Назад
Company hidden
1 час назад

Threat Detection Engineer – Security Operations (AI Security)

113 033 - 140 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Detection Engineer – Security Operations (AI Security) (Splunk/Python/AI): Building and optimizing high-fidelity security detections and AI-augmented detection pipelines across SIEM/SOAR platforms with an accent on threat analytics, automation, and AI-specific attack detection. Focus on developing detection-as-code, evaluating LLM-assisted triage, querying cloud-scale telemetry, and reducing false positives through adversarial testing and validation.

Location: Must be located in the continental U.S. and work on-site five days per week in Mountain View, California.

Salary: $113,033–$140,000 USD annually, excluding bonus, equity, and benefits.

Company

hirify.global develops a digital identity wallet and identity verification platform used by consumers, government agencies, healthcare organizations, and consumer brands.

What you will do

  • Design, implement, test, and tune high-fidelity detections across Splunk, Google Chronicle, Elastic, and Logstash.
  • Build scalable detection rules, anomaly models, and detection-as-code workflows using Python, YAML, Sigma, YARA-L, Kusto, or Lucene.
  • Develop LLM-assisted enrichment, triage, classification, anomaly scoring, similarity search, and log-analysis pipelines.
  • Detect AI-specific threats including prompt injection, model abuse, data exfiltration, model inversion, and shadow AI usage.
  • Query and normalize cloud-scale security telemetry with Snowflake and SQL, including AI system logs and API records.
  • Collaborate with threat intelligence, incident response, and platform engineering teams; participate in tuning, red/blue team exercises, post-incident reviews, and 24x7 on-call rotation.

Requirements

  • 2–4 years of experience in security engineering or security operations.
  • Experience with Splunk, Elastic Stack, Google SecOps/Chronicle, and/or Logstash.
  • Strong Python and SQL skills, with experience authoring reusable detection logic.
  • Hands-on AI literacy, including LLM APIs or AI/ML frameworks, prompt engineering, RAG, or agentic workflows.
  • Understanding of anomaly detection, clustering, embeddings, LLM-based enrichment, MITRE ATT&CK, threat modeling, and behavioral detections.
  • Knowledge of infrastructure-as-code and version control, including Terraform and CI/CD systems.

Nice to have

  • Security certifications such as GCIA, GCIH, GCFA, or Security+.
  • Experience with GCP, GKE, Snowflake Security Data Lake, SOAR integrations, or cloud-native log pipelines.
  • Experience with LangChain, LlamaIndex, red teaming, adversary emulation, or evaluating LLM security weaknesses.
  • Contributions to open-source detection or AI security tooling.

Culture & Benefits

  • Full-time, in-office work environment focused on protecting digital identities.
  • Medical, dental, and vision coverage with HSA and FSA options.
  • 401(k) with company match, parental leave, disability coverage, and insurance programs.
  • Unlimited paid time off subject to policy, including eight company-wide holidays.
  • Learning and development benefit, wellbeing resources, childcare discounts, and employee assistance program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →