Staff Detection Engineer

Fluidstack

$130K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security operations, detection engineering, or incident response in a high-growth tech or cloud-native environment.
  • Proven experience building and scaling a detection engineering function with clear programmatic outcomes.
  • Hands-on expertise with cloud telemetry (AWS, GCP, Azure) and endpoint telemetry (EDR, OS-level signals).
  • Strong automation and scripting skills in Python or similar, capable of building detection-as-code pipelines independently.
  • Incident response experience in a high-pressure, large-scale environment, with impactful postmortems.
  • Ability to lead technically without heavy management support, driving initiatives and execution.
  • Proficient in collaboration across teams to achieve shared security goals.

Responsibilities

  • Develop and establish the detection engineering function from scratch, focusing on comprehensive telemetry pipelines.
  • Manage the end-to-end process of detection-as-code, ensuring robust testing and deployment protocols.
  • Lead incident response for high-severity incidents, ensuring effective containment and root cause analysis.
  • Automate triage and enrichment processes using Python to handle alert volumes efficiently.
  • Collaborate with leadership to align security strategy with the current threat landscape and detection priorities.
  • Work closely with corp IT and infrastructure teams to obtain necessary telemetry and address root causes of alerts.

Benefits

  • Opportunity to work on groundbreaking AI infrastructure security challenges.
  • Collaborative environment with direct access to leadership and influence on security strategy.
  • Focus on innovation with a commitment to building detection capabilities rather than just operating them.
  • A culture that values exceptional talent and invites diverse skill sets beyond standard qualifications.
  • Possibility to contribute to open-source detection content and security community initiatives.
Full Job Description
The Security & Corp IT Team

The Security & Corp IT team protects the people, systems, and infrastructure behind the largest AI compute buildout in history.

Examples of key problems the team is working on:
  • Build detection and response coverage across cloud (AWS/GCP/Azure), endpoint, and identity telemetry for a company whose attack surface spans corporate IT and gigawatt-scale data center infrastructure.
  • Run incident response end to end, from first alert through containment, remediation, and postmortem, without a large SOC to fall back on.
  • Stand up detection-as-code pipelines so every detection is versioned, tested, and deployed like software rather than hand-edited in a console.
  • Harden corp IT foundations (identity, device management, access) so security scales with headcount instead of lagging it.
Role Scope
  • Build the detection engineering function from the ground up: telemetry pipelines, detection content, alert routing, and response runbooks, with coverage you can defend against a threat model, not just a tool checklist.
  • Own detection-as-code end to end, writing detections across cloud and endpoint sources with tests, version control, and CI so a bad rule never ships silently.
  • Lead incident response for high-severity events, driving containment and root cause, and closing out each incident with detections that catch the same class of attack next time.
  • Drive automation of triage and enrichment in Python (or similar) so alert volume scales without proportional headcount.
  • Partner directly with leadership on security strategy, translating threat landscape and detection gaps into a prioritized roadmap with clear tradeoffs.
  • Work across corp IT and infrastructure teams to get the telemetry, logging, and access you need, and to fix the root causes your detections keep surfacing.
What We're Looking For

The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would.
  • 8+ years in security operations, detection engineering, or incident response, with time spent at a high-growth tech company, cloud-native infrastructure provider, or top-tier MDR/threat intel firm.
  • You've built or scaled a detection engineering function, not just operated inside one: you can point to the program, the pipeline, and the coverage that exist because of you.
  • Deep hands-on experience writing detections against cloud telemetry (AWS, GCP, or Azure control plane and audit logs) and endpoint telemetry (EDR event streams, OS-level signals).
  • Strong scripting and automation skills in Python or similar, enough to build and maintain detection-as-code pipelines yourself rather than spec them for someone else.
  • Incident response experience at a company operating at significant scale, where you led response under pressure and your postmortems changed how the company operates.
  • You operate as a technical lead without heavy management overhead: you set direction, make the calls, and do the work.
  • You work well across corp IT and infrastructure teams in a fast-moving environment, and you get telemetry and fixes shipped by making the case, not by escalating.
  • Bonus: experience securing GPU clusters, HPC environments, or physical data center infrastructure, or contributions to open-source detection content (Sigma, community rule sets).


We are committed to pay equity and transparency.

Similar Jobs

More Jobs at Fluidstack

More Information Technology Jobs

Find similar Staff Detection Engineer jobs: