Detection and Response Engineer

Modal, Inc

$130K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in detection engineering or incident response roles
  • Strong software engineering background with production experience
  • Experience in cloud-native and distributed systems security
  • Knowledge of cloud infrastructure, Kubernetes, and Linux
  • Proficiency in SQL for security event investigations
  • Interest in applying AI for security solutions
  • Excellent communication skills, both written and verbal

Responsibilities

  • Design and develop high-fidelity threat detection systems
  • Enhance detections using telemetry and incident intelligence
  • Increase visibility across cloud and production systems
  • Lead investigations in production and cloud environments
  • Create automation to improve investigation efficiency
  • Implement post-incident enhancements to mitigate future threats
  • Develop internal security tooling to streamline workflows

Benefits

  • Work with cutting-edge AI technologies
  • Collaborate closely with diverse engineering teams
  • Opportunity to improve and secure large-scale infrastructures
  • Focus on automation to enhance operational effectiveness
  • Gain exposure to high-growth engineering environments
Full Job Description
The Role:

We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform.

This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness.

You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.

What You'll Work On:
Detection Engineering
  • Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
  • Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services
Incident Response
  • Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
  • Build playbooks and automation that reduce investigation time and improve response consistency
  • Drive post-incident improvements that eliminate entire classes of future incidents
Security Tooling & Automation
  • Build internal tooling that improves detection, investigation, and response workflows
  • Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry
  • Improve the collection, quality, and usability of security telemetry across the platform
Engineering Partnership
  • Partner with engineering teams to ensure new systems are observable and secure by default
  • Help teams instrument services with the telemetry needed for effective detection and response
  • Drive security improvements that make the platform easier to defend over time
What We're Looking For:
  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus
  • Strong software engineering skills with experience building production systems
  • Experience investigating security incidents in cloud-native or distributed environments
  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking
  • Experience building detections using logs, telemetry, behavioral signals, or large-scale event data
  • Strong SQL skills for investigating security events and developing detections
  • Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems
  • Strong written and verbal communication skills
Preferred Qualifications:
  • Experience building AI- or LLM-powered security tooling
  • Experience with SIEM, SOAR, or EDR platforms
  • Experience with Kubernetes security or large-scale cloud infrastructure
  • Experience with threat hunting, malware analysis, or digital forensics
  • Experience contributing to security operations in a high-growth engineering organization

Similar Jobs

More Jobs at Modal, Inc

More Information Technology Jobs

Find similar Detection and Response Engineer jobs: