Modal

Detection and Response Engineer

Modal
Apply
3 hours ago

Base Salary

$150k - $270k/yr

Responsibilities

  • Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across infrastructure and production systems.
  • Improve detections using telemetry, threat intelligence, and incident lessons learned.
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services.
  • Lead or participate in investigations across production infrastructure, cloud environments, and internal systems.
  • Build investigation playbooks and response automation that improve speed and consistency.
  • Drive post-incident improvements that eliminate future incident classes.
  • Build internal tooling for detection, investigation, and response workflows.
  • Use LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
  • Improve the collection, quality, and usability of security telemetry across the platform.
  • Partner with engineering teams to make new systems observable and secure by default.
  • Help teams instrument services with telemetry needed for effective detection and response.
  • Drive security improvements that make the platform easier to defend over time.

Requirements

  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus.
  • Strong software engineering skills and experience building production systems.
  • Experience investigating security incidents in cloud-native or distributed environments.
  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking.
  • Experience building detections from logs, telemetry, behavioral signals, or large-scale event data.
  • Strong SQL skills for investigating security events and developing detections.
  • Interest in applying AI and LLMs to detection, investigation, and response, including emerging threats involving AI-powered systems.
  • Strong written and verbal communication skills.
  • Preferred: experience building AI- or LLM-powered security tooling.
  • Preferred: experience with SIEM, SOAR, or EDR platforms.
  • Preferred: experience with Kubernetes security or large-scale cloud infrastructure.
  • Preferred: experience with threat hunting, malware analysis, or digital forensics.
  • Preferred: experience contributing to security operations in a high-growth engineering organization.

Categories

Modal

About Modal

51-200 employees

Customers rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale. Every era of computing came with new workloads that previous infrastructure couldn't serve: mainframes, databases, the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice. The window to build is open right now.