Security Engineer, Detection and Response San Francisco

Serval Inc.

San Francisco (CA)

On-site

USD 180,000 - 300,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Impact
Growth
Culture

Job summary

Serval Inc. is seeking a Detection and Response Lead to shape and scale cybersecurity operations across its infrastructure and customer environments.

You will set strategy, drive execution, and mentor a team responsible for monitoring, incident response, recovery, and post-incident improvements. You will lead a hands-on security function, partner with Engineering and Product, and ensure detection and response are embedded by design into Serval’s systems.

Qualifications

  • 10+ years in cybersecurity with deep expertise in detection engineering, incident response, and security operations.
  • Experience building and leading detection and response, instrumentation/observability, and threat intelligence teams.
  • Strong leadership skills with a track record of durable, continuous improvements to programs, processes and people.
  • Exceptional written and verbal communication skills, calm under pressure, able to lead security incidents with many stakeholders.
  • Deep expertise in modern observability stacks (SIEM, data lakes, EDR, cloud telemetry, logging).
  • Understanding adversary tradecraft (TTPs) and translating it into practical detection strategies and response actions.
  • Mission-oriented, unimpeachable integrity, thrives in a fast-paced, complex environment.

Responsibilities

  • Design, implement, and operate detection and response across networks and infrastructure.
  • Lead and mentor a team spanning observability, detection, response, and threat intelligence.
  • Maintain incident playbooks, on-call rotations, escalations, and tabletop exercises.
  • Improve detection quality and coverage with engineering partnerships for telemetry.
  • Embed detection and response into Serval's systems by design, not as an afterthought.
  • Build a security program capable of withstanding sophisticated adversaries.

Skills

Cybersecurity
Detection engineering
Incident response
Security operations
Leadership
Communication

Tools

SIEM
EDR
Data lakes
Logging

Job description

Who We Are

Serval is an AI-native automation platform transforming how enterprises operate. We build intelligent agents that understand real-world workflows and execute them end-to-end — replacing manual processes and rigid legacy systems with adaptive, learning software. Founded in early 2024, Serval is already trusted by companies like Fox, Notion, Perplexity, Vercel, and Brex to automate high-volume, high-friction operational work across their organizations.

At the core of Serval is an agentic AI platform that turns natural language into production-grade workflows. Our agents don’t just respond to requests — they reason, take action across systems, and continuously improve with usage. What began with operational use cases has quickly evolved into a horizontal AI automation layer used across IT, HR, Finance, Security, Legal, and Engineering.

Our mission is to eliminate repetitive, manual work across the enterprise and give teams leverage through intelligent automation. Long term, we’re building the universal AI operations layer — a system of agents that sits across business functions and runs the workflows that keep modern companies moving.

We’re backed by leading investors including Sequoia Capital, Redpoint Ventures, Meritech, First Round, General Catalyst, Elad Gil, and others.

Role Overview

As Detection and Response Lead, you'll build and scale the foundations of Serval's cybersecurity detection and response operations. You will set the strategy and drive execution for security monitoring, incident response, recovery, and post-incident improvement across our infrastructure and the systems our customers trust us to operate in.

You'll be a hands-on leader with deep technical credibility and strong operational instincts. You will build and mentor a team, partner closely with Engineering and Product, and ensure that detection and response capabilities are embedded by design into the systems that power Serval.

What You'll Do
  • Design, implement, and operate detection and response operations, including continuous monitoring, triage, investigation, containment, and remediation of security events across a diverse set of networks and infrastructure.

  • Build, lead, and directly mentor a team spanning observability, detection and response, and threat intelligence, hiring and scaling these functions deliberately and proportionately as Serval's platform and customer footprint grow.

  • Ensure world-class operational rigor and readiness through incident playbooks, on-call and escalation paths, tabletop exercises, and continuous improvement of response quality and speed.

  • Improve detection quality and coverage by partnering with engineering teams to ensure critical telemetry is available, reliable, and actionable across cloud, corporate, and production environments.

  • Partner deeply across Engineering, Product, and Infrastructure to embed detection and response into Serval's systems by design rather than as an afterthought.

  • Build a security program capable of withstanding sophisticated adversaries, including by using Serval's own agents to solve frontier security and security-operations problems.

What You'll Need
  • Have 10+ years in cybersecurity with deep expertise in detection engineering, incident response, and security operations.

  • Have deep experience building and leading detection and response, instrumentation/observability, and threat intelligence teams.

  • Have stellar leadership skills and a demonstrated history of driving durable, continuous improvements to programs, processes, and people.

  • Have exceptional written and verbal communication skills, can remain calm under pressure, and can effectively run command of security incidents involving numerous stakeholders across a diverse gamut of teams, expertise, and seniority.

  • Have deep expertise in modern observability stacks (e.g., SIEM, data lakes, EDR, cloud telemetry, logging) and detection primitives.

  • Understand modern adversary tradecraft (TTPs) and have demonstrated experience translating it into practical detection strategies and response actions.

  • Are mission-oriented, have unimpeachable integrity, and are passionate about detecting and responding to adversaries in a highly complex, fast-paced environment.

What We Offer
  • Impact: Be a key player in shaping the success of our product and company.

  • Growth: Build a fundamentally new AI product offering with the support of our experienced team and investors. Grow rapidly with the company.

  • Culture: Join a culture that values innovation, ownership, accountability, and fun.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer, Detection and Response
Security Engineer, Detection and Response

SERVAL • San Francisco (CA)

On-site
USD 210,000 - 270,000
Impact
Growth
Culture
Security Engineer, Application
Security Engineer, Application

Serval • San Francisco (CA)

On-site
USD 180,000 - 260,000
Security Engineer, Corporate
Security Engineer, Corporate

serval • San Francisco (CA)

On-site
USD 180,000 - 280,000
Impact
Growth
Culture
Engineering Leadership
Engineering Leadership

SERVAL • United States

On-site
USD 180,000 - 240,000
Impact
Growth
Culture
Senior Security Detection & Response Lead
Senior Security Detection & Response Lead

SERVAL • San Francisco (CA)

On-site
USD 210,000 - 270,000
Impact
Growth
Culture
Engineering Leadership
Engineering Leadership

Association of Fundraising Professionals (AFP) Silicon Valley Chapter • San Francisco (CA)

On-site
USD 280,000 - 480,000
Engineering Leadership
Engineering Leadership

Serval, Inc. • San Francisco (CA)

On-site
USD 210,000 - 320,000
Impact
Growth opportunities
Culture
Senior Detection & Response Engineer — Incident Ops Lead
Senior Detection & Response Engineer — Incident Ops Lead

Serval Inc. • San Francisco (CA)

On-site
USD 180,000 - 300,000
Impact
Growth
Culture
Solutions Engineer - Mid-Market
Solutions Engineer - Mid-Market

re-zoo-me • San Francisco (CA), Northern (KY)

Hybrid
USD 183,000 - 247,000
Impact
Growth
Culture
Deployment Leadership
Deployment Leadership

Association of Fundraising Professionals (AFP) Silicon Valley Chapter • San Francisco (CA)

On-site
USD 180,000 - 260,000