CronJobs

security jobs

Senior Security Engineer, Detection & Response

Aircallioinc · San Francisco Office; Seattle Office

unknownsenior$180,000–$180,000Posted Sep 10, 2026PythonTerraformAWSAzureGCPSIEMElasticsearchOpenSearch

Apply on the employer site

About this role

**Aircall — Senior Security Engineer, Detection & Response** Aircall is an AI-powered customer communications platform used by 22,000+ companies worldwide. We bring voice, SMS, WhatsApp, and AI into one seamless workspace—helping teams work smarter, resolve issues faster, and scale with confidence. --- ## About the Role As a **Senior Security Engineer (Detection & Response)**, you’ll **develop, scale, and evolve** Aircall’s threat detection and response capabilities. This is an **owner-operator** role: you won’t just respond to alerts—you’ll **build and run** the system end to end, including: - **Ingestion pipelines** - **Terraform** across sandbox, staging, and production AWS accounts - **Retention and cost posture** - **Automation layered on top** Expect roughly **two-thirds software/platform engineering** and **one-third investigation, incident response, and threat hunting**. You’ll write **production Python and Terraform weekly**, partnering closely with product security, cloud, and infrastructure security. --- ## Responsibilities - Lead direction and strategy of the **DART** program at Aircall - Own end-to-end development of detection logic (threat modeling → writing/testing/simulation/tuning → deployment) - Own the security data platform end to end (SIEM, ingestion pipelines, parsers, enrichment/normalization as IaC) - Operate and extend the SIEM, including **cost/capacity** and **retention vs. spend** decisions - Experiment and build unique tools to solve significant security challenges - Expand and ship **AI/agent-based tooling** for alert triage, investigation, and detection building (auth model, guardrails, evaluation harness, tracing) - Conduct proactive **threat hunts** in company-wide and production environments - Lead incident response: investigate, contain, remediate, perform root cause analysis, and feed lessons learned back into detections - Assess security for new product features (including AI/LLM-backed services) and identify detection/protection opportunities - Author and maintain detection documentation, runbooks, alert definitions, tuning guidelines, and metrics - Collaborate cross-functionally with Engineering, Product, Fraud, Privacy, and Legal - Participate in on-call and threat-response rotations; escalate, coordinate, and remove blockers during high-severity events - Stay current on attacker techniques (e.g., **MITRE ATT&CK**, red team reports, threat intel) and propose new detection patterns/responses - Participate in hiring and interview evaluation for Security/Infrastructure engineering candidates --- ## Should Have - **5+ years** hands-on experience in security operations, detection engineering, incident response, threat hunting, or equivalent - **Production-grade Python and Terraform** (build detections and pipelines managed in code; own and maintain production services/modules) - Deep knowledge of adversarial tactics/techniques/procedures and threat actor behavior (**ATT&CK**) - Proven ability to build detections from scratch (not just tune commercial alerts) with low false positives - Hands-on experience with SIEM/log analytics and data lake technologies (e.g., OpenSearch/Elasticsearch/ClickHouse/Splunk/Datadog/AWS Athena/Azure Synapse/Databricks or equivalent) - Cloud-first experience with **Azure, GCP, AWS**; strong AWS security infrastructure ownership (e.g., VPCs, IAM, networking, private service endpoints) - Experience with digital forensics, host-based detection, endpoint telemetry, proce

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord