WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: Detection Engineering is responsible for designing, developing, and maintaining high-fidelity detection logic across enterprise security platforms. This role focuses on proactive threat detection, automation-first practices, and continuous improvement of detection coverage and accuracy, supporting the WPP SOC transformation into an Autonomic Security Operations model. What you'll be doing: Develop, test, and maintain detection rules and logic across SIEM, EDR, NDR, and cloud-native platforms. Regularly review and enhance detection logic to improve accuracy, reduce noise, and align with evolving threats. Work with wider WPP engineering teams to ensure high-quality, normalized telemetry for effective detection. Automate detection rule deployment, QA, and version control using scripting and CI/CD pipelines. Root Cause Analysis (RCA) Conduct RCA on missed detections, delayed responses, and high-severity incidents. Identify technical and process-level causes of detection failures or inefficiencies. Drive corrective actions based on RCA outcomes (e.g., rule improvements,
Jobiba hiring network
Security Detection Engineer Jobs
15 active opportunities · Updated for September 2026
Fresh results
15 shown
Explore current security detection engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning–driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. You’ll partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to turn high-volume telemetry into high-confidence, low-noise detections at scale. What you’ll do: Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets. Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback). Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality. Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbo
Who We Are At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people. We’re helping businesses get off the ground by enabling them to focus on running their business. We solve HR issues. We’re data-driven and never stop iterating. If you’d like to work in a supportive, entrepreneurial environment, are interested in building something meaningful and having fun while doing it, we’d love to hear from you. We're united by shared goals and shared motivations at Justworks. These are best summed up in our company values, which are reflected in our product and in our team. Our Values If this sounds like you, you’ll fit right in. Who You Are Justworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and mature Justworks’ Security. As a Senior Detection Engineer, you’ll design, build, and maintain the detection logic that powers our platform, conduct proactive threat hunting, and drive continuous improvements across our detection and incident handling workflows. You’ll collaborate closely with IT, Engineering, Platform, and other members of the Security team to identify attacker behaviors, build high‑fidelity detections, and strengthen our defenses. You’ll also play a key role in designing and conducting table‑top exercises, improving processes, and building automation that reduces friction and accelerates response. You’ll help explore how AI can enhance detection, hunting, and operational efficiency. Your Success Profile What You Will Work On Build, tune, and deploy high‑quality detections across our platform Develop and refine detections using telemetry from EDR, threat intel, endpoint & cloud posture platforms and native AWS cloud services Conduct proactive threat hunting to uncover threat actor behaviors a
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. We are hiring for a leader for the newly forming Detection and Response team at Plaid. Our mission is to protect Plaid's financial infrastructure by detecting and responding to suspicious activity across the company. We are responsible for the entire lifecycle of detection and response, including detection infrastructure, AI triage and response, investigation tooling, Red Teaming, and Fraud Operations. Security is foundational to the trust thousands of businesses and millions of consumers place in Plaid, and we work directly to reduce risks and enable our business to move faster and safer. As the Head of Detection and Response, you will be the founding leader responsible for standing up and evaluating Plaid's detection and response team. You will lead a specialized technical team of analysts and engineers, gain deep experience partnering with the CISO and cross-functional engineering leaders, and build critical security infrastructure at scale. This is a unique leadership opportunity to manage a team that encompasses traditional security operations alongside Red Teaming and Fraud Operations, directly impacting Plaid's security posture and long-term stability. Responsibilities: Form and set up Plaid’
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Staff Security Engineer, Threat Detection for our Security team. This is a fully remote role open to candidates across the United States. As Snowflake scales globally, we are investing heavily in AI-powered threat detection and response to protect our customers and our environment at cloud scale. This role helps enhance and extend the reach of Snowflake's Threat Detection Program, with AI and automation as core primitives in how we detect, triage, and respond to threats. You will combine deep security expertise with strong engineering skills to build, maintain, and evolve detections and the pipelines that support them, partnering with stakeholders across Security and Engineering to make informed, data-driven decisions grounded in threat models, proactive threat hunts, and exploration of logs and telemetry. AS A STAFF SECURITY ENGINEER, THREAT DETECTION AT SNOWFLAKE, YOU WILL: Develop and deploy detections using modern engineering practices (testing and validation, CI/CD pipelines, detections as code, and a full detection development lifecycle), spanning both rules-based and AI-assisted detections. Mature our threat detection program by analyzing coverage gaps and mitigating risks through detective controls, experimenting with AI/ML approaches where they impr
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey – from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated Intercom help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey – from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated Intercom help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements. You Have: 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration. Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management. Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems. Platform expertise
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. About the Team The Security Operations (SecOps) team at Robinhood proactively safeguards our platform and millions of customers. We monitor, detect, and respond to security threats in real time while staying ahead of risks through threat intelligence, Red Team operations, and research partnerships. We are building the next generation of security operations—leveraging AI-driven automation, Autonomic Security Operations (ASO), and innovative detection frameworks to set the standard across the cybersecurity industry! About the Role As a Staff Security Engineer (IC6) on the Detection & Response team, you will drive our incident response strategy, build robust detection engineering frameworks, and mentor engineers across the organization. In this high-impact role, you will command high-stress incident responses, eliminate operational noise by developing an AI-native detection platform, and help shape the broader AI-agentic ecosystem for SecOps. You will work closely with cross-functional partners in Proactive Security, Security Engineering, Insider Trust, Infrastructure, Legal, and Communications to protect Robinhood’s ecosystem. This role is based in our Bellevue, WA a
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi
About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate. We take a pragmatic approach to preventing and responding to security risks. In this role not only will you build and contribute to systems which detect malicious activity, you will have the unique opportunity to implement new controls to prevent future incidents. You will work across detection and response and corporate security domains. You'll contribute to practices that keep Sentry secure as we grow: alert triage for corporate and production, detection engineering, deploying preventative controls, identity and access management, investigations and incident response, and more. You'll partner with teams across the company to prevent and respond to security incidents. You will work as a technical collaborator who prioritizes preventative controls, defense in depth, and high signal alerting practices. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security approaches and challenges. In this role, you will Maintain, improve, and own detection engineering systems. We own and operate our own detection stack and are building agentic triage with thoughtful security response and orc
About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate. We take a pragmatic approach to preventing and responding to security risks. In this role not only will you build and contribute to systems which detect malicious activity, you will have the unique opportunity to implement new controls to prevent future incidents. You will work across detection and response and corporate security domains. You'll contribute to practices that keep Sentry secure as we grow: alert triage for corporate and production, detection engineering, deploying preventative controls, identity and access management, investigations and incident response, and more. You'll partner with teams across the company to prevent and respond to security incidents. You will work as a technical collaborator who prioritizes preventative controls, defense in depth, and high signal alerting practices. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security approaches and challenges. In this role, you will Maintain, improve, and own detection engineering systems. We own and operate our own detection stack and are building agentic triage with thoughtful security response and orc
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage. In this role, you will: Build and evolve Detection & Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response. Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns. Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain. Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one. Define D&R requirements and drive visibility across endpoin
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage. In this role, you will: Build and evolve Detection & Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response. Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns. Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain. Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one. Define D&R requirements and drive visibility across endpoin
Get new security detection engineer jobs by email
Daily job updates · Unsubscribe anytime