Ovii Job Board

Senior Security Engineer, Detection and Response

hackerone

Austin, United States • Remote - Austin, United States • Full-Time • 5+ years

Posted 2026-04-21 USD 182,000 - USD 202,000 per year Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

The Senior Security Engineer, Detection & Response builds AI‑first detection‑as‑code and automated response tooling for HackerOne’s cloud‑native platform. The role blends security engineering, software development, and incident response to protect large‑scale cloud, SaaS, endpoint, and identity environments.

Role Snapshot

  • Design detection‑as‑code across cloud, SaaS, endpoints, and identity
  • Build AI/LLM‑powered investigation and response automation
  • Lead incident response from detection through remediation
  • Partner with engineering teams to improve observability and logging
  • Analyze and tune detection performance using data‑driven methods
  • Identify visibility gaps and create concrete detection solutions

Must-Have Requirements

  • Python
  • Go
  • Ruby
  • AWS
  • CloudTrail
  • GuardDuty
  • VPC flow logs
  • Datadog
  • Splunk
  • ELK
  • SentinelOne
  • CrowdStrike
  • detection and response
  • security engineering
  • software engineering with security focus
  • Visa/work permit sponsorship is not available
  • Background check required

Nice-to-Have Signals

  • AI/LLM security tooling
  • Detection-as-code frameworks
  • Docker
  • Kubernetes
  • ECS/EKS
  • Threat intelligence
  • MITRE ATT&CK
  • detection-as-code frameworks
  • containerized environments
  • threat intelligence and hunting

Work Setup

  • Location: Austin, United States
  • Work mode: REMOTE
  • Remote scope: COUNTRY_RESTRICTED
  • Remote countries: United States
  • Employment type: Full-Time

Eligibility Gates

  • Work authorization: must be authorized to work in the United States
  • Visa sponsorship: no
  • Background check: required

Not Specified in JD

  • Salary range
  • Travel requirements
  • Security clearance

What You'll Likely Work On

  • Create and maintain detection‑as‑code rules for cloud infrastructure, SaaS apps, endpoints, and identity systems
  • Automate investigation and containment workflows, replacing manual runbooks with AI‑first solutions
  • Develop AI/LLM‑driven tools to reduce alert fatigue and accelerate incident triage
  • Lead and participate in full‑cycle incident response, including post‑mortem analysis
  • Collaborate with platform engineers to expand logging, improve observability, and embed detections in the development lifecycle
  • Continuously evaluate alert performance, tune signal quality, and close feedback loops between incidents and detections
  • Proactively discover gaps in coverage and translate ambiguous problems into concrete detection solutions
  • Adapt quickly to evolving threats and tooling, maintaining momentum through change agility

Good Fit If You Have

  • Enjoys building automation and AI‑driven security tooling
  • Thrives in fast‑paced environments that require first‑principles problem solving
  • Effective cross‑functional collaborator with engineering and platform teams

Skills

  • Python / Go / Ruby
  • AWS cloud services (CloudTrail, GuardDuty, VPC flow logs)
  • Log aggregation platforms (Datadog, Splunk, ELK)
  • Endpoint detection tools (SentinelOne, CrowdStrike)
  • AI/LLM security tooling
  • Detection‑as‑code frameworks
  • Container platforms (Docker, Kubernetes, ECS/EKS)
  • Threat intelligence & MITRE ATT&CK

Remote Eligibility

  • United States
  • Austin
  • Seattle
  • San Francisco
  • Washington DC
  • Boston