Security Software Engineer, Detection & Response

Vercel · Hybrid - San Francisco, New York City, London · Engineering

Posted 2026-10-08

Apply for this role →

About the role:

We are looking for a Security Software Engineer, Detection & Response, to build the telemetry, logging, and response systems for our Detection & Response team, as a builder, not a queue-triage role. You will build detection and response as software across a multi-cloud fleet of servers, containers, and endpoints, and test where AI and agents can safely take work off responders. This is a hybrid role based in San Francisco, New York City, or London, with three days a week in the office.

What you’ll do:

Deploy and operate telemetry at fleet scale with osquery and extended Berkeley Packet Filter (eBPF) sensors across servers, containers, and endpoints, and own performance overhead, staged rollouts, canaries, and rollbacks

Build and maintain the logging and security information and event management (SIEM) pipeline behind detection, including ingestion, normalization, enrichment, storage, and cost, with detections written as code with tests, code review, and continuous integration and continuous delivery (CI/CD)

Automate response with tooling for host isolation, credential revocation, evidence collection, and enrichment, and test where AI and agents can safely take work off responders

Strengthen the corporate security stack, including endpoint detection and response (EDR) and fleet management across Mac, Windows, and Linux, email security, and GitHub controls

Join the on-call rotation, work with the managed security operations center (SOC) on escalations, and automate evidence collection for System and Organization Controls 2 (SOC 2), Payment Card Industry Data Security Standard (PCI DSS), and ISO audits

What you need:

5+ years in security, infrastructure, or platform engineering, writing production code in a compiled language (Go or Rust preferred) and a scripting language (Python or Bash)

Deployed and operated agents, sensors, or telemetry collectors at fleet scale, such as osquery or eBPF-based tooling

Operated AWS infrastructure, including networking, identity and access management (IAM), logging, and container workloads, with infrastructure as code in Terraform

Built and run a data or logging pipeline, including SIEM operations and SQL for investigation

Bonus if you:

Worked with managed SOC providers or security orchestration, automation, and response (SOAR) platforms

Built or contributed to open source security or observability tooling

Know serverless platforms and API security

Benefits & Compensation:

Competitive compensation package, including equity.

Inclusive Healthcare Package.

Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.

Flexible Time Off.

We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Apply for this role →

← Back to all jobs