←Jobiba.Me
I
Active1mo ago

Detection Engineer II

Instacart·📍 United States - Remote

Employment

FULL TIME

Work mode

Remote

Experience

MID LEVEL

Salary

Not disclosed

Salary not disclosed

Check market pay for comparable Detection Engineer roles before applying.

Salary →

Role overview

Job description

We're transforming the grocery industry

At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.

Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.

Instacart is a Flex First team

There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.

Overview

Instacart's Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North America's largest grocery technology platforms. We own the full detection lifecycle, from telemetry collection and signal design to automated response, across a complex, cloud-native environment spanning endpoint, cloud, container, and SaaS.

As a Detection Engineer, you'll be a technical anchor on the team: developing high-fidelity detection logic, hunting for novel attacker techniques, and raising the bar for how we think about coverage, quality, and scale. You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure our detections reflect real-world adversary behavior (and not just signatures).

We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed through repeatable pipelines. We care deeply about reducing noise, improving analyst efficiency through automation and SOAR, and continuously evolving our coverage as the threat landscape shifts.

If you're energized by hard forensic problems, enjoy translating attacker TTPs into durable detection logic, and want to help shape the future of a growing security function, this role is for you.

About the Job

  • Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
  • Assist in cyber forensic investigations across a variety of log sources
  • Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost
  • Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions
  • Mentor/knowledge share with other detection engineers on threat hunting methodologies, detection logic development, and investigation techniques

About You

Minimum Qualifications

  • 2+ years of experience in a detection engineering, incident response, or offensive security role.
  • Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
  • Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries
  • Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
  • Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines
  • Basic proficiency with Python, Golang, or other programming/scripting languages
  • Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar

Preferred Qualifications

  • Background in offensive security or red teaming
  • Knowledge of machine learning for threat detection

#LI-remote

Instacart provides highly market-competitive compensation and benefits in each location where our employees work. This role is remote and the base pay range for a successful candidate is dependent on their permanent work location. Please review our Flex First remote work policy here.

Offers may vary based on many factors, such as candidate experience and skills required for the role. Additionally, this role is eligible for a new hire equity grant as well as annual refresh grants. Please read more about our benefits offerings here.

For US based candidates, the base pay ranges for a successful candidate are listed below.

CA, NY, CT, NJ
$171,000—$180,500 USD
WA
$164,000—$173,000 USD
OR, DE, ME, MA, MD, NH, RI, VT, DC, PA, VA, CO, TX, IL, HI
$157,000—$165,500 USD
All other states
$142,000—$150,000 USD

What they are looking for

Skills & requirements

I

Hiring company

Instacart

Explore this employer's active roles, salary signals and company profile on Jobiba.

Keep exploring

Similar active roles

Fresh roles matched to this title and market.

View all →
P
📍 United States· Full-time· Remote

From $123.7K/yr

About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest is seeking an experienced Security Engineer to build and implement detection and response improvements and adapt to emerging threats to protect employees and infrastructure. In this role you will have the opportunity to solve challenging problems and provide a meaningful impact on our overall security posture. We are looking for a candidate with a passion for both security and innovation. What you'll do: Build alerts and automation workflows to improve capabilities to detect and response to external and internal security threats Manage our logging pipelines and infrastructure and onboard new logging sources to improve our detection coverage Develop and maintain internal tooling to expand and automate team detection and response capabilities Respond to alerts generated from our tooling and run incidents as part of an on-call rotation Co

PythonAWSLinuxRest
O
📍 Toronto, Ontario, Canada· Full-time

From C$110K/yr

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The End User Protection Team Auth0 is an easy-to-implement authentication and authorization platform designed by developers for developers. We ensure access to applications is safe, secure, and seamless for the more than 100 million daily logins worldwide. Our modern approach to identity enables this Tier-0 global service to deliver convenience, privacy, and security, allowing customers to focus on innovation. The End User Protection team is responsible for building and maintaining Auth0’s Attack Protection capabilities. Cyberattacks, such as credential stuffing and password spraying, often target end users to gain unauthorised access to applications. These attacks pose a significant threat, compromising user accounts and data. The Attack Protection features mitigate these risks by continuously monitoring user login behaviour and automatically detecting and blocking malicious activity. They protect users without adding unnecessary friction. The team works closely with our Machine Learning and AI teams to develop and deploy cutting-edge detection models. This collaboration allows application builders to provide a secure login experience for their users while isolating them from the complexities and ever-evolving tactics of these attacks. The Software Engineer II Opportunity We are looking for a Software Engineer II to join our End User Protection team. What you’ll be doing Be a part of a fast-paced, agile team. Design and buil

JavaScriptTypeScriptJavaNode.js
C-
📍 New York, NY, United States· Full-time

$180K – $220K/yr

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We’re looking for an experienced Machine Learning Engineer to help us build the next generation of products which will go beyond just ID and enable our members to leverage the power of a networked digital identity. As a Machine Learning Engineer at CLEAR, you will participate in the design, implementation, testing, and deployment of applications to build and enhance our platform - one that interconnects dozens of attributes and qualifications while keeping member privacy and security at the core. A brief highlight of our tech stack: Python / Postgres / Snowflake / dbt AWS SageMaker and MLflow What you'll do: Own and drive the foundational work of a ML system at CLEAR Design, build and deploy ML models for various applications, such as document and image processing, fraud detection. Develop and implement robust data pipelines at a variety of scales, including collection, pre-processing, transformation, and feature engineering Partner with product and other stakeholders to uncover requirements, to innovate, and to solve complex problems Have a strong sense of ownership, responsible for architectural decision-making and striving for continuous improvement in technology and processes at CLEAR What you're great at: 3+ years of experience building, operating and scaling ML models for consumer applications, particularly those with experience building end-to-end systems Experience designing, implementing, and scaling complex data pipelines for ML models and evaluating their performance Expertise in best practices for feature enginee

PythonAWSGitRest
P
📍 San Francisco, California, United States· Full-time

Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat

AWSKubernetesCI/CDGraphql
A
📍 Poland· Full-time· Remote

PLN 3.1M – PLN 4.5M/yr

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The Collections team, as part of the Repayments area, is on a mission to build a robust platform that will maximize the recovery of delinquent users by sending the right message to the right people at the right time, while monitoring and detecting problems and ensuring high reliability of the engineering systems. Collaborating closely with our product managers, backbook risk teams and other engineering teams , you will effectively manage loans throughout the delinquency phase of their lifecycle and develop and implement recovery strategies. We are looking for a highly motivated software engineer to build the next generation platform solutions that will allow us to manage our constantly growing volume while maintaining high availability and reliability of the systems. You will work closely with your team mates in the Collections team and Product to build robust collections solutions which will enable us to keep our loans portfolio healthy and help our customers pay on time and recover from any delays. What You'll Do · With the support of your team’s tech lead and manager, you will break down larger projects into individual tasks, deliver them in multiple phases, and collaborate with others to ensure timely delivery of your work. · You will support your peers and stakeholders in the product development lifecycle by collaborating with product management, design & analytics by participating in ideation, articulating technical constraints, and partnering on decisions that properly consider risks and trade-offs. · You will support the operations and availability of your team’s artifacts by creating and monitoring metrics, escalating when needed, and supporting “keep the lights on” & on-call efforts. · You will contribute to a sense of community on your team by engaging in growth and devel

PythonSQLMySQLAWS
A
📍 Spain· Full-time· Remote

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The Collections team, as part of the Repayments area, is on a mission to build a robust platform that will maximize the recovery of delinquent users by sending the right message to the right people at the right time, while monitoring and detecting problems and ensuring high reliability of the engineering systems. Collaborating closely with our product managers, backbook risk teams and other engineering teams , you will effectively manage loans throughout the delinquency phase of their lifecycle and develop and implement recovery strategies. We are looking for a highly motivated software engineer to build the next generation platform solutions that will allow us to manage our constantly growing volume while maintaining high availability and reliability of the systems. You will work closely with your team mates in the Collections team and Product to build robust collections solutions which will enable us to keep our loans portfolio healthy and help our customers pay on time and recover from any delays. What You'll Do · With the support of your team’s tech lead and manager, you will break down larger projects into individual tasks, deliver them in multiple phases, and collaborate with others to ensure timely delivery of your work. · You will support your peers and stakeholders in the product development lifecycle by collaborating with product management, design & analytics by participating in ideation, articulating technical constraints, and partnering on decisions that properly consider risks and trade-offs. · You will support the operations and availability of your team’s artifacts by creating and monitoring metrics, escalating when needed, and supporting “keep the lights on” & on-call efforts. · On-Call Rotation - There would be an on-call rotation for this role as a requirement · Y

PythonSQLMySQLAWS

🔔 Get job alerts

New Detection Engineer II jobs in United States - Remote, straight to your inbox.

No spam · Unsubscribe anytime