Applied Methods
~The MetaSecurityDetection & Incident Response

Detection & Incident Response

Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
Open Jobs61
Companies Hiring21
$02

Skills

What companies are looking for in this role.

$ skills --core

Conducting end-to-end investigations into sophisticated threat actors and their infrastructure, behavior, and tactics

95%

Designing and implementing detection logic and rules across cloud, endpoint, and enterprise environments

92%

Analyzing and responding to security incidents with root cause analysis and forensic investigation

90%

Building automation, scripts, and orchestration workflows to reduce manual security operations work

88%

Threat hunting to proactively identify malicious activity and adversarial patterns

87%

Developing and maintaining telemetry pipelines, data normalization, and enrichment processes

85%

Analyzing malware, phishing infrastructure, and attacker tooling to extract indicators and tactics

82%

Translating security findings into durable engineering solutions and systemic improvements

81%

Writing production-quality code for detection systems with version control and testing

80%

Researching and tracking threat actors, campaigns, and emerging attack techniques

80%

Modeling attacker behavior and anticipating misuse patterns

78%

Leveraging open source intelligence and vendor threat data for investigation and detection

76%

Tuning detection rules and correlation models to maximize signal-to-noise ratios

75%

Building and tuning data loss prevention policies and behavioral detection models

75%

Conducting insider risk investigations combining technical analysis and human interviews

72%

Managing and operating security information and event management platforms

72%

Identifying and closing gaps in detection coverage and telemetry

72%

Leading incident response coordination across multiple teams and stakeholders

70%

Designing hardening strategies and defensive controls across infrastructure

70%

Developing incident response playbooks and runbooks for common attack scenarios

70%

Performing technical analysis of logs from security monitoring systems

70%

Performing digital forensics to determine timeline and impact of security events

68%

Triaging security alerts and determining incident severity and response priority

68%

Reverse-engineering novel attack mechanisms and persistence techniques

65%
$ skills --emerging

Leveraging AI and machine learning to accelerate investigation workflows and automate analysis

68%

Designing detection strategies for AI-specific threats including prompt injection and model extraction

65%

Building agentic systems and autonomous capabilities for security operations

55%
$ skills --soft

Collaborating cross-functionally with product, engineering, and policy teams on security improvements

78%

Communicating technical security findings to both technical and non-technical stakeholders

75%

Mentoring junior security responders and team members

62%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonhigh
SQLhigh
Bashmoderate
$ tech --platform
Active Directoryhigh
AWShigh
GCPhigh
Windowshigh
Azuremoderate
Kubernetesmoderate
Linuxmoderate
Palantirmoderate
$ tech --tool
DLPhigh
Splunkhigh
Claudemoderate
Datadogmoderate
Elasticsearchmoderate
Gitmoderate
SOARmoderate
UEBAmoderate
YARAmoderate
Jiralow
MCPlow
Oktalow
Slacklow
Terraformlow
$ tech --concept
Detection as Codehigh
JSONmoderate
Kerberosmoderate
LLMmoderate
REST APImoderate
$04

Open Jobs

61 open Detection & Incident Response jobs across 21 companies.

xAI6d
Security Engineer - Detection & Response (Japan)
Tokyo, JP·Security
Block1w
Security Engineer, Detection & Response - Monitoring & Triage
Melbourne, Australia·Security
Nebius1w
Threat Intelligence Expert
Tel Aviv, Israel·Security
Nebius1w
Security Automation Engineer (SOAR)
Israel·Security
Nscale1w
Staff Security Engineer - Security Data, Detection and Automation
AMER·Security
CoreWeave1w
Security Operations Engineer
Livingston, NJ·Security
Atlan2w
SOC Lead - Detection & Response
India·Security
Writer2w
Security engineer, detection and response
San Francisco, CA·Security
Writer2w
Security engineer, detection and response (UK)
London, UK·Security
CoreWeave2w
Senior Security Engineer I, Advanced Response
Livingston, NJ / New York, NY / San Francisco, CA / Bellevue, WA·Security
Waymo2w
Security Operations Center Watch Lead
Phoenix, AZ, USA·Security
OpenAI3w
Technical Threat Investigator, Threat Intel Engineering
San Francisco·Security
OpenAI3w
Technical Threat Investigator, Threat Intel Engineering - UK
London, UK·Security
Abnormal Security4w
Sr. Embedded Detection Analyst
Remote - USA·Security
Anthropic1mo
Security Engineer - Threat Intel
New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY·Security
Palantir1mo
Information Security Engineer - Endpoint
New York, NY·Security
Palantir1mo
Information Security Engineer - Endpoint
Washington, D.C.·Security
Palantir1mo
Information Security Engineer - DLP
Washington, D.C.·Security
Palantir1mo
Information Security Engineer - DLP
New York, NY·Security
Anthropic1mo
Incident Manager - Detection & Response
Zürich, CH·Security