Applied Cyber, Email Security (Detection Engineering)

Wilco

United States

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible PTO
Health benefits
Parental leave
Equity

Job summary

Doppel seeks a security-focused engineer to tackle email-borne threats on an AI-native defense platform. You will own detection problems from attacker techniques to production coverage, and use AI to automate investigations and evaluate model behavior.

You will collaborate with Product and Engineering on signals, validation, and customer-facing insights, translating threat intel into practical detections and platform capabilities that scale across customers.

Qualifications

  • Deep practitioner judgment in detection engineering, SOC/IR, threat intel/OSINT, or email security.
  • Ability to turn messy detection failures into data-backed root causes and durable fixes.
  • Think like attacker and defender across phishing, BEC, impersonation, credential theft.
  • Turn expert judgment into scalable detection logic, evaluations, tests, and requirements.
  • Comfort working across security, AI, product, and customer surfaces.

Responsibilities

  • Own detection problems end to end, from attacker techniques or false negatives through investigation and production coverage.
  • Use AI as a force multiplier: build evaluations, supervise model behavior, automate investigations.
  • Partner with Product and Engineering on signals, edge cases, and validation.
  • Work with customers and go-to-market teams to understand detection gaps and platform behavior.
  • Convert tooling, threat intel partnerships, and provider relationships into new signals and detection capabilities.

Skills

Detection engineering
SOC/IR
Threat intelligence/OSINT
Email security

Tools

SIEM tools
Threat intelligence tooling
Email security APIs
Microsoft 365/Exchange Online

Job description

Role overview

Investigate the hardest email-borne threats and detection failures on an AI-native social engineering defense platform, then turn what you learn into detections, evaluations, model behaviors, and product capabilities that scale across every customer. The work sits at the intersection of security research, applied AI, and product engineering.

Responsibilities
  • Own detection problems end to end, from emerging attacker techniques or false negatives through investigation, hypothesis, validation, production coverage, and ongoing measurement.
  • Use AI as a force multiplier: build evaluations, supervise model behavior, lean on coding agents, and automate repetitive investigative work.
  • Partner with Product and Engineering on signals, detection logic, edge cases, and validation.
  • Work with customers and go‑to‑market teams to understand detection gaps, real‑world tactics, and platform behavior.
  • Convert tooling, threat intelligence partnerships, and provider relationships into new signals and detection capabilities.
Requirements
  • Deep practitioner judgment in one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email and messaging security, with breadth across multiple areas viewed as a major plus.
  • Ability to take messy detection failures from "something feels off" to a clear root cause backed by data, and turn false positives and false negatives into durable fixes.
  • Ability to think like both attacker and defender across phishing, business email compromise, impersonation, credential theft, account takeover, and evolving social engineering tactics.
  • Track record of turning expert judgment into detection logic, evaluations, tests, and requirements that scale beyond a single investigation or customer.
  • Comfort working across security, AI, product, and customer surfaces, with the willingness to challenge assumptions and move quickly through ambiguity.
Nice to have
  • Hands‑on secure email gateway depth, including SPF, DKIM, DMARC, mail headers, mail flow, and sender identity.
  • Experience with Microsoft 365/Exchange Online, Google Workspace, or email security APIs.
  • Detection‑as‑code, evaluation datasets and labeling, model benchmarks, or LLM/ML security systems.
  • Experience building agentic security workflows, autonomous triage, or LLM evaluation systems.
  • Familiarity with agentic SOC concepts, SIEM and threat intelligence tooling, and threat intelligence provider relationships.
Benefits and work setup

Remote-first culture with flexible PTO, comprehensive health benefits, parental leave, meaningful equity, and a high-growth environment where work has immediate technical and customer impact. Compensation: $120,000-$180,000 OTE depending on location, experience, and demonstrated expertise.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Email Security Analyst (AI Operations)
Email Security Analyst (AI Operations)

AegisAI, Inc. • Northern (KY)

On-site
USD 90,000 - 130,000
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

samsara • United States

Hybrid
USD 150,000 - 190,000
Professional development stipend
Comprehensive health coverage
Parental leave plans
Cyber Defense Platforms Staff Engineer
Cyber Defense Platforms Staff Engineer

Scorpion Therapeutics • Cambridge (MA)

On-site
USD 170,000 - 230,000
Senior Threat Intelligence Researcher
Senior Threat Intelligence Researcher

Aegis AI Security • New York (NY)

On-site
USD 140,000 - 200,000
Cyber Defense Engineer
Cyber Defense Engineer

BeyondTrust, Inc. • United States

Remote
USD 87,000 - 134,000
Bupa healthcare
Parental leave
Employee Assistance Programme
+5
Applied Cyber, Email Security (Detection Engineering)
Applied Cyber, Email Security (Detection Engineering)

Quiet Capital • United States

On-site
USD 120,000 - 180,000
Meaningful equity
Remote-first culture
Flexible PTO
+2
Remote Detection Engineer - Email Security & AI Threats
Remote Detection Engineer - Email Security & AI Threats

Doppel Farmaceutici S.r.l. • United States

On-site
USD 120,000 - 180,000
Remote-first culture
Flexible PTO
Meaningful equity
Applied Cyber, Email Security (Detection Engineering)
Applied Cyber, Email Security (Detection Engineering)

Doppel Farmaceutici S.r.l. • United States

On-site
USD 120,000 - 180,000
Remote-first culture
Flexible PTO
Meaningful equity
Senior Threat Intelligence Researcher
Senior Threat Intelligence Researcher

Aegis AI Security • San Francisco (CA)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

five9 • United States

Hybrid
USD 66,000 - 175,000
Equity
Performance bonus
Remote work
+1