
Staff Level - Detection & Response Engineer
San Francisco, CA · HybridContractSeen 1 day agoSeen in employer's feed 1 day ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Francisco, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
Insight Global seeks a Staff-level Detection & Response Engineer to mature detection engineering and incident response capabilities, develop custom detections, assess telemetry, lead investigations, act as Incident Commander, and shape security operations across cloud, endpoint, identity and application environments.
Skills & qualifications
Skills
Qualifications
Full job description
Job Description
TITLE: Staff level - Detection & Response Engineer TEAM: Cybersecurity LOCATION: San Francisco, CA SCHEDULE: Hybrid (Target 3 days onsite per week) WORK HOURS: Primarily 9:00 AM - 5:00 PM PT with occasional incident response coverage DURATION: 6+ Month Contract 2 Hire START DATE: ASAP
ABOUT THIS ROLE:
Insight Global is seeking a Detection & Response Engineer to help mature the client's detection engineering and incident response capabilities.
The ideal candidate is equally comfortable building custom detections as they are leading complex cybersecurity incidents. This role requires someone who can assess telemetry coverage, improve detection quality, build response playbooks, tune alerting logic, manage MDR relationships, and confidently act as incident commander during security events.
This is a Staff-level security engineering role. The team is looking for someone who can help define detection strategy, determine what threats matter most to the organization, evaluate whether telemetry exists to detect those threats, and build a sustainable detection and response program. Candidates should understand why a detection is being written and what attack behavior it is intended to identify, rather than simply creating alerts.
This is also the highest visibility role across the security organization. The individual will regularly engage with Engineering, Security, IT, leadership teams, and executive stakeholders during highly sensitive security incidents.
DAY-TO-DAY
- Develop and tune detections across a cloud-first technology stack
- Assess logging and telemetry coverage across endpoint, cloud, identity, and application environments
- Improve detection fidelity and reduce false positives
- Build threat-informed detection strategies
- Lead incident investigations from detection through remediation
- Act as Incident Commander during security events
- Create and improve response playbooks and operating procedures
- Conduct threat hunting activities
- Partner with MDR vendors including Red Canary
- Run tabletop exercises and incident simulations
- Help shape and scale the organization's security operations program
Skills and Requirements
Required Skills & Experience
- 8-12 years of Security Operations, Detection Engineering, Incident Response, Threat Hunting, or related experience
- Strong experience with EDR platforms such as CrowdStrike Falcon, Cortex XDR, SentinelOne, Microsoft Defender, Palo Alto Cortex, or similar
- Experience building and tuning custom detections
- Experience assessing telemetry coverage and detection gaps
- Experience tuning alert fidelity and reducing false positives
- Experience with SIEM environments and detection engineering workflows
- Strong threat hunting experience
- Strong incident response leadership experience
- Experience acting as Incident Commander or Incident Lead during security incidents
- Experience creating and improving incident response playbooks
- Experience with security telemetry architecture and logging strategy
- Understanding of MITRE ATT&CK Framework and threat-informed defense
- Strong stakeholder communication and executive-facing communication skills
Tech Stack
-
CrowdStrike Falcon (Preferred) or SentinelOne or Cortex XDR or Palo Alto Cortex or Microsoft Defender
-
Red Canary
-
AWS
-
Okta
-
SIEM Platforms
-
SOAR Platforms
-
Threat Intelligence Platforms Nice to Have Skills & Experience
-
MDR management experience
-
Security Automation
-
Python scripting
-
Threat Intelligence Programs
-
Tabletop Exercise Leadership
-
Cloud telemetry architecture experience
-
Detection coverage modeling experience
LOOKING FOR:
- Detection engineering ownership, not alert monitoring experience
- Incident leadership and incident response expertise
- Ability to determine what should be detected and why
- Telemetry strategy experience
- Strong stakeholder management and executive communication skills
- Program-level ownership and Staff/Principal-level thinking
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Staff Detection & Response EngineerKikoff · San Francisco, CA · $338–387K/yrPosted 3w agoPosted 3w ago
- Senior Manager, Detection and ResponseLambda · Bellevue, WA (Hybrid) · $324–480K/yrPosted 4w agoPosted 4w ago
Senior Security Engineer, Detection & ResponseBlock · CA · $218–327K/yrPosted 1 day agoPosted 1 day ago
Lead Security EngineerSalient · San Francisco, CA · $200–300K/yrPosted 1w agoPosted 1w ago
Staff Security Data EngineerAdobe · San Jose, CA · $159–302K/yrPosted 5 days agoPosted 5 days ago
You've read the whole posting — now see how you match it.