Senior Threat Detection Engineer - Intelligence

WeHireYou

Austin (IN)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
Wellbeing benefit
WFH equipment allowance
Learning & Development stipend

Job summary

Miro is seeking a Senior Threat Detection Engineer - Intelligence to translate attacker behavior into proactive detections and lead investigative response. You’ll work across cloud, identity, and app layers, guiding incident response and shaping detection programs.

This role is based in Austin and involves collaborating with engineering to improve security maturity. You’ll be tracking threats, designing detections, and leading investigations from signal to remediation, with a focus on

Qualifications

  • 5–7 years in security with 2+ years in threat detection, threat intelligence, or investigations.
  • Experience in cloud-native SaaS environments, AWS strongly preferred.
  • Strong investigation skills and ability to analyze attacker behavior.
  • Experience using threat intelligence to inform detection and response.
  • Proficiency in Python and comfort automating security workflows.
  • Experience querying large datasets (SQL or similar).
  • Familiarity with cloud security telemetry, logging, and detection platforms.
  • Solid understanding of incident response and digital forensics.
  • Experience with Infrastructure as Code (Terraform or similar).

Responsibilities

  • Track emerging threats, attacker techniques, and campaigns relevant to cloud and SaaS.
  • Turn threat intelligence into practical detection strategies and attack hypotheses.
  • Design and maintain context-aware detections across cloud, identity, and application layers.
  • Lead deep investigations, from first signal to root cause and remediation.
  • Act as a technical lead during security incidents, guiding response and decision-making.
  • Analyze detection and investigation trends to improve preventative controls.
  • Partner with engineering teams to raise security maturity across the organization.

Skills

Threat detection
Threat intelligence
Incident response
Python
SQL
Terraform
Cloud security
Investigation

Tools

AWS
SQL databases

Job description

Senior Threat Detection Engineer - Intelligence

We’re looking for a Senior Threat Detection & Intelligence Engineer to help us understand how adversaries operate, detect meaningful threats early, and lead investigations when it matters most. This role sits at the intersection of threat intelligence, detection engineering, and incident investigation with an engineering-first mindset.

If you enjoy turning messy signals into clear attacker narratives, this role is for you.

About the Team

The Cloud Security & Detection & Response (CSDR) team protects Miro by staying ahead of credible threats. We focus on:

  • Translating external threat intelligence into actionable detections
  • Building custom, high-fidelity detections for cloud and SaaS environments
  • Leading complex investigations and incident response
  • Partnering with engineering to drive security by design

We care about context, signal quality, and attacker intent not alert volume.

What You’ll Do
  • Track emerging threats, attacker techniques, and campaigns relevant to cloud and SaaS
  • Turn threat intelligence into practical detection strategies and attack hypotheses
  • Design and maintain context-aware detections across cloud, identity, and application layers
  • Lead deep investigations, from first signal to root cause and remediation
  • Act as a technical lead during security incidents, guiding response and decision-making
  • Analyze detection and investigation trends to improve preventative controls
  • Partner with engineering teams to raise security maturity across the organization
Who This Role Is For

This role is a great fit if you:

  • Think in attacker TTPs, not just alerts or dashboards
  • Enjoy investigating ambiguous signals and turning them into clear conclusions
  • Have experience in threat intelligence, threat hunting, or security investigations
  • Care about why something is happening, not just what fired
  • Want to build detection programs that evolve with the threat landscape
  • Are comfortable explaining technical risk in business terms

This role is not a fit if you’re mainly focused on compliance, policy writing, or managing vendors.

What We’re Looking For
  • 5–7 years in security, with 2+ years in threat detection, threat intelligence, or investigations
  • Experience in cloud-native SaaS environments (AWS strongly preferred)
  • Strong investigation skills and ability to analyze attacker behavior
  • Experience using threat intelligence to inform detection and response
  • Proficiency in Python and comfort automating security workflows
  • Experience querying large datasets (SQL or similar)
  • Familiarity with cloud security telemetry, logging, and detection platforms
  • Solid understanding of incident response and digital forensics
  • Experience with Infrastructure as Code (Terraform or similar)
Why You’ll Love This Role
  • You’ll help define how threat intelligence is used, not just consume it
  • You’ll work on real attacker behavior, not checkbox security
  • You’ll have room to build, experiment, and improve detection capabilities
  • You’ll partner closely with engineers who value security as an engineering problem
What's in it for you

We want you to feel supported, connected, and ready to grow. Our global benefits package generally includes equity, a wellbeing benefit, a WFH equipment allowance, and an annual Learning & Development stipend. Join a diverse team where you can do your best work. Full benefits may differ per location. If you would like to learn more about location‑specific benefits, please refer to our Global Miro benefits board.

  • equity
  • a wellbeing benefit
  • a WFH equipment allowance
  • an annual Learning & Development stipend

Austin

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Detection & Intelligence Engineer
Senior Threat Detection & Intelligence Engineer

WeHireYou • Austin (IN)

On-site
USD 140,000 - 180,000
Equity
Wellbeing benefit
WFH equipment allowance
+1
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

samsara • United States

Hybrid
USD 150,000 - 190,000
Professional development stipend
Comprehensive health coverage
Parental leave plans
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

United States Digital Space LLC • United States

On-site
USD 158,000 - 239,000
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Securitas Security Services USA, Inc. • United States

On-site
USD 120,000 - 150,000
Senior Threat Intelligence Engineer
Senior Threat Intelligence Engineer

CloudFlare • United States

On-site
USD 140,000 - 190,000
Equity plan
Health & welfare benefits
401(k) Retirement Savings Plan
+2
Detection & Response Engineering Manager
Detection & Response Engineering Manager

InfraTech Solutions LLC • Chicago (IL)

On-site
USD 150,000 - 180,000
Health, dental, and vision insurance
Paid time off and holidays
Parental leave
+2
Detection & Response Engineering Manager
Detection & Response Engineering Manager

Objective Partners • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Manager, Threat Intelligence
Manager, Threat Intelligence

Lever, Inc. • United States

Hybrid
USD 150,000 - 190,000
Threat Intelligence and Detection Engineer
Threat Intelligence and Detection Engineer

Insane Cyber • San Antonio (TX)

On-site
USD 90,000 - 120,000
Competitive Base Salary
Equity offering subject to board approval
Comprehensive medical/dental/vision/life insurance plan
+2
Threat Intelligence Engineer
Threat Intelligence Engineer

Docusign • United States

Hybrid
USD 120,000 - 180,000