About this roleAs our first Detection & Response engineer, you'll build that capability from the ground up focused on our enterprise environment. Looking for and monitoring threats within identity systems our employees authenticate through, the laptops they work on, the SaaS applications that run the business, our enterprise network, and the internal infrastructure behind it. You'll decide what we monitor, build the pipelines and detections that monitor it, and write the playbooks we run when something fires. This is a zero-to-one role and it will suit someone who enjoys building with a lot of autonomy.
What You'll Do- Shape the technical direction for detection and response at Faire. Define what good looks like, build the roadmap that gets us there, and make the case for the tooling and support it needs.
- Build detection engineering for Faire's enterprise environment end to end. Telemetry pipelines, detection content, alert routing, and enrichment.
- Bring a threat-informed point of view. Track how adversaries operate against companies like ours and translate that into detections, hunts, and tabletop exercises that test whether we'd catch it.
- Own detections and data pipelines written as IaaC.
- Automate triage, enrichment, and response so alert volume can grow without a proportional increase in analyst time.
- Work with IAM, CPE, NetEng, and IT Infrastructure Engineering to get the telemetry you need.
- Partner with Enterprise Security to translate detection findings into control improvements, and hand root causes to the teams that own them with enough context that they actually get fixed.
Qualifications- Deep hands-on experience in detection engineering, incident response, or security operations, with a track record of building capability
- Depth in corporate attack surfaces such as identity providers and SSO, endpoint and EDR telemetry, email security, SaaS logs, device management signals, and corporate network access.
- Strong proficiency in Python and query language such as SQL.
- The ability to build and maintain detection-as-code pipelines yourself rather than specify them for someone else to build.
- Practical experience with SIEM, EDR, and security analytics platforms
- Investigative depth on endpoints and in cloud and SaaS environments, so you can reconstruct what happened across an IdP, a laptop, and a SaaS admin console, and say what you know versus what you're inferring.
- Excellent written communication and a collaborative approach to influence. You'll explain to engineers why a detection matters and to leadership what an incident actually means.
- Bonus points for experience as a founding security hire, insider threat or data loss detection, an offensive security background against corporate identity and endpoint paths, incident commander experience, endpoint or cloud forensics depth, or a clear view on what belongs in a SIEM versus a data warehouse.
Salary RangeSan Francisco: the pay range for this role is $174,500 to $240,000 per year.
This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.
Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting.
Why you'll love working at Faire- Move fast: You'll own meaningful problems that serve customers around the globe with the agency to move fast and see your results clearly.
- Equipped to scale: We invest in what matters, including the latest enterprise AI tools, to help you work smarter and get more out of every day.
- Best in class: Our team is full of sharp, kind, and generous colleagues who care about their craft and about helping you grow in yours.
- Real rewards. Competitive pay, equity, and comprehensive benefits designed to support your life inside and outside of work.
- Belonging: We're intentional about building an environment where every Faire employee has equal access to opportunities, growth, and success.
Faire was founded in 2017 by a team of early product and engineering leads from Square. We're backed by some of the top investors in retail and tech including: Y Combinator, Lightspeed Venture Partners, Forerunner Ventures, Khosla Ventures, Sequoia Capital, Founders Fund, and DST Global. We have headquarters in San Francisco and Kitchener-Waterloo, and a global employee presence across offices in Toronto, London, and New York. To learn more about Faire and our customers, you can read more on our blog.