← Back to job listings
EN
Member of Technical Staff (SecOps & Threat Detection Engineer)
Envoy · San Francisco, United States
About The Role
Join our team as a Member of Technical Staff (SecOps & Threat Detection Engineer) at an L5 level. In this role, you will lead the shift towards a proactive security posture, focusing on threat detection, visibility, and automation. You will define our detection strategy, improve our SIEM and monitoring architecture, and drive visibility across all critical assets. Additionally, you will mentor and guide other engineers, raising the overall capability of the team in detection and security operations.
- Ownership and evolution of Security Operations and Threat Detection capabilities, including defining detection strategy across cloud infrastructure, applications, and endpoints.
- Establishment and improvement of SIEM and monitoring architecture, including signal quality, coverage, and scalability, and driving visibility across all critical assets.
- Leading investigations into complex or ambiguous security signals, setting the standard for root cause analysis and response, and defining and tracking key metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- 10+ years of experience in Security Engineering, SRE, or Infrastructure Engineering with a strong security focus
- Experience working with endpoint detection and response tools such as SentinelOne or similar
- A pragmatic, outcome-oriented mindset focused on reducing real risk and improving operational effectiveness
- Ability to operate in ambiguous environments and define structure where none exists
- Strong understanding of cloud environments (ideally AWS), including IAM, networking, and logging at scale
- Experience defining alerting models and reducing noise while maintaining strong coverage
- Deep experience working with logs, events, and telemetry to build meaningful, high-signal detections
- Proven experience designing or significantly improving security monitoring, detection, or SIEM systems
- Strong cross-functional communication skills, with the ability to influence engineering and leadership
- A strong understanding of attacker behavior and the ability to translate threats into detection strategies
- Strong programming or scripting skills (Python, Go, or similar), with a focus on automation and system design
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring