Base Salary
$182k - $202k/yr
Responsibilities
- Design, build, and maintain detection-as-code capabilities across cloud infrastructure, SaaS applications, endpoints, and identity systems.
- Build automated AI-assisted investigation and response workflows for triage, enrichment, containment, and remediation.
- Develop and deploy AI/LLM-powered tooling to accelerate investigations and reduce alert fatigue.
- Lead and participate in incident response, including detection, investigation, containment, and retrospectives.
- Partner with engineering and platform teams to expand logging, improve observability, and embed detection into the development lifecycle.
- Analyze alert performance, tune detections for stronger signal, and create feedback loops between incidents and detections.
- Identify visibility and coverage gaps and translate ambiguous security problems into concrete detection and response solutions.
- Adapt detection and response capabilities to evolving threats, tools, and priorities.
Requirements
- At least five years of experience in detection and response, security engineering, or security-focused software engineering.
- Strong software engineering fundamentals and proficiency in Python, Go, Ruby, or similar languages, with experience in production codebases.
- Hands-on experience with cloud environments, preferably AWS, including CloudTrail, GuardDuty, and VPC flow logs.
- Experience with log aggregation and analysis platforms such as Datadog, Splunk, or ELK, and endpoint detection tools such as SentinelOne or CrowdStrike.
- Preferred experience building AI/LLM-powered security tooling or applying AI to detection, triage, or investigation workflows.
- Preferred experience with detection-as-code frameworks or custom detection pipelines.
- Familiarity with Docker, Kubernetes, ECS, or EKS is preferred.
- Threat intelligence, threat hunting, forensics, or attacker tradecraft framework experience such as MITRE ATT&CK is preferred.
- Visa/work permit sponsorship is not available, and employment is contingent on a background check.
Benefits
- Medical, vision, dental, life, and disability insurance, with eligibility varying by country.
- Equity stock options and retirement plans.
- Paid public holidays, unlimited PTO, and paid maternity and parental leave.
- Leaves of absence, including caregiver leave and leave under Colorado’s Healthy Families and Workplaces Act.
- Employee Assistance Program.
- Remote role targeted to candidates within approximately 50 miles of Austin, Seattle, Washington, DC, San Francisco, or Boston.
- Visa/work permit sponsorship is not available; employment is contingent on a background check.
Tech Stack
Categories
About HackerOne
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.
