Founding Security Lead — Detection & Incident Response

CipherData

Bellevue (WA)

On-site

USD 160,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CipherData seeks a Lead Security Engineer to own the company’s security program, from product-level detections to incident response and compliance. You’ll lead a small founding team, define the ground truth for detections, and build a scalable security lakehouse that drives product security and customer trust.

The role reports to the CEO/CISO and sits in Bellevue, WA, with ownership of security posture, incident response, and SOC 2/ISO 27001 readiness.

Qualifications

  • 8+ years in security engineering or detection engineering with outcomes
  • Proven production detections: written, tuned, retired detections with FP trade-offs
  • Deep hands-on with SIEM and security data platforms, EDR/XDR, and cloud/identity telemetry
  • Strong Python and engineering codebase experience
  • Incident response leadership on real intrusions with customer/executive communication
  • Ability to articulate what separates a good investigation from a bad one precisely enough that it can be written down and measured

Responsibilities

  • Own security lakehouse roadmap and detection platform
  • Develop detection logic and correlation rules
  • Curate benchmark datasets from real investigations
  • Track attacker tradecraft and translate into agent capability
  • Deploy and validate AIDR in customer environments; integrate feedback
  • Own incident response and playbooks; manage security assessments and pen tests

Skills

Security engineering
Detection engineering
Incident response
Python
Cloud security

Tools

SIEM platforms
EDR/XDR
Cloud telemetry
CI/CD pipelines

Job description

CipherData seeks a Lead Security Engineer to own the company’s security program, from product-level detections to incident response and compliance. You’ll lead a small founding team, define the ground truth for detections, and build a scalable security lakehouse that drives product security and customer trust.

The role reports to the CEO/CISO and sits in Bellevue, WA, with ownership of security posture, incident response, and SOC 2/ISO 27001 readiness.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

CipherData • Bellevue (WA)

On-site
USD 160,000 - 190,000
Security Engineer
Security Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 180,000
Staff Security Engineer – Detection & Response Lead
Staff Security Engineer – Detection & Response Lead

IBM • Boston (KY)

On-site
USD 150,000 - 210,000
Detection & Response Lead - Hands-on Engineer
Detection & Response Lead - Hands-on Engineer

Iceberg • New York (NY)

On-site
USD 180,000 - 260,000
Detection & Response Lead — Security Operations
Detection & Response Lead — Security Operations

Serval • San Francisco (CA)

On-site
USD 150,000 - 200,000
Impact on product success
Growth opportunities
Innovative company culture
Detection & Response Leader
Detection & Response Leader

Iceberg • New York (NY)

On-site
USD 180,000 - 260,000
Founding Security Engineer, AI/ML Infra & SOC2
Founding Security Engineer, AI/ML Infra & SOC2

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Staff Security Engineer: Detection & Response Leader
Staff Security Engineer: Detection & Response Leader

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000
Security Operations Leader: Detection, IR & Platform Engineering
Security Operations Leader: Detection, IR & Platform Engineering

Envista Holdings Corporation • Brea (CA)

On-site
USD 156,000 - 191,000
Annual bonus
Medical benefits
401K match
+1
Senior Detection & Response Lead
Senior Detection & Response Lead

Serval, Inc. • San Francisco (CA)

On-site
USD 180,000 - 260,000