Applied Methods
~The MetaSecurityDetection & Incident Response

Detection & Incident Response

Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
Open Jobs59
Companies Hiring25
$02

Skills

What companies are looking for in this role.

$ skills --core

Investigating security incidents including indicators of compromise, malware, phishing, and unauthorized access

95%

Monitoring and triaging security alerts across multiple systems and data sources in real-time

95%

Escalating and coordinating incident response across security and infrastructure teams

90%

Conducting threat hunting missions to identify malicious activity across infrastructure

85%

Managing and supporting security tools including SIEM, EDR, and intrusion detection systems

85%

Conducting threat intelligence research on threat actors, campaigns, tactics, and procedures

85%

Designing and implementing detection rules and custom security detections

85%

Developing incident response playbooks, runbooks, and standard operating procedures

80%

Performing post-incident reviews and providing recommendations for security improvements

80%

Performing technical analysis of malware, infrastructure, and attacker tooling

80%
$ skills --emerging

Designing and developing automation workflows to reduce manual security processes

80%

Building and maintaining threat intelligence tooling and automated pipelines

70%

Building and deploying AI agents for autonomous alert triage and investigation

65%

Developing telemetry architecture and security data foundations across multiple domains

60%

Identifying and implementing AI-specific threat detection for model extraction and data poisoning

55%

Designing detection strategies for attacks targeting distributed AI infrastructure and GPU clusters

50%
$ skills --soft

Working collaboratively across multiple teams including infrastructure, product, and research

85%

Communicating technical security findings clearly to non-technical stakeholders and leadership

80%

Continuously improving processes, procedures, and detection quality through iterative refinement

75%

Taking ownership and demonstrating initiative in ambiguous problem spaces

70%

Mentoring and guiding junior security engineers and operators

65%

Managing relationships with external security vendors and managed service providers

60%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonhigh
Bashmoderate
SQLmoderate
$ tech --framework
n8nlow
$ tech --platform
Cloud infrastructurehigh
Active Directorymoderate
Kubernetesmoderate
Linuxmoderate
SaaS platformsmoderate
Windowsmoderate
GPU clusterslow
macOSlow
$ tech --tool
EDRvery high
SIEMvery high
SOARmoderate
Claude AIlow
$ tech --concept
REST APIhigh
MITRE ATT&CKmoderate
OSINTmoderate
Webhooksmoderate
Kerberoslow
MDRlow
$04

Open Jobs

59 open Detection & Incident Response jobs across 25 companies.

Anthropic1w
Security Engineer, Detection & Response
San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC·Security
True Anomaly1w
Senior Security Engineer, Threat Detection & Response
Denver, CO or Long Beach, CA·Security
Scale AI1w
Security Engineer, Detection & Response
New York, NY; San Francisco, CA; Seattle, WA; Washington, DC·Security
Nabla1w
Senior Security Engineer
Paris office·Security
Databricks1w
Sr. Staff Security Assurance Engineer
Mountain View, California; San Francisco, California·Security
Serval1w
Security Engineer, Detection and Response
San Francisco·Security
Anthropic1w
Senior/Staff Security Engineer, Threat Intelligence
Zürich, CH·Security
Artemis Security2w
Security Analyst
New York City·Security
Notion2w
Security Engineer, Detection and Response
San Francisco, California·Security
Crusoe2w
Senior Security Engineer, Detection and Response
Dublin - IE·Security
Figma2w
Manager, Security Operations
San Francisco, CA • New York, NY • United States·Security
xAI3w
Security Engineer - Detection & Response
New York, NY; Palo Alto, CA·Security
OpenAI3w
Technical Threat Investigator, Threat Intel Engineering - UK
London, UK·Security
xAI1mo
Security Engineer - Detection & Response (Japan)
Tokyo, JP·Security
Block1mo
Security Engineer, Detection & Response - Monitoring & Triage
Melbourne, Australia·Security
Nebius1mo
Security Automation Engineer (SOAR)
Israel·Security
Nscale1mo
Staff Security Engineer - Security Data, Detection and Automation
AMER·Security
True Anomaly1mo
Threat Detection & Response Engineer III
Denver, CO or Long Beach, CA·Security
Atlan1mo
SOC Lead - Detection & Response
India·Security
Writer1mo
Security engineer, detection and response
US-Office Hubs·Security