Applied Methods
~The MetaSecurityDetection & Incident Response

Detection & Incident Response

Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
Open Jobs62
Companies Hiring22
$02

Skills

What companies are looking for in this role.

$ skills --core

Designing and implementing security information and event management platforms and infrastructure

95%

Developing detection rules, correlation logic, and alert mechanisms to identify security threats

92%

Monitoring security alerts and events across multiple platforms and data sources

90%

Analyzing security incidents and conducting root cause analysis

89%

Coordinating security incident response and serving as incident commander

88%

Conducting threat hunting and proactive threat identification activities

87%

Managing and leading security operations center teams and analysts

85%

Researching and tracking threat actors, campaigns, and attack techniques

85%

Building and maintaining incident response playbooks and runbooks

83%

Translating threat intelligence into actionable detections and defense improvements

83%

Designing log ingestion pipelines, normalization, and enrichment processes

82%

Building data pipelines and telemetry collection systems for security analysis

80%

Integrating and managing multiple security tools and third-party applications

78%

Operating endpoint detection and response systems across diverse environments

76%

Writing production-quality code and developing security tooling

75%

Assessing security configurations and managing security state

73%

Managing alert fatigue and optimizing alerting systems for high-volume environments

70%

Performing digital forensics and memory forensics investigations

65%
$ skills --emerging

Developing and deploying automation and orchestration workflows for security response

79%

Building detection systems using artificial intelligence and machine learning techniques

71%

Designing containment mechanisms and entity-tracking systems across heterogeneous environments

68%

Developing and operating deception detection systems such as honeypots and canary systems

62%

Detecting and mitigating risks from autonomous AI agents and agentic systems

58%
$ skills --soft

Collaborating across cross-functional teams to improve security posture

87%

Communicating complex security concepts clearly to stakeholders at all levels

84%

Leading and managing incident response teams during crises

82%

Driving continuous improvement and automation of security processes

81%

Mentoring and providing technical guidance to junior security personnel

80%

Developing team members and coaching personnel for career growth

76%

Navigating complex organizational environments and driving strategic change

75%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonvery high
Gohigh
$ tech --framework
dbtlow
MCP serverslow
$ tech --platform
AWSvery high
Azurehigh
GCPhigh
Kuberneteshigh
Elasticsearchmoderate
GitHubmoderate
Google Workspacemoderate
Office 365moderate
Claudelow
OpenAIlow
$ tech --tool
EDR/XDRvery high
SIEMvery high
Githigh
SOARhigh
ArgoCDmoderate
Criblmoderate
Splunkmoderate
Terraformmoderate
VirusTotalmoderate
YARAmoderate
BindPlanelow
Censyslow
Geneteclow
Jenkinslow
Urlscanlow
$ tech --concept
FedRAMPlow
$04

Open Jobs

62 open Detection & Incident Response jobs across 22 companies.

OpenAI5d
Technical Threat Investigator, Threat Intel Engineering
San Francisco·Security
OpenAI5d
Technical Threat Investigator, Threat Intel Engineering - UK
London, UK·Security
Abnormal Security1w
Sr. Embedded Detection Analyst
Remote - USA·Security
Anthropic2w
Security Engineer - Threat Intel
New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY·Security
CoreWeave2w
Senior Security Engineer, Insider Risk
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Franciso, CA·Security
Scale AI2w
Security Engineer, Detection & Response
New York, NY; San Francisco, CA; Seattle, WA; Washington, DC·Security
Writer2w
Security engineer, detection and response (US)
San Francisco, CA·Security
Palantir2w
Information Security Engineer - Endpoint
New York, NY·Security
Palantir2w
Information Security Engineer - Endpoint
Washington, D.C.·Security
Palantir3w
Information Security Engineer - DLP
Washington, D.C.·Security
Palantir3w
Information Security Engineer - DLP
New York, NY·Security
Writer3w
Security engineer, detection and response (UK)
London, UK·Security
Anthropic3w
Incident Manager - Detection & Response
Zürich, CH·Security
Crusoe3w
Staff Security Engineer
Dublin - IE·Security
Palantir3w
Information Security Engineer - Insider Risk
Seattle, WA·Security
Palantir3w
Information Security Engineer - Insider Risk
Washington, D.C.·Security
Palantir3w
Information Security Engineer - Insider Risk
New York, NY·Security
Gong3w
Senior Security Operations Engineer
Dublin·Security
Anthropic3w
Insider Risk Investigator - Technical & Human Intelligence
San Francisco, CA | New York City, NY | Seattle, WA·Security
Databricks3w
Senior Security Engineer, Incident Response
Amsterdam, Netherlands; Berlin, Germany; London, United Kingdom; Remote - Denmark; Remote - France; Remote - Germany; Remote - Italy; Remote - Spain; Remote - Sweden·Security