2 months ago
Base Salary
$150k - $270k/yr
Responsibilities
- Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across infrastructure and production systems.
- Improve detections using telemetry, threat intelligence, and incident lessons learned.
- Improve visibility across cloud infrastructure, containers, identity systems, and production services.
- Lead or participate in investigations across production infrastructure, cloud environments, and internal systems.
- Build investigation playbooks and response automation that improve speed and consistency.
- Drive post-incident improvements that eliminate future incident classes.
- Build internal tooling for detection, investigation, and response workflows.
- Use LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry.
- Improve the collection, quality, and usability of security telemetry across the platform.
- Partner with engineering teams to make new systems observable and secure by default.
- Help teams instrument services with telemetry needed for effective detection and response.
- Drive security improvements that make the platform easier to defend over time.
Requirements
- Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus.
- Strong software engineering skills and experience building production systems.
- Experience investigating security incidents in cloud-native or distributed environments.
- Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking.
- Experience building detections from logs, telemetry, behavioral signals, or large-scale event data.
- Strong SQL skills for investigating security events and developing detections.
- Interest in applying AI and LLMs to detection, investigation, and response, including emerging threats involving AI-powered systems.
- Strong written and verbal communication skills.
- Preferred: experience building AI- or LLM-powered security tooling.
- Preferred: experience with SIEM, SOAR, or EDR platforms.
- Preferred: experience with Kubernetes security or large-scale cloud infrastructure.
- Preferred: experience with threat hunting, malware analysis, or digital forensics.
- Preferred: experience contributing to security operations in a high-growth engineering organization.
Tech Stack
Categories
About Modal
Modal builds a serverless compute platform for AI and data workloads, offering instant GPU access, sub-second container starts, and native storage to run inference, fine-tuning, and batch jobs. It sells a usage-based cloud service to developers and ML teams to deploy generative models and pipelines. Privately held and headquartered in New York City, its customers include companies like DoorDash and Ramp.
