Security Engineer, Detection & Response

Scale AI · New York, NY; San Francisco, CA; Seattle, WA; Washington, DC · Public Sector Engineering · listed April 10, 2026

The shape of it

Seniority
Senior
Experience asked
5+ years
Where
Not stated
Stated pay
$237,600 – $297,000 USD
Requirements listed
7
Length
938 words

In the posting’s own words

We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering — you won't just investigate incidents, you'll build the systems that detect, contain, and prevent them. You will design and ship high-precision detections across cloud services and enterprise SaaS, develop automation that shortens response timelines, and mature the telemetry pipelines that make it all possible. Your ability to write production-quality code is just as important as your ability to triage an alert.

What it asks for · 7

  • 5+ years of experience in Detection Engineering, Incident Response, or Security Operations, with a strong emphasis on building and shipping security tooling and automation.
  • Proficiency in at least one programming language (e.g., Python, Go) and comfort writing production-grade code — not just scripts.
  • Practical experience with SIEM, EDR, and SOAR tools, with a preference for candidates who have built integrations or extended these platforms programmatically.
  • Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs.
  • Familiarity with digital forensics tools and malware analysis techniques.
  • Experience with cloud-native environments (e.g., AWS, GCP, Azure) and the security telemetry those environments generate.
  • Strong communication skills, with the ability to translate complex security findings into clear business impact.

Tools and skills named

Security & compliance
  • Security11×
Cloud & infra
  • AWS
  • Azure
  • GCP
Go to market
  • SaaS
Languages
  • Python

Words the posting leans on

  • security11×
  • detection9×
  • incident7×
  • response6×
  • engineering5×
  • automation4×
  • experience4×
  • workflows4×
  • e.g3×
  • impact3×
  • incident response3×
  • investigations3×
  • adversary2×
  • alerting2×
  • attack2×
  • build2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Scale AI

every open role at Scale AI

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Scale AI on August 4, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.