freehire launches on Product Hunt on 26 August.

Follow →

Detection Engineering Lead

Open 27d posting dated 3 weeks ago

Summary

Leads the design and development of AI-driven detection content for cybersecurity, combining deep detection engineering expertise with product innovation to automate threat detection across SIEM, EDR, and cloud platforms.

About Dropzone AI

Dropzone’s mission is to scale cybersecurity beyond human limits, and augment every single human security engineer/analyst with an army of AI security specialists. Humans alone cannot sufficiently protect our digital future, and AI augmentation is the only way for defenders to reclaim the high ground. We are an award winning company disrupting the $200B+ cybersecurity market.

Powered by Gen AI advancements, our technology offloads repetitive day-to-day work and frees human analysts to focus on real threats and higher-value projects. We are venture-backed, and our team has a rare blend of deep experience across cybersecurity, AI/ML, and SaaS product development. Join us if you want to be on the ground floor of using Gen AI to transform cyber defense. Learn more at.

About the role

We're looking for a highly experienced Senior / Principal Detection Engineer to help shape the future of AI-driven security operations. This is a senior-to-principal level role for an individual who combines deep detection engineering expertise with a passion for innovation, customer impact, and advancing the state of security operations.

As the Detection Engineering Lead, you will serve as one of Dropzone AI's foremost experts in adversary tradecraft, threat detection, detection efficacy evaluation, and SIEM content. You will work closely with product management and engineering teams to ensure our AI detection engineer can draft new detection contents and improve existing detection rules as well as the best detection engineer on the planet.

This role is part of the R&D team and you will focus on building the best software that replicates your expert intuitions and techniques. This is not a service or consulting role and you will not be performing hands-on detection engineering service to our customers.

What you'll do

Detection Engineering Leadership

  • Reimagine how having unlimited detection engineering capacity could change Detection and Response teams and how future security practitioners interact with an AI detection engineer
  • Prototype, validate, and continuously improve an AI agent that programmatically generates detection content across diverse security environments.
  • Experiment autonomous agentic loops between detection engineering and other D&R functions such as threat intelligence and threat hunting

Product Development

  • Partner with engineering teams to encode expert detection knowledge into our product.
  • Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and SaaS security platforms.
  • Provide guidance on detection methodologies used by mature SOCs.
  • Establish best practices for detection quality, tuning, testing, and lifecycle management.
  • Influence product roadmap decisions based on customer and operational needs.

Threat Research & Innovation

  • Stay current on emerging threats, attacker techniques, and defensive strategies.
  • Conduct original research into detection opportunities and gaps.
  • Develop novel approaches for AI-assisted threat detection.

Requirements

  • 5+ years of experience in detection engineering.
  • Deep expertise with two or more major SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, Chronicle, Sumo Logic, etc.).
  • Strong understanding of endpoint, cloud, identity, network, and SaaS telemetry.
  • Expertise in MITRE ATT&CK, adversary emulation, and detection coverage analysis.
  • Experience building and tuning high-fidelity detections at scale.
  • Strong understanding of modern attacker tradecraft across Windows, Linux, cloud, identity, and SaaS environments.
  • Excellent communication skills with the ability to engage practitioners, executives, and customers.
  • Early-stage startup mindset. You thrive on ambiguity and move with lightspeed execution
  • Being data-driven is part of your DNA.

Preferred

  • Experience leading detection engineering programs at large complex environments.
  • Expertise with EDR platforms such as CrowdStrike, Microsoft Defender, SentinelOne, or Palo Alto Cortex XDR.
  • Experience with cloud security platforms including AWS, Azure, and GCP.
  • Familiarity with AI, machine learning, LLMs, or autonomous security workflows.
  • Experience contributing to open-source detection content (Sigma, YARA, Suricata, Zeek, etc.).
  • Public speaking, research publication, or conference presentation experience.

Work Environment/Travel

We are a 100% remote company where you will work from your home with company-provided equipment to set you up for success. Semi-frequent travel to professional office settings and other events locally and nationally; some overnight travel expected.

Compensation

In the spirit of pay transparency, we are excited to share the base salary range below, exclusive of fringe benefits or potential bonuses. If you are hired at Dropzone your final base salary compensation will be determined based on factors such as geographic location, skills, education, and/or experience. In addition, all compensation packages include significant above market new hire equity grants because we believe in rewarding long term value creation. If you are hired at Dropzone your final base salary compensation will be determined based on factors such as geographic location, skills, education, and/or experience. In addition to those factors, we believe in the importance of pay equity and consider internal equity of our current team members as a part of any final offer. Please keep in mind that hiring at the maximum of the range would not be typical to allow for future and continued salary growth. We also offer a generous benefits package, including company paid health insurance, 401K Plan with employer match, Self-Managed PTO, parental leave, and more.

The pay range for this role is:
$200,000$250,000 USD

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Preferred First Name optional
  • LinkedIn Profile optional
  • Website optional
  • Are you legally authorized to work in the United States? choose one
  • Do you now or in the future require any type of sponsorship to work in the United States? choose one
  • In what US state do you currently reside? choose one
  • What are you targeting in terms of a base salary?
  • Please list which SIEM platforms you would rate yourself as having deep expertise in. written answer
  • Policy on the Use of Artificial Intelligence (AI): At Dropzone, we require all job applicants to provide authentic, human-generated content throughout the entire application and interviewing process. The use of generative AI tools or AI assistance to create, draft, edit, or significantly modify application materials (including resumes, cover letters, writing and code samples, and answers to screening questions) or during any interview stage is strictly prohibited. This policy is in place to evaluate your non-AI-assisted communication skills, original thought, and genuine qualifications for the position. Acknowledgment and Agreement: By selecting "I Agree" below and submitting this application, I acknowledge that I have read and understood Dropzone's policy prohibiting the use of AI in the application and interviewing process. I attest that all materials submitted and all responses provided during the application and interview process are my own original work and were not generated or substantially assisted by any AI tool. I understand that if I have used AI in any part of the process, I am required to disclose the extent and nature of that use to Dropzone in advance. I further understand and agree that any failure to disclose the use of AI, or any violation of this policy, is a material misrepresentation and is grounds for immediate removal from consideration or, if hired, for immediate termination of employment, regardless of when the violation is discovered. choose one
  • I acknowledge that falsifying information during my application and interview process may result in exclusion from hire with Dropzone or employment termination. choose one

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available