extending SIEM, EDR, and SOAR tools.
- Understanding of modern cyber threats, adversary TTPs, and cloud-native security telemetry (AWS, GCP, Azure).
- Experience with digital forensics tools and malware analysis.
- Ability to integrate threat intelligence into investigation workflows.
- Strong communication skills for explaining security findings and business impact.
- Demonstrated ability to work effectively in a fast-paced, high-priority environment.
- Willingness to adhere to strict security policies and operational best practices.
- Capability to manage multiple priorities and deliverables while maintaining attention to detail.
- Commitment to continuous learning and staying current with evolving security threats and technologies.
- Compliance with all organizational security standards and regulatory requirements as applicable.
- Readiness to participate in on-call rotations and provide timely response during security incidents.
Nice to have
- Relevant security certifications such as GCIH, GCFA, GCIA, CISSP, or GDSA.
Skills & tools
- Python
- Go
- AWS
- GCP
- Azure
- SIEM
- EDR
- SOAR
- Threat Intelligence Platforms
Practical notes
- Compensation includes base salary, equity, and benefits such as health, dental, vision, retirement plans, learning stipends, and PTO.
- Candidates who have applied for this role must wait 90 days before reapplying.
- Reasonable accommodations are available for applicants with disabilities by contacting accommodations@scale.com.