Security Engineer

CipherData

Bellevue (WA)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CipherData is seeking a Security Engineer to design and refine detection and correlation rules for our AIDR platform. You will work alongside the AI engineering team and contribute to ground truth labeling, threat research, and incident response in live customer environments.

The role is suited for a hands-on engineer with a few years in SOC/detection who can scale responsibilities rapidly, potentially advancing to senior capability ownership as the team grows.

Qualifications

  • 3+ years hands-on in a SOC, detection engineering, threat hunting, or incident response role.
  • Experience writing and tuning detections in production and explaining false-positive trade-offs.
  • Experience with at least one SIEM or security data platform and EDR/XDR telemetry.

Responsibilities

  • Write, test, tune, and retire detection logic and correlation rules.
  • Label real investigations into benchmark datasets and document false conclusions.
  • Track attacker tradecraft and turn it into detection content and test cases.
  • Contribute to normalization, enrichment, and query patterns in our security lakehouse.
  • Help deploy, tune, and validate AIDR in customer environments and feedback detection.
  • Participate in incident response and post-incident reviews.

Skills

SOC experience
Detections engineering
Python
Code review
Ownership

Tools

SIEM
EDR/XDR

Job description

About the Role

AIDR's agents investigate every alert autonomously. Your job is to make sure they investigate the right things, the right way. You will build the detection and correlation content our agents reason over, label the real investigations that tell us whether their conclusions are correct, and work inside customer SOCs while AIDR runs in production.

This is a product role, not a corporate security or compliance role. You are joining our founding security team — you will work directly with the AI engineering team and with the engineer who leads our security function, and you will see your detection work go from idea to customer environment in days. We will level this role to the person: a strong engineer with a few years of hands‑on SOC or detection work will grow fast here; a senior engineer will own large pieces outright.

What You'll Do
  • Detection and correlation engineering: Write, test, tune, and retire the detection logic and correlation rules that turn multi‑vendor security data into signal our agents can reason over.
  • Ground truth: Label real investigations into the benchmark datasets that measure whether agent output is right; find and document the cases where it is confidently wrong.
  • Threat research: Track attacker tradecraft and turn it into detection content, test cases, and agent capability.
  • Security lakehouse: Contribute to normalization, enrichment, and query patterns on our SIEM‑less security lakehouse as we expand it.
  • Customer SOC work: Help deploy, tune, and validate AIDR in customer environments and carry analyst feedback back into detection and evaluation.
  • Incident response: Participate in customer‑reported and internal incident response, including analysis, documentation, and post‑incident review.
Our Core Values

Five principles guide every decision at CipherData. We hire against them and evaluate against them:

  • Trustworthiness — be trustworthy to all people. Integrity, transparency, and dependability with colleagues, partners, and customers.
  • Growth Mindset — learn from anything, anyone, anytime. Past experience is data, not dogma. Curiosity over ego; first principles over status quo.
  • Proactive Ownership — do the right thing for the customer. Customer first, then company, then team, then self. Step beyond your role and hold yourself accountable.
  • Disagree and Commit — debate when it matters, execute with unity. Challenge high‑impact decisions with data and conviction, regardless of title. Once decided, commit fully.
  • Impact‑Driven Execution — ship, learn, iterate. Move fast, take calculated risks, and measure yourself by outcomes, not activity.
Minimum Qualifications
  • 3+ years hands‑on in a SOC, detection engineering, threat hunting, or incident response role
  • You have written and tuned detections in production and can explain the false‑positive trade‑offs you made
  • Working experience with at least one SIEM or security data platform and EDR/XDR telemetryli>
  • Working Python; comfortable in a codebase with code review, tests, and CI
  • Comfort with ambiguity and ownership at an early‑stage startup: you scope your own work, ask for help early, and ship
Preferred Qualifications
  • 5+ years, including senior‑level detection engineering or IR (we will level and title accordingly — Senior Security Engineer)
  • Detection‑as‑code practice
  • Cloud and identity telemetry depth
  • Experience building labeled datasets or evaluations
  • Familiarity with LLM‑based systems and their failure modes
  • Purple team, adversary emulation, or offensive security background
Details
  • Position: Security Engineer / Senior Security Engineer, Detection & Response (leveled to experience)
  • Experience: 3+ years
  • Employment type: Full‑time
  • Location: Bellevue, WA

CipherData is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

CipherData • Bellevue (WA)

On-site
USD 160,000 - 190,000
AI Engineer
AI Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 155,000
AI-Driven Detection Engineer for Security Ops
AI-Driven Detection Engineer for Security Ops

CipherData • Bellevue (WA)

On-site
USD 120,000 - 180,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Detection and Response Engineer
Detection and Response Engineer

Modal • New York (NY)

On-site
USD 140,000 - 210,000
Security Software Engineer II, Detection and Response
Security Software Engineer II, Detection and Response

Pinterest • San Francisco (CA)

On-site
USD 123,696 - 254,667
AI Engineer
AI Engineer

CipherData, Inc. • Bellevue (WA)

On-site
USD 120,000 - 160,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Detection and Response Engineer
Detection and Response Engineer

Modal Labs • New York (NY)

On-site
USD 140,000 - 190,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Cerebras • Sunnyvale (CA)

On-site
USD 180,000 - 240,000