Responsibilities
- Lead detection engineering for Fluidstack’s IT surface, including cross-domain detections where IT bridges OT or physical surfaces.
- Author and tune production detections as code, with peer review, CI/CD, and measured precision and recall.
- Apply AI and machine learning to build effective detections, including behavioral analytics and anomaly detection at scale.
- Develop novel detection tooling, including agentic capabilities that use LLMs for triage, investigation, and response.
- Set the engineering standards, coverage methodology, and quality metrics for the detection engineering discipline.
- Conduct threat and security research that informs detection logic, surfaces coverage gaps, and drives new detections.
- Partner with security platform engineers, incident response, and threat intelligence to close the detection-to-response loop.
- Participate in the on-call rotation for incident response.
Requirements
- You have strong detection engineering experience and have built detection programs at scale.
- You are fluent across coding and querying languages, pick up new ones quickly, and have handled security-relevant data at massive scale and complexity.
- You have written sophisticated detection logic against diverse telemetry, not synthesized it from vendor templates.
- You have handled security incidents and investigated anomalies as part of a team.
- You have set up detection CI/CD, or know how you would build it on day one.
- You have well-founded opinions on what makes a detection program work in production.
- You read the agent-first thesis as the most interesting design choice in security operations right now.
- You have built or contributed to internal tooling, not just consumed commercial products.
- You see what is needed, scope it yourself, and run with it.
Nice to Have
- Experience building or operating agentic detection tooling using LLMs.
- Experience designing and tuning LLM-based triage or investigation systems against measured precision and recall.
- Experience with Python and SQL applied to detection development and security data analysis.
- Experience at the boundary between detection engineering and security platform engineering at scale.
- Background in detection or security engineering at GPU compute, HPC, or other hyperscale infrastructure.
Additional Information
- Participate in the on-call rotation for incident response.