Senior Detection and Response Engineer

Remote Full-time
Who: You! And the rest of the Threat Detection & Response team, Security organization, & our cross-functional partners across Engineering and Infrastructure.
What: A Senior Detection & Response Engineer role and an outstanding ability to operate with autonomy and ownership across the full detect-and-respond lifecycle.
When: ASAP! We are looking to hire and onboard a new hire as soon as we find the right person for the job. Exciting work awaits!
Where: Our office hub location of Palo Alto or NYC – you will be required to be in office 1+ days per week in alignment with our office work policy. This role is also eligible for 100% remote work.
Why: We're looking for a Detection & Response Engineer to join our Threat Detection & Response team. You'll build, tune, and maintain detection logic across a modern cloud-native security stack, investigate alerts and incidents end-to-end, and help mature our detection engineering and incident response capabilities.
How (to land the job!): Our interview process typically includes an initial recruiter conversation, a technical screening, and a series of interviews with team members to assess hands-on experience, problem-solving, and collaboration skills.

The day-to-day:
Author, test, and maintain detection logic as code across SIEM, EDR, and cloud platforms
Investigate security alerts, triage findings, and escalate as appropriate
Lead and participate in incident response as both responder and incident commander
Conduct threat hunts informed by emerging TTPs and threat intelligence
Build and improve automation to accelerate detection, triage, and response workflows
Contribute to runbooks, playbooks, and post-incident documentation
Collaborate with engineering and infrastructure teams to improve logging coverage and signal quality

Skills & qualities we value:
3+ years in a detection engineering, SOC, or incident response role
Hands-on detection-as-code experience β€” writing, testing, versioning, and deploying custom detection rules in a CI/CD or Git-based workflow
Strong custom detection authoring across at least one SIEM platform (ES|QL, KQL, SPL, or similar query languages)
Demonstrated alert investigation and triage skills β€” comfortable working from raw logs to root cause
Incident response experience in both responder and commander capacities, including coordination, containment, and post-incident review
Intermediate or above programming proficiency in Python or Go β€” able to build tooling, parse data, and automate workflows
Engineering background in building, deploying, or maintaining security systems (log pipelines, detection infrastructure, integration work)
Familiarity with the MITRE ATT&CK framework for mapping detections and threat hunts to adversary TTPs
Experience with at least one EDR platform (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) β€” writing custom queries and hunting beyond built-in alerts
Threat hunting experience using hypothesis-driven, intelligence-driven, or anomaly-driven approaches
Security log pipeline experience β€” building or maintaining ingestion from diverse sources (cloud APIs, webhook integrations, custom parsers)
Version control and CI/CD fluency β€” Git workflows for detection content

Preferred experience:
Experience with AWS, Azure, and/or GCP security services and cloud-native logging (CloudTrail, Azure Activity Logs, GCP Audit Logs)
Elastic Security experience (detection rules, ES|QL, index and ingest pipeline familiarity)
Experience with identity-based attack detection (Entra ID, Okta, SSO/OIDC abuse patterns)
SOAR or security automation tooling experience β€” building response playbooks, enrichment workflows, or triage automation
API security monitoring or investigation experience
Exposure to Zero Trust architectures (Cloudflare, Zscaler, or similar)
Familiarity with threat intelligence platforms or feeds (MISP, OTX, abuse.ch)
Supply chain security awareness (npm, PyPI, container image compromise detection)
Strong written communication β€” able to produce clear incident reports, runbooks, and stakeholder updates

Perks & benefits you will love
Spotnana strives to offer fair, industry-competitive, and equitable compensation. Our approach assesses total compensation, including cash, annual performance bonus, company equity, and comprehensive benefits.

The base salary range for this role is $150,000 - $190,000 per year, depending on a number of factors including the candidate’s working location.

We care for the people who make everything possible - our benefits include:
Pre-tax and ROTH 401(k) options via Fidelity with up to a 4% company match
Comprehensive benefit plans covering medical, dental, vision, life, and disability effective on your hire date. We cover 100% of your employee premiums and 85% of your eligible dependents
Pre-tax flexible spending account options for health, dependent care and commuter expenses
Flexible PTO in addition to 10 company holidays and an end-of-year company shutdown
Up to 26 weeks of parental leave
Monthly cell phone/internet stipend
Extra perks β€” IATAN travel membership, pet insurance, financial wellness tools, Calm app access, and more
Apply Now β†’

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Experienced Elementary Music Educator - Long Term Substitute Teacher Opportunity

Remote

FACILITY WILL CALL

Remote

Account Executive II, Eastern Region (R-18933)

Remote

Sr. Accountant – Remote (U.S. Based)

Remote

**Experienced Data Entry Specialist – Flexible Online Opportunity for Students**

Remote

Sr. Commercial Loan Processor - REMOTE

Remote

Project Manager, Construction/Commercial Interiors

Remote

[Remote] About UsCo-Chief Marketing Officer

Remote

Experienced Remote Walmart Customer Service Representative – Delivering Exceptional Support and Driving Customer Satisfaction through Empathy and Professionalism

Remote

Job Title: Junior Cloud/Backend Web3 Engineer (Remote) - Unlock the Future of Decentralized Finance

Remote
← Back