Senior Detection Engineer

1 month, 2 weeks ago
Full-time
Senior
DevOps and Infrastructure
ActiveCampaign

ActiveCampaign

ActiveCampaign is a web-based software company that offers Email Marketing, Automation, and CRM services. Their Customer Experience Automation platform helps over 185,000 businesses build meaningful connections with their customers through personalized...

Internet Software & Services
251-1K
Founded 2003
$360M raised

Description

  • Design and deploy detection logic across the technology stack using detection-as-code principles.
  • Build automated response workflows to enrich, triage, and remediate security alerts.
  • Investigate complex security signals, including novel attack patterns and phishing campaigns.
  • Collaborate with DevOps and Security Engineering teams to update detections as infrastructure changes.
  • Use AI and LLMs to accelerate threat hunting, generate detection hypotheses, and automate investigative work.
  • Lead post-incident reviews and translate findings into preventative architectural improvements.
  • Prototype and test emerging detection capabilities and data sources.
  • Participate in an on-call rotation to help defend critical systems.

Requirements

  • 5+ years of hands-on experience in detection engineering, incident response, or security operations in high-growth technology environments.
  • Advanced Python programming proficiency with experience building production-quality security automations and custom integrations.
  • Deep expertise in AWS cloud security, including IAM, VPC, CloudTrail, and Lambda attack vectors.
  • Mastery of detection logic in at least two major languages such as YARA-L, Sigma, KQL, or SPL.
  • Experience building SOAR workflows or equivalent automation platforms that reduce operational overhead at scale.
  • Exceptional communication skills with the ability to translate complex security risks into actionable insights.
  • Experience using AI/LLMs for threat analysis, investigation automation, and improving security work velocity.
  • A self-directed, engineering-first mindset, ideally with a background in SRE, DevOps, or platform engineering.
  • Experience contributing to open-source security projects is preferred.

Benefits

  • Base salary of $126,000 to $154,000 per year, plus potential bonus and equity.
  • Fully covered HDHP, telehealth access, and a free Calm subscription.
  • Open PTO for flexible time off and work-life balance.
  • LinkedIn Learning access, professional development programs, and career growth opportunities.
  • Generous 401(k) matching with immediate vesting.
  • Quarterly perks, including commuter and lunch benefits for hub-based employees or a stipend for remote workers.
  • Four-week paid sabbatical with a bonus after five years.
  • Remote work arrangement in the United States.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

AI Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring an AI Security Engineer to help customers design, implement, secure, and operate generative AI security solutions across enterprise environments.

Cybersecurity Generative AI LLM Python SageMaker Terraform
6 hours, 15 minutes ago

Staff Software Engineer - K9 Security

Datadog 5K-10K IT Services

Datadog is hiring a Staff Software Engineer on its Security Agent team to lead low-level Linux instrumentation and runtime security work that powers threat detection and workload protection across its security products.

Datadog Linux
6 hours, 30 minutes ago

Director of Security

Puck 1-10 Internet Software & Services

Earnest is seeking a Director of Security to lead its security function and build a mature, business-aligned security program for a growth-stage fintech environment.

Ansible CI/CD DevSecOps Terraform
6 hours, 30 minutes ago

Staff Software Engineer - K9 Security

Datadog 5K-10K IT Services

Datadog is hiring a Staff Software Engineer for its Security Agent team to lead Linux instrumentation and runtime security work that supports threat detection, workload protection, and cloud security products at scale.

Linux
7 hours, 15 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers