Security Engineer - Detection & Response

LangChain, Inc.

San Francisco, Northern (CA, KY)

Hybrid

USD 180,000 - 240,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage
Flexible vacation
401(k) plan
In-office meals in the US

Job summary

LangChain, Inc. is seeking a hands-on Security Detection Engineer to protect our production platform and cloud infrastructure. You will translate threat models into telemetry, build scalable detections, and drive proactive threat hunting while collaborating with Product Security.

The role requires strong software skills, on-call experience, and a pragmatic mindset to ship durable security solutions across LangChain's services and agents.

Qualifications

  • 5+ years in security engineering, with experience in detection engineering, security operations, or incident response.
  • Strong software engineering in Python or Go, with TypeScript a plus.
  • Experience with GCP or AWS logging, Kubernetes audit and runtime telemetry.
  • Ability to model attacker behavior, hunt across complex systems, and distinguish signal from noise.
  • Participated in on-call, led incidents, and written postmortems that changed team operations.
  • Experience building automation or developer-facing systems and writing production code.
  • Pragmatic product mindset: identify users and requirements, prioritize high-leverage problems, and ship iteratively.

Responsibilities

  • Own the detection lifecycle: translate threat models, incidents, and attacker behavior into telemetry requirements and detections-as-code.
  • Build security monitoring and telemetry: design the telemetry pipeline end-to-end across cloud, Kubernetes, and control plane.
  • Engineer investigations and threat hunting: build tools and workflows for proactive hunting and scoping.
  • Use agents to scale the team: build internal AI agents to triage alerts and enrich findings.
  • Lead incident response and participate in on-call: triage, scope, contain, and drive postmortems.
  • Partner with Product Security: turn threat findings into production monitoring and secure design feedback.

Skills

5+ years in security engineering
Strong software engineering
Cloud and Kubernetes detection depth
Detection and adversary expertise
Hands-on incident response
Experience building reliable automatio
Pragmatic product mindset

Job description

About Us

At LangChain, our mission is to make intelligent agents ubiquitous. We build the foundation for agent engineering in the real world, helping developers move from prototypes to production-ready AI agents that teams can rely on. We began as widely adopted open-source tools and have grown to also offer a platform for building, evaluating, deploying, and operating agents at scale.

With $125M raised at Series B from IVP, Sequoia, Benchmark, CapitalG, and Sapphire Ventures, we're at a stage where we're continuing to develop new products, growth is accelerating, and all team members have meaningful impact on what we build and how we work together. LangChain is a place where your contributions can shape how this technology shows up in the real world.

Today, our platform includes LangSmith (Observability, Evaluation, Deployment, Fleet, and Sandboxes), our open source frameworks (LangChain, LangGraph, and Deep Agents), and the newly launched LangSmith Engine for autonomous agent improvement. We have 100M+ monthly open source downloads, 6,000+ active LangSmith customers, and 5 of the Fortune 10 use LangSmith in production (+ 35% of the Fortune 500 overall), including teams at Klarna, Clay, Coinbase, Workday, Lyft, Cloudflare, Harvey, Rippling, Vanta, LinkedIn, Monday.com, Nvidia, and Bridgewater.

About the Team

The Security team ensures that while AI moves at breakneck speed, everyone driving the racecar is wearing a seatbelt. We secure LangChain's core platform and protect AI agents from emerging threats. We work across the stack so developers can confidently ship from prototype to production without compromising on safety or privacy.

About the role

You'll be the hands-on detection and response engineer responsible for how we see, stop, and learn from threats across LangChain's production platform, cloud infrastructure, and the services that host and execute agentic workloads. You'll partner closely with Product Security to turn threat models, vulnerabilities, and incidents into telemetry, detections, and durable defenses. Your primary focus is engineering: building detection, investigation, and response systems that scale the Security team's impact beyond what manual operations allow. We are looking for engineers who think like builders, not just operators — strong software skills are a must.

This role participates in an incident on-call rotation, but its core focus is engineering systems that reduce risk, speed up investigations, and make incidents less frequent and less costly.

Location/City: San Francisco or NYC

What you'll do
  • Own the detection lifecycle: Translate threat models, incidents, and attacker behavior into telemetry requirements and detections-as-code. Validate coverage, measure signal quality, tune false positives, and continuously test whether defenses work.

  • Build security monitoring and telemetry: Design the telemetry pipeline end-to-end across cloud (GCP/AWS), Kubernetes, and the LangSmith/LangGraph control plane. Instrument services, define the signals that matter, and make security data reliable and useful.

  • Engineer investigations and threat hunting: Build tools and workflows for proactive hunting, evidence collection, incident scoping, and containment. Turn investigation findings into new detections and lasting improvements.

  • Use agents to scale the team: Build reliable internal AI agents and automation that triage alerts, enrich findings, gather evidence, scope incidents, and accelerate routine security work. Design human-in-the-loop controls and evaluations so automation is safe, observable, and trustworthy.

  • Lead incident response and participate in on-call: Triage, scope, contain, and remediate security incidents, then drive postmortems that produce durable engineering changes.

  • Partner with Product Security: Turn product threat models and vulnerability findings into production monitoring, and feed real-world detection and incident learnings back into secure design.

What you'll bring
  • 5+ years in security engineering, with meaningful experience in detection engineering, security operations, or incident response — and the software skills to build your way out of repetitive work.

  • Strong software engineering in Python or Go (TypeScript a plus). You design maintainable systems and write production code, not just one-off scripts.

  • Cloud and Kubernetes detection depth: Experience with GCP or AWS logging, Kubernetes audit and runtime telemetry, workload identity, and turning raw signals into actionable detections.

  • Detection and adversary expertise: The ability to model realistic attacker behavior, hunt across complex systems, test detection coverage, and distinguish meaningful signal from noise.

  • Hands-on incident response: You've participated in on-call, led incidents, and written postmortems that changed how a team operates.

  • Experience building reliable automation or developer-facing systems: You can design APIs and workflows, instrument what you build, evaluate quality, and operate it in production.

  • A pragmatic product mindset: You can identify users and requirements, prioritize the highest-leverage problems, define success, and ship iteratively.

Nice to have
  • Experience building or operating AI agents for security workflows such as alert triage, investigation, evidence collection, or human-in-the-loop response.

  • Proficiency using AI tooling to accelerate security investigations and engineering work.

  • Understanding of AI threats, adversarial testing, and the security boundaries of LLM and agent workloads.

  • Exposure to SOC 2 or ISO 27001 monitoring and evidence automation.

  • Experience with infrastructure as code such as Terraform or Helm.

  • Experience securing both SaaS and self-hosted or air-gapped deployments.

    Annual salary range: $180,000- $240,000 USD

Compensation Philosophy:

We offer competitive compensation that includes base salary, variable compensation for relevant roles, meaningful equity, benefits, and perks. Actual compensation and offerings will vary based on role, level, and location. Team members in the EU, UK, and APAC receive locally competitive benefits aligned with regional norms and regulations.

Benefits

Benefits include medical, dental, and vision coverage, flexible vacation, a 401(k) plan, meals on in-office days in the US and more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Detection & Response
Security Engineer - Detection & Response

Doist • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision coverage
Equity and 401(k)
Security Engineer - Detection & Response
Security Engineer - Detection & Response

LangChain • New York (NY)

On-site
USD 180,000 - 240,000
Principal Software Engineer, AI Observability & Evals Platform
Principal Software Engineer, AI Observability & Evals Platform

LangChain • Cambridge (MA)

On-site
USD 230,000 - 270,000
Medical, dental, and vision coverage
401(k) plan with company match
Meals on in-office days (US)
Deployed Engineer (Bay Area)
Deployed Engineer (Bay Area)

LangChain • San Francisco (CA)

On-site
USD 165,000 - 315,000
Medical, dental, and vision coverage
401(k) plan
Meals on in-office days in the US
Solutions Engineer (Chicago)
Solutions Engineer (Chicago)

LangChain, Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 200,000 - 250,000
Medical,dental, and vision coverage
401(k) plan
Meals on in-office days in the US
Solutions Engineer (Chicago)
Solutions Engineer (Chicago)

AI Chopping Block • Chicago (IL), Northern (KY)

Hybrid
USD 200,000 - 250,000
Medical/Dental/Vision coverage
401(k) plan
In-office meals
Solutions Engineer (Texas)
Solutions Engineer (Texas)

LangChain, Inc. • Dallas (TX), Northern (KY)

Hybrid
USD 200,000 - 250,000
Medical coverage
Dental coverage
Vision coverage
+2
Deployed Engineer (Early Career- SF/NY)
Deployed Engineer (Early Career- SF/NY)

LangChain, Inc. • San Francisco (CA)

On-site
USD 155,000 - 165,000
Medical benefits
401(k) plan
Meals on in-office days
Deployed Engineer (Early Career-NYC)
Deployed Engineer (Early Career-NYC)

Neura Market • New York (NY)

On-site
USD 155,000 - 165,000
Deployed Engineer (Early Career-NYC)
Deployed Engineer (Early Career-NYC)

LangChain, Inc. • New York (NY)

On-site
USD 155,000 - 165,000
Medical coverage
Flexible vacation
401(k) plan
+1