
- B2B
- Scale StageRapidly increasing operations
- Top InvestorsThis company has received a significant amount of investment from top investors
- +2
Senior Detection and Response Engineer
- $175k – $240k
- |
- |Full Time
Not Available

About the job
About this role
As our first Detection & Response engineer, you'll build that capability from the ground up focused on our enterprise environment. Looking for and monitoring threats within identity systems our employees authenticate through, the laptops they work on, the SaaS applications that run the business, our enterprise network, and the internal infrastructure behind it. You'll decide what we monitor, build the pipelines and detections that monitor it, and write the playbooks we run when something fires. This is a zero-to-one role and it will suit someone who enjoys building with a lot of autonomy.
What You'll Do
- Shape the technical direction for detection and response at Faire. Define what good looks like, build the roadmap that gets us there, and make the case for the tooling and support it needs.
- Build detection engineering for Faire's enterprise environment end to end. Telemetry pipelines, detection content, alert routing, and enrichment.
- Bring a threat-informed point of view. Track how adversaries operate against companies like ours and translate that into detections, hunts, and tabletop exercises that test whether we'd catch it.
- Own detections and data pipelines written as IaaC.
- Automate triage, enrichment, and response so alert volume can grow without a proportional increase in analyst time.
- Work with IAM, CPE, NetEng, and IT Infrastructure Engineering to get the telemetry you need.
- Partner with Enterprise Security to translate detection findings into control improvements, and hand root causes to the teams that own them with enough context that they actually get fixed.
Qualifications
- Deep hands-on experience in detection engineering, incident response, or security operations, with a track record of building capability
- Depth in corporate attack surfaces such as identity providers and SSO, endpoint and EDR telemetry, email security, SaaS logs, device management signals, and corporate network access.
- Strong proficiency in Python and query language such as SQL.
- The ability to build and maintain detection-as-code pipelines yourself rather than specify them for someone else to build.
- Practical experience with SIEM, EDR, and security analytics platforms
- Investigative depth on endpoints and in cloud and SaaS environments, so you can reconstruct what happened across an IdP, a laptop, and a SaaS admin console, and say what you know versus what you're inferring.
- Excellent written communication and a collaborative approach to influence. You'll explain to engineers why a detection matters and to leadership what an incident actually means.
- Bonus points for experience as a founding security hire, insider threat or data loss detection, an offensive security background against corporate identity and endpoint paths, incident commander experience, endpoint or cloud forensics depth, or a clear view on what belongs in a SIEM versus a data warehouse.
Salary Range
San Francisco: the pay range for this role is $174,500 to $240,000 per year.
This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.
About the company
- B2B
- Scale StageRapidly increasing operations
- Top InvestorsThis company has received a significant amount of investment from top investors
- YC FundedStartup funded by Y Combinator
- Valuation $1B+This company has a valuation of $1B or more
Similar Jobs








