freehire launches on Product Hunt on 26 August.

Follow →

Staff Information Security Engineer - Threat Detection & Response

Open 31d posting dated 2 weeks ago

Summary

Senior security engineer designs and runs threat detection pipelines, writes high-fidelity detections, and leads incident response for a multi-cloud SaaS platform handling sensitive HR data.

Visier is the global leader in Workforce Intelligence that powers every people decision. We bring Workforce AI to life for HR departments through our award-winning, agentic AI technology by surfacing the insights leaders need to plan, decide, and act with confidence in the moments that matter most. As the market leader in people analytics, workforce planning, organizational design, and manager effectiveness solutions, we fuel smarter decision-making for organizations across the globe. Our mission is to help businesses lead with insight at scale as they continuously transform.

Founded in 2010 by the pioneers of business intelligence, we have over 85,000 customers in 75 countries—including enterprises like BASF, Panasonic, Domino’s Pizza, Experian, Amgen, eBay, and Ford Motor Company.

Position Overview This senior technical IC role owns Visier’s threat detection and response capabilities end-to-end—driving the overarching strategy, tooling engineering, detection content, and incident response processes. Operating within a high-leverage team, you will scale our security capabilities through advanced engineering and AI, directly safeguarding our multi-cloud platform, corporate identity, and sensitive customer data from sophisticated global threats. Your work will ensure our defensive posture continuously evolves ahead of the threat landscape.

Bring your 8+ years of deep information security expertise, mastery of modern SIEM architectures, and calm incident command experience to a team where you will operate with high autonomy. You will leverage your technical depth to champion engineering-first security practices, safely adopt generative AI workflows, and mentor peers to elevate our collective defense.

What you’ll deliver:

  • End-to-End Pipeline Resilience: Design and operate a cohesive detection pipeline spanning multi-cloud, SaaS, identity, and endpoint telemetry to eliminate visibility gaps and ensure comprehensive logging infrastructure.
  • Proactive Detection Engineering: Build, test, and tune high-fidelity detections using a modern detection-as-code framework mapped to the MITRE ATT&CK matrix, drastically minimizing false positives while prioritizing critical threat coverage.
  • Incident Lifecycle Ownership: Author robust playbooks, runbooks, and escalation criteria that define how Visier handles security incidents, ensuring immediate containment during major events.
  • Continuous Defensive Evolution: Lead blameless post-incident reviews and seamlessly translate post-mortem findings into automated detections and architectural hardening requirements.
  • Cross-Functional Security Integration: Partner closely with software developers, SREs, and offensive security functions to convert emerging vulnerabilities and organization-specific risks into highly targeted defensive rules.
  • AI-Accelerated Operations: Securely integrate and pioneer the use of Generative AI tools to accelerate detection development, alert triage, telemetry enrichment, and automated responses.

What You’ll Bring to the Table

  • Education & Experience: 8+ years of hands-on experience in information security, with a proven track record of designing, owning, and scaling threat detection architectures or major incident response programs.
  • Detection-as-Code Mastery: Expert-level detection engineering skills utilizing modern SIEM environments (Splunk Enterprise Security preferred) alongside fluent structural mapping to the MITRE ATT&CK framework.
  • Cloud & Infrastructure Fluency: Deep technical experience analyzing and building threat coverages across enterprise multi-cloud environments (AWS, Azure, or GCP), core identity providers, and endpoint/EDR telemetry.
  • Incident Command Presence: Proven experience acting as an Incident Commander, successfully steering cross-functional technical teams through high-pressure, complex, and high-visibility security incidents.
  • Security Automation & Scripting: Strong hands-on coding proficiency (Python, Go, or Bash) to build resilient automation pipelines, data enrichments, and automated response playbooks.
  • Strategic Communication: Exceptional ability to translate deeply technical indicators of compromise and complex security risks into clear, high-level business insights for executive stakeholders.

🌱 Most importantly, you share our values…

  • You roll up your sleeves
  • You make it easy
  • You are proud
  • You never stop learning
  • You play to win

🚀 How we work & what we offer...

  • Fixed hybrid work model: 3 days a week in office (Tuesday, Wednesday, Thursday)
  • Modern, pet-friendly downtown office spaces with collaborative areas and an on-site gym
  • Annual company All Hands in Vancouver, our entire organization travels to our Vancouver HQ for a week of team building, learning and breakout sessions
  • Competitive salary, and top-tier health and wellness benefits
  • Stock options and/or bonus based on your role, location, and employment type
  • Generous paid time off, including volunteering days and extra days over the December holidays

The base pay range for this position in the 130,000 - 170,000 /year + bonus

Benefits and working arrangements may vary depending on your seniority, location and employment type. The compensation offered will be determined by factors such as relevant qualifications, experience, knowledge and skills. Many of our positions are eligible for additional types of compensation (e.g., commission plans, bonus, etc.) which our Talent Acquisition team will share with you if you interview for the role.

Instagram - @visier_inc

Linkedin - https://www.linkedin.com/company/visier-analytics/

Visier Candidate Privacy Notice and Recruiter Policy

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter

  • Preferred First Name
  • Pronouns choose one · optional
  • If selected self-describe for Pronouns, please specify optional
  • LinkedIn Profile optional
  • How did you hear about us? Please specify choose one
  • Are you legally eligible to work in the location this position is based? choose one
  • Address
  • City
  • Province/State
  • Country
  • What is the single most complex project you owned in your last role? written answer · optional
  • If you don't live in Vancouver, would you be willing to relocate with no support? optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available