Obsidian Security

Detection Engineering Lead – Taiwan

Obsidian Security
Apply
2 hours ago
Taipei, TaiwanStaff+
H1B Sponsor

Responsibilities

  • Establish and lead the Taiwan detection engineering function, including technical direction, operating model, quality standards, and hiring plan.
  • Research cloud, identity, and SaaS threats and translate attacker behavior into actionable detection opportunities and threat models.
  • Design, author, test, maintain, and tune detection rules and behavioral detection models.
  • Define telemetry, enrichment, correlation, and historical-context requirements for effective detections.
  • Partner with platform and data engineering teams to build scalable detection capabilities and production processing pipelines.
  • Develop detection testing, simulation, coverage measurement, versioning, release management, and lifecycle frameworks.
  • Measure and improve detection precision, recall, explainability, performance, and customer value.
  • Investigate false positives and false negatives and improve detection logic and data quality.
  • Map detection coverage to threat frameworks, attack techniques, product use cases, and customer risks.
  • Collaborate with product management and customer success to understand customer environments and detection requirements.
  • Document detection intent, evidence, expected behavior, limitations, and recommended response actions.
  • Mentor detection engineers and security researchers and collaborate across Taiwan, the US, the UK, and Australia.

Requirements

  • Significant experience in detection engineering, threat research, security analytics, incident response, threat hunting, or a related security discipline.
  • Experience leading security research or detection initiatives and mentoring practitioners.
  • Strong knowledge of attacker behavior, identity threats, cloud security, and enterprise SaaS environments.
  • Demonstrated experience developing production detections using rules, queries, correlations, statistical methods, or behavioral models.
  • Experience working with large security datasets such as audit events, authentication activity, identity data, application logs, or cloud telemetry.
  • Strong data analysis skills and proficiency with relevant query, scripting, or programming languages.
  • Understanding of the detection lifecycle, including research, development, validation, deployment, monitoring, tuning, and retirement.
  • Experience measuring detection quality and using production feedback to improve security outcomes.
  • Ability to communicate technical security concepts clearly to engineering, product, customer-facing, and executive audiences.
  • Strong written and verbal English communication skills and the ability to collaborate across regions, time zones, functions, and cultures.
  • Preferred experience with identity security, SaaS security, cloud detection and response, SIEM, UEBA, EDR, XDR, or detection-as-code systems.
  • Preferred familiarity with identity-based attacks, MITRE ATT&CK or similar frameworks, machine learning or anomaly detection for security, generative AI security applications, real-world intrusions, incident response, and scaling detection engineering teams.
  • Mandarin proficiency and experience working in Taiwan or with globally distributed APAC teams are preferred.

Tech Stack

DatabricksGoogle Cloud

Categories

Obsidian Security

About Obsidian Security

51-200 employees

Every enterprise runs on software it doesn't own: third-party apps, AI copilots, and agents logging in with OAuth tokens nobody's reviewing. Obsidian Security secures all of it, discovering every third-party app and AI feature connected to your business, governing risky permissions, and detecting threats in real time. Trusted by the world's most regulated, highest-scale enterprises. If you're adopting AI, you're adopting third-party software faster than ever we make sure that doesn't mean adopting its risk. SPECIALTIES AI Security Posture Management, AI Security, SaaS Security Posture Management, Identity Threat Detection & Response, AI & Agentic Security, Continuous Governance, OAuth & API Risk, Supply Chain Integration Risk, App-to-App Security Subscribe to our newsletter: https://www.linkedin.com/newsletters/true-positives-7435782529825038336/ Get a demo: https://www.obsidiansecurity.com/get-a-demo Sign up for a trial: https://www.obsidiansecurity.com/trial