Staff Security Engineer: Threat Detection & SIEM Architecture

Envoy

San Francisco (CA)

On-site

USD 180,000 - 240,000

Full time

12 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Envoy is seeking a Staff Security Engineer to own and evolve our security operations and threat-detection capabilities from our San Francisco HQ. You will define detection strategies across cloud, applications, and endpoints, enhance our SIEM, and drive automated controls and robust alerting.

This on-site role emphasizes engineering-led security with measurable impact and strong cross-functional collaboration.

Qualifications

  • 10+ years in security engineering, SRE, or infra with a security focus.
  • Proven experience designing or improving security monitoring, SIEM.
  • Experience with cloud environments (AWS) including IAM, networking, and logging at scale.
  • Experience with endpoint detection and response tools such as SentinelOne.
  • Strong logs, events, and telemetry usage to build high-signal detections.
  • Strong programming or scripting skills (Python, Go) with automation.
  • Understanding attacker behavior and translating to detection strategies.
  • Experience defining alerting models and reducing noise while maintaining coverage.
  • Ability to operate in ambiguous environments and create structure.
  • Strong cross-functional communication and leadership.

Responsibilities

  • Own the design and evolution of threat detection and security operations capability.
  • Define detection strategy across cloud infrastructure, applications, and endpoints.
  • Establish and improve SIEM and monitoring architecture for signal quality, coverage, and scalability.
  • Design and implement detection-as-code practices, setting standards for how detection logic is built, tested, and maintained.
  • Drive visibility across all critical assets, ensuring endpoints, services, and identities are monitored.
  • Take ownership of endpoint security monitoring (e.g., SentinelOne), including integration into centralized detection workflows.
  • Lead the design and rollout of automated security controls, including secrets rotation for high-risk systems.
  • Define alerting strategy, including severity models, escalation paths, and on-call expectations.
  • Lead investigations into complex or ambiguous security signals, setting the standard for root cause analysis and response.
  • Partner with engineering teams to improve instrumentation and ensure systems emit high-quality security signals.
  • Define and track metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Mentor and guide other engineers, raising the overall detection and security-operations capability.

Skills

Security engineering
Cloud AWS knowledge
Programming Python/Go
SentinelOne/EDR
Logging/telemetry analysis
Alerting models
Cross-functional communication

Tools

SentinelOne
SIEM systems

Job description

Envoy is seeking a Staff Security Engineer to own and evolve our security operations and threat-detection capabilities from our San Francisco HQ. You will define detection strategies across cloud, applications, and endpoints, enhance our SIEM, and drive automated controls and robust alerting.

This on-site role emphasizes engineering-led security with measurable impact and strong cross-functional collaboration.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Threat Detection & SecOps Engineer
Staff Threat Detection & SecOps Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Member of Technical Staff, SecOps & Threat Detection (Staff/Principal Engineer)
Member of Technical Staff, SecOps & Threat Detection (Staff/Principal Engineer)

Envoy • San Francisco (CA)

On-site
USD 180,000 - 240,000
Member of Technical Staff, SecOps & Threat Detection Engineer
Member of Technical Staff, SecOps & Threat Detection Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000
DevSecOps Engineer (Threat Detection & Penetration Testing)
DevSecOps Engineer (Threat Detection & Penetration Testing)

Bask Health LLC • New York (NY)

On-site
USD 80,000 - 120,000
Senior Threat Detection & Response Engineer - Equity
Senior Threat Detection & Response Engineer - Equity

Rippling • San Francisco (CA)

On-site
USD 151,000 - 280,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Staff Security Engineer: Detection & Response Leader
Staff Security Engineer: Detection & Response Leader

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000
Staff Corporate Security Engineer - Remote Threat Detection
Staff Corporate Security Engineer - Remote Threat Detection

Entrata • Lehi (UT)

Hybrid
USD 170,000 - 278,000
Flexible work options
Comprehensive health coverage
HSA/FSA programs
+4
Security Engineer - Enterprise SIEM & AI Security
Security Engineer - Enterprise SIEM & AI Security

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Staff Security Engineer: Threat Intelligence & AI (Remote)
Staff Security Engineer: Threat Intelligence & AI (Remote)

Multi Media LLC • Northern (KY)

Hybrid
USD 188,000 - 227,000
Fully Remote Optional
Health, Vision, Dental, Life Insurance
Unlimited PTO
+3