Detection & Incident Response
Engineers in this role design and operate detection systems that identify security threats across AI infrastructure, cloud environments, and enterprise platforms, then lead investigations when incidents occur. They combine deep technical expertise in SIEM/SOAR platforms, forensics, and threat analysis with the ability to automate response workflows and mentor teams on detection improvements. These roles typically sit within dedicated Security Operations or Detection & Response teams at AI-native companies, where they bridge the gap between passive monitoring and proactive threat hunting while scaling security capabilities alongside rapid infrastructure growth.
Measured across 45 of 45 open postings.
This role is advertised at 2 levels, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.
| Level | Share | Median years | Median pay |
|---|---|---|---|
| Mid | 51%(23) | 5 | — |
| Senior | 24%(11) | — | — |
A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate. 3 levels with fewer than 10 open postings are not shown.
“Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.”
“Experience building detections or guardrails for AI agents, LLM tooling or MCP servers”
“You can apply statistical or machine-learning methods to security analysis”
“defending cutting-edge AI/AGI systems against adversaries, securing systems that are fundamentally different from anything you've protected before”
Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.
Skills
What companies are looking for in this role.
Detection engineering
Incident response and forensics
Threat intelligence and hunting
Security engineering
Security operations management
Security data analysis
Security tooling and automation engineering
Cloud and infrastructure security
Threat modeling and architecture review
Incident response and reliability
Data pipeline engineering
AI safety and guardrails
Hands-on AI tool fluency
AI red teaming and safety testing
Technology
The tools and technologies that define this role.
Open Jobs
45 open Detection & Incident Response jobs across 20 companies.
Other Security roles
Identifies and mitigates security vulnerabilities in applications and products.
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Conducts offensive security assessments including red teaming, penetration testing, and adversarial simulation.
Designs and maintains identity infrastructure, authentication systems, and access control policies.