CronJobs

security jobs

Staff Security Engineer, Detection & Response

Maven Clinic · New York, NY; Remote, US (Hub cities)

remotesenior$221,000–$299,000Posted Sep 25, 2026SIEMthreat modelingSDLCLLMsprompt injection

Apply on the employer site

About this role

**Maven Clinic — Staff Security Engineer, Detection & Response** ## About the Role Own Maven Clinic’s Incident Detection and Response program—leading threat modeling across systems and code, directing investigations when incidents occur, and proactively finding bugs and SDLC gaps before they become incidents. You’ll also help manage the security risks introduced by growing reliance on LLMs, AI-generated code, and agentic tooling. ## What You’ll Own ### Investigation & Technical Direction - Lead investigations hands-on: pull logs, build the incident narrative, and advise business and engineering leaders on next steps. - Read production code when needed to understand what’s actually happening. ### Proactive Hunting & SDLC Hardening - Hunt for bugs in the codebase and weaknesses in the SDLC where issues can slip past existing controls. - Propose and implement fixes yourself, or manage resolution with the right teams (code fixes, process changes, or control updates). - Partner with the Product Security Engineer on “golden paths” when weaknesses point to systemic gaps. ### Detection Engineering - Own and tune detection logic running through 7AI: validate investigations/escalations and define alert-trigger criteria. - Close gaps in logging and visibility so tooling has the right data. ### Managing AI Risk - Help understand and manage security risks from Maven’s use of LLMs and AI tooling—both in what you build and what you adopt internally. ## What We’re Looking For ### Required - 6+ years of security experience combining hands-on software/AppSec depth with detection and SIEM engineering ownership. - Ability to read production code across multiple languages/stacks and judge whether findings are truly exploitable. - Experience building threat models (attack surface, trust boundaries, data flow) to anticipate where problems will emerge. - Track record of finding and fixing systemic weaknesses (incident-driven or proactive). - Strong communication skills with credibility to direct investigations and influence peers informally. ### Strongly Preferred - Hands-on experience with AI-assisted security operations tooling (AI SOC platforms, LLM-based triage, agentic escalation systems). - Interest/experience securing AI and LLM-powered systems (e.g., prompt injection, model misuse, agent tool abuse). - Exposure to golden-path or secure-by-default infrastructure initiatives. - Experience with container/image security and the patching lifecycle. - Relevant certification such as GCIH, GCFA, GCDA, OSCP, or CISSP. ## Compensation & Work Model - Base salary range: **$221,000 – $299,000/year** (equity and benefits also included). - Maven uses a flexible hybrid model. Teams primarily operate from the **New York Metropolitan area**, with remote options via **San Francisco/Bay Area, Seattle, WA**. - For NYC: work onsite **three days/week (Tue/Wed/Thu)**. - For Boston, DC, Chicago, Seattle, and San Francisco: attend **monthly Work Together Days** in those cities. ## Benefits (Highlights) - Maven for Mavens (access to platform specialists, including mental health, reproductive health, family planning, pediatrics) - Wellness partnerships - Hybrid work support (in-office meals + work together days) - **16 weeks 100% paid parental leave** + new parent stipend (1 year+) - Annual professional development stipend + access to a personal career coach - 401(k) matching for US-based employees (immediate vesting) ## Notes - Maven is an affirmative action and equal

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord