Applied Methods
~The MetaSecurityDetection & Incident Response

Detection & Incident Response

Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
Open Jobs53
Companies Hiring22
$02

Skills

What companies are looking for in this role.

$ skills --core

Investigating security incidents including indicators of compromise, malware, phishing, and unauthorized access

95%

Monitoring and triaging security alerts across multiple systems and data sources in real-time

95%

Escalating and coordinating incident response across security and infrastructure teams

90%

Conducting threat hunting missions to identify malicious activity across infrastructure

85%

Managing and supporting security tools including SIEM, EDR, and intrusion detection systems

85%

Conducting threat intelligence research on threat actors, campaigns, tactics, and procedures

85%

Designing and implementing detection rules and custom security detections

85%

Developing incident response playbooks, runbooks, and standard operating procedures

80%

Performing post-incident reviews and providing recommendations for security improvements

80%

Performing technical analysis of malware, infrastructure, and attacker tooling

80%
$ skills --emerging

Designing and developing automation workflows to reduce manual security processes

80%

Building and maintaining threat intelligence tooling and automated pipelines

70%

Building and deploying AI agents for autonomous alert triage and investigation

65%

Developing telemetry architecture and security data foundations across multiple domains

60%

Identifying and implementing AI-specific threat detection for model extraction and data poisoning

55%

Designing detection strategies for attacks targeting distributed AI infrastructure and GPU clusters

50%
$ skills --soft

Working collaboratively across multiple teams including infrastructure, product, and research

85%

Communicating technical security findings clearly to non-technical stakeholders and leadership

80%

Continuously improving processes, procedures, and detection quality through iterative refinement

75%

Taking ownership and demonstrating initiative in ambiguous problem spaces

70%

Mentoring and guiding junior security engineers and operators

65%

Managing relationships with external security vendors and managed service providers

60%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonhigh
Bashmoderate
SQLmoderate
$ tech --framework
n8nlow
$ tech --platform
Cloud infrastructurehigh
Active Directorymoderate
Kubernetesmoderate
Linuxmoderate
SaaS platformsmoderate
Windowsmoderate
GPU clusterslow
macOSlow
$ tech --tool
EDRvery high
SIEMvery high
SOARmoderate
Claude AIlow
$ tech --concept
REST APIhigh
MITRE ATT&CKmoderate
OSINTmoderate
Webhooksmoderate
Kerberoslow
MDRlow
$04

Open Jobs

53 open Detection & Incident Response jobs across 22 companies.

Modal4d
Detection and Response Engineer
New York·Security
Vanta1w
Manager, Security Operations
Remote U.S.·Security
Artemis Security1w
Detection Engineer
Remote·Security
Nebius1w
Security Analyst - Tier 3
Tel Aviv, Israel·Security
CHAOS Industries2w
Cybersecurity SOC Analyst II
London, England, United Kingdom·Security
Anthropic2w
Insider Risk Investigator
Boston, MA; New York City, NY; Washington, DC·Security
ElevenLabs2w
Detection Engineer
London·Security
Databricks2w
Sr Security Engineer, Incident Response
Switzerland·Security
Writer3w
Security engineer, detection and response (UK)
London, UK·Security
Writer3w
Security engineer, detection and response
San Francisco, CA·Security
ElevenLabs3w
Detection Engineer - APAC
Australia·Security
Scale AI4w
Security Engineer, Public Sector
New York, NY; St. Louis, MO; Washington, DC·Security
Nebius4w
Lead Detection Engineer
Israel·Security
Nebius1mo
Incident Response Lead
Israel·Security
Apollo1mo
Engineering Manager, Security Detection & Response
Remote, United States·Security
Nscale1mo
Security Response Engineer, Cyber Defense
New York; San Francisco; Seattle·Security
Harvey1mo
Detection & Response Security Engineer
New York·Security
Nebius1mo
Detection Engineering & Response Lead
Israel; Remote - Europe·Security
Artemis Security1mo
SOC Manager
New York City·Security
CHAOS Industries2mo
Cybersecurity SOC Analyst II
Washington, District of Columbia, United States·Security