Detection & Response Engineer
π San Francisco, United States
USD 250,000-350,000 per year
SCRAPED
Used Tools & Technologies
Not specified
Required Skills & Competences ?
Security @ 3 Python @ 5 AWS @ 3 Azure @ 3 Bash @ 5 macOS @ 3 PowerShell @ 5Details
Perplexity is seeking a highly skilled, experienced and hands-on Detection & Response Security Engineer to join the Security team, revolutionizing the way people search and interact with the internet. You will build, operate, and evolve detection and response systems, tools, and processes that provide deep visibility and rapid response capabilities, enabling innovation while keeping users and the business secure at scale. The role is hybrid in San Francisco.
Responsibilities
- Design and implement scalable detection and response solutions that integrate directly into engineering and IT workflows.
- Lead threat detection projects, investigation workflows, and technical incident response for security events.
- Build and maintain infrastructure and tools for detection rule lifecycle management and continuous improvement.
- Develop, measure, and tune detection rules for effective and sustainable operations across our environment (cloud, endpoints, SaaS, AWS, macOS, Windows, etc.).
- Automate manual response processes and containment actions for security incidents.
- Ensure deep visibility and control over identity, endpoints, productivity suites, and cloud resources.
- Collaborate with engineering, IT, and product teams to investigate, remediate, and drive incident postmortems.
- Drive improvements in IAM, device management, and cloud usage securely.
- Stay current on adversary tactics, techniques, and procedures (TTPs); drive ongoing maturity of the detection and response program.
- Work with external partners (pen testing firms, bug bounty researchers) to rapidly detect and respond to new vulnerabilities and threats.
Requirements
- 4+ years of experience in Security Operations, Detection & Response, Incident Response, or similar roles.
- Strong knowledge of detection engineering, response automation, and SIEM/SOAR toolchains.
- Experience designing or managing monitoring infrastructure for endpoints, cloud, and SaaS environments.
- Familiarity with adversary TTPs, threat intelligence, and modern attacker methods.
- Proficiency in scripting languages (Python, Bash, PowerShell, etc.) for automation.
- Experience with cloud infrastructure platforms (preferably AWS, Azure).
- Ability to independently run investigations, manage projects, and prioritize efforts for risk reduction.
- Bonus: Experience collaborating on cutting-edge AI research or using AI to improve detection and response.
Compensation & Benefits
- Cash compensation range: $250,000 - $350,000 per year. Final offer amounts are determined by multiple factors including experience and expertise and may vary from the amounts listed above.
- Equity: In addition to base salary, equity may be part of the total compensation package.
- Benefits: Comprehensive health, dental, and vision insurance for you and your dependents. Includes a 401(k) plan.