Detection and Response Engineer

Modal Labs

New York (NY)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Modal is seeking a Detection & Response Engineer to build scalable security systems across our platform. Youll design detections, incident response workflows, and tooling, leveraging AI to speed investigations and reduce toil.

Work closely with infrastructure, platform, and security teams to improve visibility, response consistency, and post-incident improvements. Strong software engineering and cloud-native experience are required.

Qualifications

  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus.
  • Strong software engineering skills with experience building production systems.
  • Experience investigating security incidents in cloud-native or distributed environments.
  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking.
  • Experience building detections using logs, telemetry, behavioral signals, or large-scale event data.
  • Strong SQL skills for investigating security events and developing detections.
  • Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems.
  • Strong written and verbal communication skills.

Responsibilities

  • Detection Engineering: Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems.
  • Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents.
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services.
  • Incident Response: Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems.
  • Build playbooks and automation that reduce investigation time and improve response consistency.
  • Drive post-incident improvements that eliminate entire classes of future incidents.
  • Security Tooling & Automation: Build internal tooling that improves detection, investigation, and response workflows.
  • Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
  • Improve the collection, quality, and usability of security telemetry across the platform.
  • Engineering Partnership: Partner with engineering teams to ensure new systems are observable and secure by default.
  • Help teams instrument services with the telemetry needed for effective detection and response.
  • Drive security improvements that make the platform easier to defend over time.

Skills

Detection engineering
Incident response
Security engineering
Cloud-native environments
Kubernetes
Linux
Networking
SQL
AI / LLM for security
Communication skills

Tools

Kubernetes
Linux

Job description

About Us

AI needs a new infrastructure layer. We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now. Our customers include category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale. We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September. Our team includes creators of popular open-source projects (e.g.,Seaborn,Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.

The Role

We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform. This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness. You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.

What You'll Work On
  • Detection EngineeringDesign and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
  • Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services
  • Incident ResponseLead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
  • Build playbooks and automation that reduce investigation time and improve response consistency
  • Drive post-incident improvements that eliminate entire classes of future incidents
  • Security Tooling & AutomationBuild internal tooling that improves detection, investigation, and response workflows
  • Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry
  • Improve the collection, quality, and usability of security telemetry across the platform
  • Engineering PartnershipPartner with engineering teams to ensure new systems are observable and secure by default
  • Help teams instrument services with the telemetry needed for effective detection and response
  • Drive security improvements that make the platform easier to defend over time
What We're Looking For
  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus
  • Strong software engineering skills with experience building production systems
  • Experience investigating security incidents in cloud-native or distributed environments
  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking
  • Experience building detections using logs, telemetry, behavioral signals, or large-scale event data
  • Strong SQL skills for investigating security events and developing detections
  • Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems
  • Strong written and verbal communication skills
Preferred Qualifications
  • Experience building AI- or LLM-powered security tooling
  • Experience with SIEM, SOAR, or EDR platforms
  • Experience with Kubernetes security or large-scale cloud infrastructure
  • Experience with threat hunting, malware analysis, or digital forensics
  • Experience contributing to security operations in a high-growth engineering organization
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection and Response Engineer
Detection and Response Engineer

Modal • New York (NY)

On-site
USD 140,000 - 210,000
Detection and Response Engineer
Detection and Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
AI-Driven Detection & Response Engineer
AI-Driven Detection & Response Engineer

Modal • New York (NY)

On-site
USD 140,000 - 210,000
Staff / Principal Software Engineer, Detection and Response
Staff / Principal Software Engineer, Detection and Response

Lovable • Town of Stockholm (NY)

On-site
USD 180,000 - 320,000
Security Engineer, Detection and Response
Security Engineer, Detection and Response

OpenAI • United States

On-site
USD 293,000 - 385,000
Senior Detection & Response Engineer: Incident Lead
Senior Detection & Response Engineer: Incident Lead

Foundation Capital • Sunnyvale (CA)

On-site
USD 180,000 - 240,000
AI-Driven Detection & Response Engineer
AI-Driven Detection & Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
Detection & Response Engineering Manager
Detection & Response Engineering Manager

Objective Partners • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Security Engineer, Detection & Response
Security Engineer, Detection & Response

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Lead Detection Architect: AI-Driven Cyber Defense
Lead Detection Architect: AI-Driven Cyber Defense

Foundation Capital • San Francisco (CA)

On-site
Confidential