Applied Methods
~The MetaSecurityDetection & Incident Response

Detection & Incident Response

Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.

$ titles --canonical
Security Engineer, Detection & ResponseIncident Response EngineerSOC AnalystThreat Detection EngineerDFIR AnalystSecurity Operations Engineer
Open Jobs45
Companies Hiring20
$ expectations --role detection-&-incident-response

Measured across 45 of 45 open postings.

51%
expect AI in the role's own work
4% state it as a requirement
7%
work directly with customers
13%
manage people
Mid
most common level
51% of open postings
BY LEVEL

This role is advertised at 2 levels, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.

LevelShareMedian yearsMedian pay
Mid51%(23)5—
Senior24%(11)——

A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate. 3 levels with fewer than 10 open postings are not shown.

WHAT THEY ASK FOR, VERBATIM

“Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.”

Notion · Security Engineer, Detection and Response

“Experience building detections or guardrails for AI agents, LLM tooling or MCP servers”

Runway · Detection & Response Engineer

“You can apply statistical or machine-learning methods to security analysis”

Nscale · Staff Security Engineer, Data Science Engineering

“defending cutting-edge AI/AGI systems against adversaries, securing systems that are fundamentally different from anything you've protected before”

Writer · Security engineer, detection and response (UK)
$ barriers
46%
advertised as remote
of postings that state a work mode
7%
state a degree requirement
4%
need a security clearance
82%
still advertised a month later
3 points faster than the board

Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.

$02

Skills

What companies are looking for in this role.

$ skills --core

Detection engineering

89%

Incident response and forensics

76%

Threat intelligence and hunting

69%

Security engineering

49%

Security operations management

44%

Security data analysis

42%

Security tooling and automation engineering

27%

Cloud and infrastructure security

22%

Threat modeling and architecture review

11%

Incident response and reliability

11%

Data pipeline engineering

9%
$ skills --emerging

AI safety and guardrails

13%

Hands-on AI tool fluency

11%

AI red teaming and safety testing

11%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonmoderate
SQLmoderate
Golow
$ tech --platform
AWSmoderate
Google Cloud Platformmoderate
Kubernetesmoderate
Azurelow
Cloud platformslow
Linuxlow
Microsoft Entra IDlow
Oktalow
$ tech --concept
EDRmoderate
MITRE ATT&CKmoderate
SIEMmoderate
AI agentslow
SOARlow
$04

Open Jobs

45 open Detection & Incident Response jobs across 20 companies.

Nscale4d
Senior Detection & Response Engineer, Cyber Defense
Houston; New York; San Francisco; Seattle·Security
Databricks4d
Staff Security Software Engineer - Agentic Security Engineering
United States·Security
Notion1w
Security Engineer, Detection and Response
San Francisco, California·Security
Anthropic2w
Incident Response Manager - Privacy
San Francisco, CA | New York City, NY·Security
Runway2w
Detection & Response Engineer
Remote·Security
Nscale2w
Staff Security Engineer, Data Science Engineering
Houston; New York; San Francisco; Seattle·Security
Writer2w
Security engineer, detection and response (UK)
London, UK·Security
Writer2w
Security engineer, detection and response
San Francisco, CA·Security
Artemis Security2w
Security Research Engineer
Remote·Security
Artemis Security2w
Detection Engineer
Remote·Security
Doppel3w
Applied Cyber, Email Security (Detection Engineering)
US Remote·Security
CoreWeave3w
Senior Security Engineer, eDiscovery, Insider Risk
Remote·Security
Nscale1mo
Senior Staff Security Engineer, Incident Response
Houston; New York; San Francisco; Seattle·Security
Figma1mo
Security Scientist
San Francisco, CA • New York, NY • United States·Security
Legora1mo
(Senior OR Staff) Detection & Response Engineer
New York City·Security
Lambda1mo
Senior Manager, Detection and Response
Bellevue Office·Security
Anthropic1mo
Security Engineer - Threat Intel
New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY·Security
Synthesia1mo
SecOps Security Engineer (Staff-level, L6)
US Remote·Security
Nebius1mo
Security Analyst- Tier 2
Tel Aviv, Israel·Security
Modal1mo
Detection and Response Engineer
New York·Security