Senior Threat Detection Engineer

Posted 2 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
108K-169K Annually
Senior level
Software
Cribl is the AI Platform for Telemetry.
The Role
Design and maintain detection-as-code rules, conduct threat hunts, investigate incidents, and improve security telemetry pipelines. Build KQL detections through GitOps and CI/CD workflows, map coverage to MITRE ATT&CK, tune alert quality, and maintain log parsing and normalization. Participate in incident response, write runbooks, and convert findings into durable detections. Collaborate across security, IT, infrastructure, engineering, and GRC while mentoring teammates and supporting on-call duties.
Summary Generated by Built In

Join the company that’s building the telemetry infrastructure for the AI era. At Cribl, we partner with IT and Security teams at many of the world’s biggest enterprises, including half of the Fortune 100, to bridge the gap between AI ambition and infrastructure reality. As the AI Platform for Telemetry, we give customers the choice, control, and flexibility to manage and analyze telemetry for both humans and agents, so they can build what’s next.

We’re one of the fastest‑growing private companies and a leading player in a massive, fast‑moving market. With a global workforce, we’re remote‑first and grounded in a simple idea: software is a people business. Cribl is the place where curious, collaborative people can do their best work, grow fast, and bring their full selves to the herd.

Why You’ll Love This Role

Cribl builds telemetry infrastructure for some of the world's biggest security teams. Now we're looking for someone to protect Cribl itself. You'll join Cribl's internal security team, Team Alpine, to run detection as code. Our team runs a detection as code pipeline where rules live in Git, are tested in CI, and deploy to our SIEM automatically. AI agents watch for coverage gaps and help review every change.

This is a hands-on senior role covering the whole detection lifecycle. You'll hunt for threats nobody has written a rule for yet, turn what you find into detections, and keep the log pipelines behind those detections healthy. For the first [6–12] months you'll also be a core part of our incident response rotation while we build out that function. You'll lead investigations, and what you learn will feed straight back into the detections. 

If you want your work to show up in production quickly, and you like owning the data as well as the rules, this role is for you. You will partner closely with Product Security, IT, and Legal teams, and report to the Sr. Director, Security Engineering and Operations under the CISO.


As An Active Member Of Our Team, You Will…

Detection Engineering

  • Design, build, test, and tune detections as code (KQL) through a GitOps workflow: issue, pull request, unit and back-testing, then automated deployment
  • Map detections to MITRE ATT&CK, find coverage gaps, and decide where to invest next based on our threat model
  • Review new community and vendor rule releases, such as Sigma, and decide what to adopt, adapt, or skip
  • Cut alert noise by tuning, retiring rules that no longer earn their place, and tracking detection quality metrics

Threat Hunting

  • Plan and run hypothesis-driven hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry
  • Use adversary emulation to generate test events for detections that have nothing to fire on yet
  • Turn hunt findings into durable detections, documentation, and backlog items

Incident Response (initial [6–12] months)

  • Take part in the IR rotation: triage, scope, contain, and investigate security incidents from first alert to closure
  • Run retrospectives and turn the lessons into new detections, playbook updates, and fixes to visibility gaps
  • Write and maintain runbooks so others on the team can respond consistently

Detection Infrastructure & Log Pipelines

  • Assist in ownership of the health of security log flow: onboard new sources, maintain parsing and normalization, and monitor for dropped, delayed, or malformed data
  • Assist and Build and maintain data pipelines with Cribl Stream to route, enrich, and reduce telemetry before it reaches the SIEM
  • Maintain the CI/CD and automation behind the detection program, including GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and PR review

Across the Team

  • Work independently, and design the processes, standards, and tools that help others work well
  • Mentor teammates through code review, pairing, and clear documentation
  • Work with IT, Infrastructure, Engineering, and GRC to close visibility gaps and improve detection coverage
  • This position will require stand-by, on-call, or off-hours duties


