22 days ago
Stockholm, SwedenStaff+
Responsibilities
- Build the detection engineering platform, including telemetry pipelines, detections-as-code, automated triage, and response playbooks.
- Design and own a 24/7 security incident response process supported by a small human and agent team.
- Lead high-severity incidents through detection, containment, eradication, post-mortem, and follow-through.
- Proactively hunt across corporate, production, and AI-agent surfaces and convert findings into durable detections.
- Define and build world-class detection and response capabilities for an AI-native company.
Requirements
- Require 8+ years in detection engineering, incident response, or threat hunting, including at least 3 years at staff or principal level.
- Strong software engineering background with experience building detections as code.
- Deep experience with cloud telemetry from GCP, AWS, or Cloudflare; endpoint EDR; identity logs; and modern SIEM/data-lake stacks such as Panther, Elastic, Snowflake, or ClickHouse.
- Battle-tested incident commander with experience leading real high-severity incidents from first alert through public post-mortem.
- Experience with MITRE ATT&CK, threat intelligence, purple teaming, and red team collaboration.
- Detection for LLM or agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering organizations is a bonus.
Tech Stack
AWSClickHouseCloudflareGitHub ActionsGoGoogle BigQueryGoogle Cloud PlatformGrafanaReactRustSnowflakeTerraformTypeScript