Senior Detection Engineer II

EngineersOfAI

Canada

Hybrid

CAD 181,000 - 250,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Instacart is seeking a Senior Detection Engineer II to join our Detection Engineering team, part of Security. You will architect high-fidelity detection logic across endpoint, cloud, container, and SaaS to surface threats in a scalable way.

Collaborate with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to translate attacker techniques into durable coverage, design SOAR playbooks, and mentor junior engineers in threat hunting and automation.

Qualifications

  • 6+ years of experience in detection engineering, incident response, or offensive security.
  • Experience with 1+ public cloud platforms (AWS/Azure/GCP).
  • Deep understanding of attacker TTPs and zero-trust environments.
  • Proficient understanding of macOS internals and related telemetry.
  • Experience implementing detection-as-code workflows (version control, automated testing, CI/CD).
  • Basic proficiency with Python, Golang, or similar languages.
  • Certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA or similar.

Responsibilities

  • Develop, tune, document, and maintain detection logic across endpoint, cloud, container, and SaaS sources.
  • Assist in cyber forensic investigations across log sources.
  • Optimize log ingestion pipelines and telemetry collection for high-quality data while managing volume and cost.
  • Design and build SOAR playbooks and automation workflows for detection triage and response.
  • Mentor junior analysts and detection engineers on threat hunting and investigation techniques.

Skills

Detection engineering experience
Incident response
Offensive security
Public cloud platforms
Attacker TTPs knowledge
macOS internals
Detection-as-code workflows
Python / Golang
CI/CD pipelines
Security certifications

Tools

Job description

We're transforming the grocery industry

At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.

Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.

Instacart is a Flex First team

There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work- whether it’s from home, an office, or your favorite coffee shop- while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.

Overview

Instacarts Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North America's largest grocery technology platforms. We own the full detection lifecycle, from telemetry collection and signal design to automated response, across a complex, cloud-native environment spanning endpoint, cloud, container, and SaaS.

As a Senior Detection Engineer II, you'll be a technical anchor on the team: developing high-fidelity detection logic, hunting for novel attacker techniques, and raising the bar for how we think about coverage, quality, and scale. You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure our detections reflect real-world adversary behavior; not just signatures.

We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed through repeatable pipelines. We care deeply about reducing noise, improving analyst efficiency through automation and SOAR, and continuously evolving our coverage as the threat landscape shifts.

If you're energized by hard forensic problems, enjoy translating attacker TTPs into durable detection logic, and want to help shape the future of a growing security function, this role is for you.

About the Job
  • Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
  • Assist in cyber forensic investigations across a variety of log sources
  • Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost
  • Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions
  • Mentor junior security analysts and detection engineers on threat hunting methodologies, detection logic development, and investigation techniques
About You

Minimum Qualifications

  • 6+ years of experience in a detection engineering, incident response, or offensive security role.
  • Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
  • Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries
  • Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
  • Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines
  • Basic proficiency with Python, Golang, or other programming languages
  • Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar

Preferred Qualifications

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection Engineer II
Detection Engineer II

EngineersOfAI • Canada

On-site
CAD 110,000 - 140,000
Remote Senior Detection Engineer II – Threat Hunting & SOAR
Remote Senior Detection Engineer II – Threat Hunting & SOAR

EngineersOfAI • Canada

Hybrid
CAD 181,000 - 250,000
Forward Deployed Engineer
Forward Deployed Engineer

EngineersOfAI • Canada

On-site
CAD 140,000 - 190,000
Flexible work arrangements
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Sobeys • Stellarton

On-site
CAD 110,000 - 170,000
Senior Data Engineer II, Finance
Senior Data Engineer II, Finance

EngineersOfAI • Canada

On-site
CAD 120,000 - 180,000
Senior Software Engineer - Core Experience, Growth
Senior Software Engineer - Core Experience, Growth

EngineersOfAI • Canada

On-site
CAD 90,000 - 140,000
Senior Engineering Manager, Activation & Engagement
Senior Engineering Manager, Activation & Engagement

EngineersOfAI • Canada

On-site
CAD 180,000 - 240,000
Senior Software Engineer II, Marketing Enablement & Technology
Senior Software Engineer II, Marketing Enablement & Technology

EngineersOfAI • Canada

On-site
CAD 140,000 - 190,000
Senior Machine Learning Engineer, Digital Twin Platform
Senior Machine Learning Engineer, Digital Twin Platform

EngineersOfAI • Canada

On-site
CAD 120,000 - 180,000
Senior Security Operations Analyst, Detection & Response
Senior Security Operations Analyst, Detection & Response

Financeit • Toronto

On-site
CAD 110,000 - 125,000
Hybrid workplace options
Competitive pay and bonus
RRSP matching
+3