If You’ve Got It - We Want It

  • [5+] years in security operations, with significant hands-on time in detection engineering, threat hunting, or incident response
  • Experience writing and maintaining detections as code in a modern SIEM
  • Strong Python skills and comfort with Git-based workflows, code review, and CI/CD
  • Strong in KQL for writing detection queries
  • Working knowledge of MITRE ATT&CK and how to use it for coverage analysis, not just labeling
  • Experience investigating incidents in cloud (AWS, GCP, and/or Azure), SaaS, and identity providers
  • Hands-on experience with log pipelines: getting data in, parsing it, and fixing it when it breaks
  • The judgment to separate a real signal from noise, and to know when to escalate
  • Clear writing for both technical and non-technical audiences: incident summaries, runbooks, detection docs
  • Uses AI as a routine part of engineering work, with concrete examples of how it has changed how you build, test, or investigate
  • Bonus: experience with Cribl Stream or other telemetry pipeline tools
  • Bonus: experience with Sigma rules, adversary emulation (Atomic Red Team, Caldera, or similar), or purple teaming
  • Bonus: experience building agentic or AI-assisted workflows for security operations
  • Bonus: certifications such as GCIH,GCDA, or equivalent experience

#LI-KJ1
#LI-Remote

The salary for this role is dependent on geographic location and will be based on the individual candidate's job-related knowledge, skills, and experience.
In addition to base salary, for sales and some sales-adjacent roles, employees are eligible to earn incentive compensation (commission). For all other roles, employees are eligible to participate in the Cribl Corporate Bonus Program.
In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), and equity.

Base Salary Range
$108,000—$169,000 USD

Bring Your Whole Self

Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us. 

Skills Required

  • 5+ years in security operations, including significant hands-on experience in detection engineering, threat hunting, or incident response
  • Experience writing and maintaining detections as code in a modern SIEM
  • Strong Python skills
  • Experience with Git-based workflows, code review, and CI/CD
  • Strong KQL skills for writing detection queries
  • Working knowledge of MITRE ATT&CK for coverage analysis
  • Experience investigating incidents across cloud environments, SaaS, and identity providers
  • Hands-on experience with security log pipelines, including data ingestion, parsing, and troubleshooting
  • Ability to distinguish genuine security signals from noise and determine when to escalate
  • Clear technical and non-technical writing skills for incident summaries, runbooks, and detection documentation
  • Routine use of AI in engineering, testing, or security investigations, with concrete examples
  • Experience with Cribl Stream or other telemetry pipeline tools
  • Experience with Sigma rules, adversary emulation, or purple teaming
  • Experience building agentic or AI-assisted workflows for security operations
  • GCIH, GCDA, or equivalent certification or experience
  • Availability for standby, on-call, or off-hours duties

Cribl Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cribl and has not been reviewed or approved by Cribl.

  • Affordable Benefits — Medical and dental premiums are fully covered for individuals in the U.S., with low costs for dependents, and the plans are described as low‑cost overall. This positions healthcare expenses favorably for many employees.
  • Leave & Time Off Breadth — Unlimited PTO, paid holidays, and periodic company “refresh” or winter‑break days provide ample time away. Flexible schedules further support taking time when needed.
  • Wellbeing & Lifestyle Benefits — A monthly stipend for home office, phone, and internet, plus strong remote‑work setup support, underpin the remote‑first model. Additional perks like recharge days and equipment support bolster day‑to‑day wellbeing.

Cribl Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
1,000 Employees
Year Founded: 2018

What We Do

Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents. Trusted by organizations worldwide, including half of the Fortune 100, Cribl bridges the gap between AI ambition and infrastructure reality. No lock-in. No data loss. No compromises. Cribl’s vendor-agnostic platform ensures data remains portable and interoperable. By cost-effectively handling increasing data volume and variety without delay, Cribl gives enterprises the choice, control, and flexibility to build what’s next.

Why Work With Us

We are building the company that will become the industry leader in IT and Security data. But, doing that doesn’t mean we’re always serious. We approach our work fearlessly, learn quickly, improve constantly, and celebrate our wins at every turn. And more importantly, we laugh a lot.

Gallery

Gallery

Similar Jobs

Samsara Logo Samsara

Senior Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Dallas, TX, USA
4000 Employees
158K-239K Annually

Samsara Logo Samsara

Senior Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Seattle, WA, USA
4000 Employees
158K-239K Annually
Remote or Hybrid
US
15100 Employees
137K-191K Annually

Dragos Logo Dragos

Senior Threat Detection Engineer

Security • Cybersecurity
Easy Apply
Remote
United States
295 Employees
152K-152K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account