Staff Detection and Response Engineer

Spotnana Technology, Inc

  • NY
  • 30+ days ago
  • Remote
  • $150,000–$190,000 Per Year

Highlights

Youll build, tune, and maintain detection logic across a modern cloud-native security stack, investigate alerts and incidents end-to-end, and help mature our detection engineering and incident response capabilities. Preferred experience: Experience with AWS, Azure, and/or GCP security services and cloud-native logging (CloudTrail, Azure Activity Logs, GCP Audit Logs).

Numbers & Facts

LocationNY (
Remote
)
Salary$150,000–$190,000 Per Year

Description

Who: You! And the rest of the Threat Detection & Response team, Security organization, & our cross-functional partners across Engineering and Infrastructure.

What: A Staff Detection & Response Engineer role and an outstanding ability to operate with autonomy and ownership across the full detect-and-respond lifecycle.

When: ASAP! We are looking to hire and onboard a new hire as soon as we find the right person for the job. Exciting work awaits!

Where: Our office hub location of Palo Alto or NYC - you will be required to be in office 1+ days per week in alignment with our office work policy. This role is also eligible for 100% remote work.

Why: Were looking for a Detection & Response Engineer to join our Threat Detection & Response team. Youll build, tune, and maintain detection logic across a modern cloud-native security stack, investigate alerts and incidents end-to-end, and help mature our detection engineering and incident response capabilities.

How (to land the job!): Our interview process typically includes an initial recruiter conversation, a technical screening, and a series of interviews with team members to assess hands-on experience, problem-solving, and collaboration skills.

The day-to-day:

  • Author, test, and maintain detection logic as code across SIEM, EDR, and cloud platforms
  • Investigate security alerts, triage findings, and escalate as appropriate
  • Lead and participate in incident response as both responder and incident commander
  • Conduct threat hunts informed by emerging TTPs and threat intelligence
  • Build and improve automation to accelerate detection, triage, and response workflows
  • Contribute to runbooks, playbooks, and post-incident documentation
  • Collaborate with engineering and infrastructure teams to improve logging coverage and signal quality

Skills & qualities we value:

  • 4+ years in a detection engineering, SOC, or incident response role
  • Hands-on detection-as-code experience - writing, testing, versioning, and deploying custom detection rules in a CI/CD or Git-based workflow
  • Strong custom detection authoring across at least one SIEM platform (ES|QL, KQL, SPL, or similar query languages)
  • Demonstrated alert investigation and triage skills - comfortable working from raw logs to root cause
  • Incident response experience in both responder and commander capacities, including coordination, containment, and post-incident review
  • Intermediate or above programming proficiency in Python or Go - able to build tooling, parse data, and automate workflows
  • Engineering background in building, deploying, or maintaining security systems (log pipelines, detection infrastructure, integration work)
  • Familiarity with the MITRE ATT&CK framework for mapping detections and threat hunts to adversary TTPs
  • Experience with at least one EDR platform (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) - writing custom queries and hunting beyond built-in alerts
  • Threat hunting experience using hypothesis-driven, intelligence-driven, or anomaly-driven approaches
  • Security log pipeline experience - building or maintaining ingestion from diverse sources (cloud APIs, webhook integrations, custom parsers)
  • Version control and CI/CD fluency - Git workflows for detection content

Preferred experience:

  • Experience with AWS, Azure, and/or GCP security services and cloud-native logging (CloudTrail, Azure Activity Logs, GCP Audit Logs)
  • Elastic Security experience (detection rules, ES|QL, index and ingest pipeline familiarity)
  • Experience with identity-based attack detection (Entra ID, Okta, SSO/OIDC abuse patterns)
  • SOAR or security automation tooling experience - building response playbooks, enrichment workflows, or triage automation
  • API security monitoring or investigation experience
  • Exposure to Zero Trust architectures (Cloudflare, Zscaler, or similar)
  • Familiarity with threat intelligence platforms or feeds (MISP, OTX, abuse.ch)
  • Supply chain security awareness (npm, PyPI, container image compromise detection)
  • Strong written communication - able to produce clear incident reports, runbooks, and stakeholder updates

Perks & benefits you will love

Spotnana strives to offer fair, industry-competitive, and equitable compensation. Our approach assesses total compensation, including cash, annual performance bonus, company equity, and comprehensive benefits.

The base salary range for this role is $150,000 - $190,000 per year, depending on a number of factors including the candidate's working location.

We care for the people who make everything possible - our benefits include:

  • Pre-tax and ROTH 401(k) options via Fidelity with up to a 4% company match
  • Comprehensive benefit plans covering medical, dental, vision, life, and disability effective on your hire date. We cover 100% of your employee premiums and 85% of your eligible dependents
  • Pre-tax flexible spending account options for health, dependent care and commuter expenses
  • Flexible PTO in addition to 10 company holidays and an end-of-year company shutdown
  • Up to 26 weeks of parental leave
  • Monthly cell phone/internet stipend
  • Extra perks - IATAN travel membership, pet insurance, financial wellness tools, Calm app access, and more

Similar Jobs