Applied Methods
~metaSecurityDetection & Incident Response

Detection & Incident Response

Builds detection systems, investigates security incidents, and leads incident response efforts.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
51open jobs
20companies hiring
$02

Skills

What companies are looking for in this role.

$ skills --core

Designing and implementing security information and event management platforms and infrastructure

95%

Developing detection rules, correlation logic, and alert mechanisms to identify security threats

92%

Monitoring security alerts and events across multiple platforms and data sources

90%

Analyzing security incidents and conducting root cause analysis

89%

Coordinating security incident response and serving as incident commander

88%

Conducting threat hunting and proactive threat identification activities

87%

Managing and leading security operations center teams and analysts

85%

Researching and tracking threat actors, campaigns, and attack techniques

85%

Building and maintaining incident response playbooks and runbooks

83%

Translating threat intelligence into actionable detections and defense improvements

83%

Designing log ingestion pipelines, normalization, and enrichment processes

82%

Building data pipelines and telemetry collection systems for security analysis

80%

Integrating and managing multiple security tools and third-party applications

78%

Operating endpoint detection and response systems across diverse environments

76%

Writing production-quality code and developing security tooling

75%

Assessing security configurations and managing security state

73%

Managing alert fatigue and optimizing alerting systems for high-volume environments

70%

Performing digital forensics and memory forensics investigations

65%
$ skills --emerging

Developing and deploying automation and orchestration workflows for security response

79%

Building detection systems using artificial intelligence and machine learning techniques

71%

Designing containment mechanisms and entity-tracking systems across heterogeneous environments

68%

Developing and operating deception detection systems such as honeypots and canary systems

62%

Detecting and mitigating risks from autonomous AI agents and agentic systems

58%
$ skills --soft

Collaborating across cross-functional teams to improve security posture

87%

Communicating complex security concepts clearly to stakeholders at all levels

84%

Leading and managing incident response teams during crises

82%

Driving continuous improvement and automation of security processes

81%

Mentoring and providing technical guidance to junior security personnel

80%

Developing team members and coaching personnel for career growth

76%

Navigating complex organizational environments and driving strategic change

75%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonvery high
Gohigh
$ tech --framework
dbtlow
MCP serverslow
$ tech --platform
AWSvery high
Azurehigh
GCPhigh
Kuberneteshigh
Elasticsearchmoderate
GitHubmoderate
Google Workspacemoderate
Office 365moderate
Claudelow
OpenAIlow
$ tech --tool
EDR/XDRvery high
SIEMvery high
Githigh
SOARhigh
ArgoCDmoderate
Criblmoderate
Splunkmoderate
Terraformmoderate
VirusTotalmoderate
YARAmoderate
BindPlanelow
Censyslow
Geneteclow
Jenkinslow
Urlscanlow
$ tech --concept
FedRAMPlow
$04

Open Jobs

51 open Detection & Incident Response jobs across 20 companies.

Databricks2d
Senior Security Engineer, Incident Response
Amsterdam, Netherlands; Berlin, Germany; London, United Kingdom; Remote - Denmark; Remote - France; Remote - Germany; Remote - Italy; Remote - Spain; Remote - Sweden·Security
Abnormal Security3d
Sr. Embedded Detection Analyst
Remote - USA·Security
Harvey3d
Detection & Response Security Engineer
San Francisco·Security
Abnormal Security4d
Email Security Analyst
Remote - UK·Security
Nebius1w
SIEM Engineers Lead
Tel Aviv, Israel·Security
Nebius1w
Security Operations Center (SOC) Manager
Tel Aviv, Israel·Security
CoreWeave1w
Senior Security Engineer, Threat Intelligence
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA·Security
Databricks1w
Staff Security Software Engineer
United States·Security
Reflection1w
Member of Technical Staff - Incident Detection & Response
New York·Security
Nebius1w
Security Operations Center Analyst
Amsterdam, Netherlands·Security
Nscale1w
Staff Security Engineer, Threat Intelligence
AMER·Security
Nscale1w
Staff Security Engineer, Detection Platform
AMER·Security
Nscale1w
Manager, Security Operations
AMER·Security
Waymo1w
Security Operations Center Watch Lead
Phoenix, AZ, USA·Security
Nscale1w
Security Incident Response Lead
AMER·Security
CoreWeave1w
Staff Security Engineer, SOAR
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA·Security
CoreWeave1w
Senior Security Engineer, SOAR
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA·Security
Anthropic2w
Threat Collections Engineer
Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC·Security
xAI2w
Security Engineer - Detection & Response
New York, NY; Palo Alto, CA·Security
xAI2w
SOC Manager
Palo Alto, CA·Security