
Senior Security Engineer, Detection & Response
Aircall.io, Inc.7 hours ago
Base Salary
$180k - $220k/yr
Responsibilities
- Lead the direction and strategy of Aircall’s Detection and Response program.
- Develop, test, simulate, tune, and deploy detection logic and alerts across logs, telemetry, hosts, networks, and cloud environments.
- Own the security data platform, including SIEM operations, ingestion pipelines, parsers, enrichment, normalization, infrastructure as code, retention, cost, and capacity.
- Build security tools and AI- and agent-based tooling for alert triage, investigation, and detection development.
- Conduct proactive threat hunting across company-wide and production environments.
- Lead incident investigations, containment, remediation, root cause analysis, and post-incident reviews.
- Assess security for new product features, including AI- and LLM-backed services.
- Maintain detection documentation, runbooks, alert definitions, tuning guidelines, and metrics.
- Collaborate with Engineering, Product, Fraud, Privacy, and Legal teams.
- Participate in on-call and threat-response rotations and coordinate high-severity events.
- Track attacker techniques, threat intelligence, and MITRE ATT&CK patterns to improve detections.
- Participate in interviewing and hiring Security and Infrastructure engineering candidates.
Requirements
- At least 5 years of hands-on experience in security operations, detection engineering, incident response, threat hunting, or similar work, or an equivalent combination.
- Production-grade Python and Terraform experience, including services or Lambdas and Terraform modules maintained in production.
- Deep knowledge of adversarial tactics, techniques, procedures, threat actor behavior, and the ATT&CK framework.
- Experience building production-quality detections from scratch with low false-positive rates.
- Hands-on experience with SIEM or log analytics platforms, data lakes, and alerting or monitoring tools.
- Experience with Azure, GCP, and AWS, including AWS VPCs, IAM, networking, and private service endpoints.
- Experience with digital forensics, host-based detection, endpoint telemetry, process and network visibility, and cloud observability.
- Experience responding to production incidents through investigation, timeline construction, root cause analysis, and containment.
- Familiarity with security automation, orchestration, playbooks, response automation, and alert triage workflows.
- Ability to own a security domain, set priorities, and drive initiatives with minimal oversight.
- Strong communication skills and ability to explain detection logic, trade-offs, and risk to engineers and leadership.
- Preferred experience securing LLM and agent systems, including Azure Foundry, Bedrock/AgentCore, LangGraph, guardrails, policy-based authorization, prompt-injection defense, and agent evaluation.
- Preferred purple-team, red-team, application security, production security, vulnerability management, fraud and abuse investigation, open-source detection tooling, or security conference experience.
Benefits
- Base salary range is $180,000–$220,000 USD.
- Work-life balance, a fast-learning environment, entrepreneurial culture, and strong team spirit.
- Multicultural workplace with more than 45 nationalities.
- Competitive salary package and benefits.
Tech Stack
Categories
About Aircall.io, Inc.
Aircall builds a cloud-based business phone and contact center platform for sales and support teams, integrating voice, SMS, WhatsApp, and social channels with 200+ CRM/helpdesk apps. It sells its software via subscription to companies that want VoIP calling, call routing/recording, analytics, and AI features like automated agents and post-call summaries. Founded in 2014 and privately held, it serves 22,000+ businesses worldwide, with operations spanning Paris (European HQ) and the Seattle area (North American HQ).