Skip to content
← Back to job listings

Detection and Response Engineer

modal · New York

External listingfull-time18 days ago

About The Role

About Us:AI needs a new infrastructure layer. We're building it at Modal.Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.Our customers include category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September.Our team includes creators of popular open-source projects (e.g.,Seaborn,Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.The Role:We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform.This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational <effectiveness.You>'ll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.What You'll Work On:Detection EngineeringDesign and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systemsContinuously improve detections based on telemetry, threat intelligence, and lessons learned from incidentsImprove visibility across cloud infrastructure, containers, identity systems, and production servicesIncident ResponseLead or participate in investigations spanning production infrastructure, cloud environments, and internal systemsBuild playbooks and automation that reduce investigation time and improve response consistencyDrive post-incident improvements that eliminate entire classes of future incidentsSecurity Tooling & AutomationBuild internal tooling that improves detection, investigation, and response workflowsLeverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetryImprove the collection, quality, and usability of security telemetry across the platformEngineering PartnershipPartner with engineering teams to ensure new systems are observable and secure by defaultHelp teams instrument services with the telemetry needed for effective detection and responseDrive security improvements that make the platform easier to defend over timeWhat We're Looking For:Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focusStrong software engineering skills with experience building production systemsExperience investigating security incidents in cloud-native or distributed environmentsFamiliarity with modern cloud infrastructure, Kubernetes, Linux, and networkingExperience building detections using logs, telemetry, behavioral signals, or large-scale event dataStrong SQL skills for investigating security events and developing detectionsInterest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systemsStrong written and verbal communication skillsPreferred Qualifications:Experience building AI- or LLM-powered security toolingExperience with SIEM, SOAR, or EDR platformsExperience with Kubernetes security or large-scale cloud infrastructureExperience with threat hunting, malware analysis, or digital forensicsExperience contributing to security operations in a high-growth engineering organization

This is an external listing. JobSpring does not represent or verify the employer. Report this listing