Detection Engineer II

EngineersOfAI

United States

Hybrid

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Instacart is expanding its Detection Engineering team within Security to build and operate systems that surface threats across a large grocery technology platform. You will develop high-fidelity detection logic, hunt for attacker techniques, and drive coverage, quality, and scale with a detection-as-code mindset.

You’ll work with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure detections reflect real-world adversary behavior, and you’ll help reduce noise while

Qualifications

  • Minimum 2+ years in detection engineering, incident response, or offensive security.
  • Experience with one or more public cloud platforms (AWS, Azure, GCP).
  • Deep understanding of attacker TTPs across modern environments.
  • Proficiency in macOS internals and telemetry.
  • Experience implementing detection-as-code workflows with VCS, automated testing, and CI/CD.
  • Proficiency in Python or Golang.
  • Relevant certifications (GCFA, GCFE, GNFA, GREM, OSCP, GCIA or similar).

Responsibilities

  • Develop, tune, document, and maintain detection logic across multiple log sources (endpoint, cloud, container, SaaS).
  • Assist in cyber forensic investigations across various log sources.
  • Optimize log ingestion pipelines and telemetry to balance quality, volume, and cost.
  • Design and build SOAR playbooks and automation workflows for triage and response.
  • Mentor other detection engineers on threat hunting, detection logic, and investigation techniques.

Skills

2+ years in detection/security
Cloud platforms AWS/Azure/GCP
Attacker TTPs knowledge
macOS internals telemetry
Detection-as-code workflows
Python or Go
Cyber security certifications

Job description

We're transforming the grocery industry

At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.

Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.

Instacart is a Flex First team

There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work- whether it’s from home, an office, or your favorite coffee shop- while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.

Overview

Instacart's Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North America's largest grocery technology platforms. We own the full detection lifecycle, from telemetry collection and signal design to automated response, across a complex, cloud-native environment spanning endpoint, cloud, container, and SaaS.

As a Detection Engineer, you'll be a technical anchor on the team: developing high-fidelity detection logic, hunting for novel attacker techniques, and raising the bar for how we think about coverage, quality, and scale. You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure our detections reflect real-world adversary behavior (and not just signatures).

We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed through repeatable pipelines. We care deeply about reducing noise, improving analyst efficiency through automation and SOAR, and continuously evolving our coverage as the threat landscape shifts.

If you're energized by hard forensic problems, enjoy translating attacker TTPs into durable detection logic, and want to help shape the future of a growing security function, this role is for you.

About the Job
  • Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
  • Assist in cyber forensic investigations across a variety of log sources
  • Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost
  • Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions
  • Mentor/knowledge share with other detection engineers on threat hunting methodologies, detection logic development, and investigation techniques
About You
Minimum Qualifications
  • 2+ years of experience in a detection engineering, incident response, or offensive security role.
  • Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
  • Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries
  • Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
  • Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines
  • Basic proficiency with Python, Golang, or other programming/scripting languages
  • Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar
Preferred Qualifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer II
Senior Detection Engineer II

EngineersOfAI • Northern (KY)

Hybrid
USD 140,000 - 190,000
Remote Detection Engineer II - Security & SOAR
Remote Detection Engineer II - Security & SOAR

EngineersOfAI • United States

Hybrid
USD 130,000 - 180,000
Senior Threat Detection Engineer — Remote
Senior Threat Detection Engineer — Remote

Instacart • San Francisco (CA)

On-site
USD 192,000 - 243,000
Senior Threat Detection Engineer – Cloud & Forensics
Senior Threat Detection Engineer – Cloud & Forensics

EngineersOfAI • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Threat Detection Engineer — Remote
Senior Threat Detection Engineer — Remote

United States Digital Space LLC • United States

Remote
USD 196,000 - 207,000
Equity grant
Detection and Response Engineer
Detection and Response Engineer

United States Digital Space LLC • New York (NY)

On-site
USD 140,000 - 200,000
Detection and Response Engineer
Detection and Response Engineer

Neura Market • New York (NY)

On-site
USD 140,000 - 210,000
Detection and Response Engineer
Detection and Response Engineer

AI Chopping Block • New York (NY)

On-site
USD 140,000 - 200,000
Detection and Response Engineer
Detection and Response Engineer

Mixpeek • New York (NY)

On-site
USD 140,000 - 190,000
Detection and Response Engineer
Detection and Response Engineer

Modal • New York (NY)

On-site
USD 140,000 - 210,000