Confluent - Staff Security Engineer I - Detection & Response

IBM

Lowell (MA)

On-site

USD 140,000 - 190,000

Full time

21 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confluent seeks an experienced security engineer to join our infrastructure security engineering team focusing on Detection and Response. You will scale threat detection, build foundational systems, and partner with engineering to keep environments secure.

You will mentor peers, drive on-call incident response, and translate threat models into high-signal detections while pushing secure-by-default visibility across multi-cloud deployments.

Qualifications

  • 8+ years in detection and response or similar security engineering role.
  • Expert-level knowledge in detection engineering and incident response.
  • Experience instrumenting telemetry and building detections at scale (Kubernetes, containers, multi-cloud).

Responsibilities

  • Architect and maintain cloud-based security monitoring solutions across logging pipelines and SIEM ingestion.
  • Drive long-term threat-hunting roadmap translating TTPs into high-signal detections.
  • Triage security alerts and drive incidents to closure, including on-call rotation.
  • Research new threat vectors and align detection program with current landscape.
  • Improve detection rules by tracking metrics like coverage and MTTD.
  • Collaborate with engineering to gather relevant telemetry and ship secure-by-default visibility.

Skills

Threat detection
Incident response
Security tooling
Python
Golang
Cloud security
Mentorship

Education

Master's Degree

Tools

Kubernetes
Containers
SIEM
SOAR

Job description

Introduction

At Confluent, we’re creating a category that transforms how every company manages and streams data. Have you ever found a new favorite series on Netflix, picked up groceries curbside at Walmart, or paid for something using Square? That’s Confluent in action - giving our customers instant access to massive amounts of real-time data, enabling them to thrive in an ever-changing digital world. As one of the fastest-growing enterprise companies in history, and with Fortune 100 customers across major industries, we have a tremendous opportunity in front of us. We also have experience on our side. Our leaders have taken companies of our size to major success before and include some of the original creators of Apache Kafka®.

We’re looking for self-motivated team members who crave a challenge and feel energized to roll up their sleeves and help realize Confluent’s unlimited potential. Chart your own path and take healthy risks with the backing and support of our #OneTeam culture. Be part of inclusive initiatives like Employee Resource Groups and development programs, and take advantage of benefits that support our diverse global teams. Grow as we grow - whether you’re just starting out or managing a large team, you’ll be amazed at the magnitude of your impact.

Your Role And Responsibilities

We are looking for an experienced security engineer to join our infrastructure security engineering team with a focus on Detection and Response. You will have a unique opportunity to leverage your threat detection and response experience and build some of the foundational systems and services to keep our infrastructure free from malicious actors and threats.

As an expert in your domain, you will be identifying high-leverage problems and driving open-ended projects. You will partner closely with engineering teams and compliance analysts to ensure that we maintain sufficient visibility into our environments and develop effective programs and practices to ensure that our environments are always secure. Tooling and automation will be key to success as we scale our environments to meet customer demand. In addition to being a highly productive engineer, you will serve as a technical compass and mentor the next generation of security engineers.

We intend to be the world's best, fastest, and most complete stream processing service built by an excellent team, all while having fun - come join us on the journey!

What You Will Do
  • Architect, build and maintain scalable cloud-based security monitoring solutions, across logging pipelines, ETL jobs, and SIEM ingestion.
  • Drive the long-term roadmap for threat hunting by translating modern adversary tradecraft (TTPs) and threat models into high-signal detection strategies to ensure our critical infrastructure operates safely.
  • Build processes and workflows to triage security alerts and drive incidents to closure, including participating in a shared on-call rotation for incident response.
  • Research new threat attack vectors and ensure that our detection and response program is in line with the current threat landscape.
  • Proactively improve the quality of our detection rules by defining and tracking key metrics (e.g., coverage, precision, MTTD), working directly with engineering teams to eliminate classes of issues.
  • Collaborate with engineering teams in building logging pipelines needed to gather relevant security telemetry, ensuring new infrastructure ships with secure-by-default visibility.
  • Contribute to strategy, risk management and prioritization for all efforts around detection and response.
  • Provide technical guidance, mentorship, and leadership to other engineers, raising the bar for security operations across the organization.
Preferred Education

Master's Degree

Required Technical And Professional Expertise
  • 8+ years of relevant industry experience in detection and response or similar security engineering role in a cloud-first environment.
  • Deep, expert-level domain knowledge in detection engineering and security incident response.
  • Experience in instrumenting telemetry and building high-quality detections in large-scale, heterogeneous deployments (e.g., Kubernetes, containers, multi-cloud).
  • Proficient ability in writing code using Python or Golang to design complex tooling, automation, and data pipelines.
  • Demonstrated experience with effective incident response and containment practices, preferably in a cloud-first environment.
  • Experience with operating open-source and/or commercial solutions for logging and security event management (e.g. SIEM, log aggregation, SOAR, etc).
  • Ability to work alongside a remote team, using a data-driven mindset to propose and own engineering decisions, and the capability to drive consensus across ambiguous, organizational-wide challenges.
Preferred Technical And Professional Experience
  • Familiarity with more than one cloud vendor (AWS, GCP, Azure) is a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Confluent - Staff Security Engineer I - Detection & Response
Confluent - Staff Security Engineer I - Detection & Response

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000
Confluent - Staff Security Engineer I - Detection & Response
Confluent - Staff Security Engineer I - Detection & Response

IBM • City of Poughkeepsie (NY)

On-site
USD 150,000 - 230,000
Staff Security Engineer: Detection & Response Leader
Staff Security Engineer: Detection & Response Leader

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000
Senior Manager, Detection & Response (Security Engineering)
Senior Manager, Detection & Response (Security Engineering)

Confluent • United States

Hybrid
USD 180,000 - 260,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • City of Poughkeepsie (NY)

On-site
USD 150,000 - 210,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • San Diego (CA)

On-site
USD 190,000 - 230,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Boston (KY)

On-site
USD 150,000 - 210,000
Detection & Response Engineering Lead
Detection & Response Engineering Lead

Confluent • United States

Hybrid
USD 180,000 - 260,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Armonk (NY)

On-site
USD 170,000 - 230,000
Cloud Security Detection Engineer – IR & Threat Hunting
Cloud Security Detection Engineer – IR & Threat Hunting

IBM • Lowell (MA)

On-site
USD 140,000 - 190,000