Staff Security Engineer, Cloud Detection & Response

Posted Yesterday
Be an Early Applicant
4 Locations
Hybrid
171K-303K Annually
Expert/Leader
Automotive
The Role
Lead cross-functional initiatives to mature cloud and enterprise detection infrastructure, including telemetry pipelines, detection-as-code, logging, and scalable coverage. Design and tune detections for cloud, identity, endpoint, SaaS, CI/CD, and service-to-service threats. Conduct threat hunting, support incident response and on-call operations, apply threat intelligence and adversary emulation, mentor SOC engineers, and improve detection capabilities based on incident lessons learned.
Summary Generated by Built In

Who we are

Aurora’s mission is to deliver the benefits of self-driving technology safely, quickly, and broadly.

The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.

At Aurora, you will tackle massively complex problems alongside other passionate, intelligent individuals, growing as an expert while expanding your knowledge. For the latest news from Aurora, visit aurora.tech or follow us on LinkedIn.

 

What we are looking for

We're searching for a Staff Cybersecurity Engineer to help mature Cloud & Enterprise Detection within our Detection & Response (D&R) team, under the Technical Assurance division. This is a senior individual contributor role focused on driving cross-functional projects that strengthen Aurora's detection infrastructure and expand detection coverage across our cloud infrastructure, enterprise environments. You will scope and lead multi-quarter initiatives that raise the maturity of our detection program and powering detection at scale, executing through your own hands-on work and through close partnership with Cloud Infrastructure, IT, and Platform Engineering teams.

In this role you will

  • Drive cross-functional projects to mature Aurora's detection infrastructure, log ingestion and normalization, detection-as-code pipelines with testing, versioning, and CI/CD for detection content, and scalable, cost-aware telemetry collection

  • Expand detection coverage across cloud and corporate environments and prioritize coverage improvements

  • Design, build, and tune detections for cloud control plane and workload activity, identity-based attacks, endpoint, SaaS threats, abuse of CI/CD and service-to-service communication paths

  • Partner with Cloud Infrastructure, IT, and Platform Engineering to embed logging and detection requirements into system design, and represent D&R in cross-functional working groups and design reviews

  • Integrate threat intelligence and adversary emulation into detection coverage priorities, and conduct proactive threat hunting across cloud, identity, endpoint, and SaaS data

  • Respond to cloud and enterprise security incidents and participate in an on-call rotation, feeding lessons learned back into detection coverage and infrastructure improvements

  • Collaborate with and mentor SOC engineers on cloud and enterprise detection practices, and contribute to quarterly planning for detection infrastructure and coverage initiatives

Required qualifications

  • 10+ years of security experience; demonstrated experience leading cross-functional security projects or programs from scoping through delivery

  • Strong technical foundation in threat detection, incident response

  • Expertise with cloud security across one or more major providers, including cloud-native telemetry and detection sources

  • Experience building or maturing detection infrastructure - SIEM or security data lake pipelines, log onboarding and normalization, detection-as-code workflows

  • Expertise with endpoint detection and response (EDR) and SaaS security monitoring, or comparable host and application telemetry depth

  • Expertise authoring and maintaining detections (anomalous, network, host, identity, or cloud activity) and measuring detection coverage against adversary behavior

  • Experience with incident management, driving cross-departmental collaboration for containment and remediation

  • Expertise with MITRE ATT&CK framework and modern adversarial techniques; understanding of NIST CSF

  • Ability to write quality, testable code in Python

Desirable qualifications

  • Experience designing and implementing Zero Trust Architecture

  • Experience scaling SOC, Detection Engineering with AI/LLM

  • Experience building and architecting data lakes

  • Experience with compliance frameworks (SOC 2, ISO 27001)

For roles based in San Francisco, CA, Mountain View, CA, and Seattle, WA: The salary range for this position is $189,000 - $303,000 per year.

For roles based in Pittsburgh, PA,: The salary range for this position is $171,000 - $273,000 per year.
Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

Working at Aurora

At Aurora, we bring together extraordinarily talented and experienced people united by the strength of our values. We operate with integrity, set outrageous goals, and build a culture where we win together — all without any jerks.

We believe in-person work increases collaboration, empathy and our ability to lead effectively. As a result, we operate in a hybrid work environment where Aurorans are in office at least 3 days per week.

Our Careers page provides insight into what it is like to work at Aurora, and you can find all the latest updates in our Newsroom.

Our commitment to safety

At the core of everything we do is our commitment to safety. Building best-in-class self-driving technology will take time, and we believe that each employee at Aurora has a role in contributing to safety, every step of the way. Aurora expects commitment to our safety policies from every employee, and seeks candidates who take an active responsibility, can contribute to building an atmosphere of trust, and invest in the organization’s long-term success by prioritizing working safely, no matter what.

Our commitment to inclusion

Aurora considers candidates without regard to their race, color, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal, state, and local law. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at [email protected].

For California applicants, information collected and processed as part of your application and any job applications you choose to submit is subject to Aurora’s California Employment Privacy Policy.

Skills Required

  • 10+ years of security experience
  • Experience leading cross-functional security projects or programs from scoping through delivery
  • Strong technical foundation in threat detection and incident response
  • Expertise with cloud security across one or more major cloud providers, including cloud-native telemetry and detection sources
  • Experience building or maturing SIEM or security data lake pipelines, log onboarding and normalization, and detection-as-code workflows
  • Expertise with endpoint detection and response and SaaS security monitoring, or comparable host and application telemetry
  • Expertise authoring and maintaining detections and measuring detection coverage against adversary behavior
  • Experience with incident management and cross-departmental collaboration for containment and remediation
  • Expertise with the MITRE ATT&CK framework and modern adversarial techniques
  • Understanding of the NIST Cybersecurity Framework
  • Ability to write quality, testable code in Python
  • Experience designing and implementing Zero Trust Architecture
  • Experience scaling SOC detection engineering with AI or LLM technology
  • Experience building and architecting data lakes
  • Experience with SOC 2 and ISO 27001 compliance frameworks

Aurora Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Aurora and has not been reviewed or approved by Aurora.

  • Healthcare Strength A broad set of medical plan options with dental and vision, plus company‑paid life and disability, signals strong healthcare support. Mental wellness access, including coaching and therapy sessions, further strengthens the offering.
  • Leave & Time Off Breadth Flexible vacation for salaried employees, 12 paid holidays, and reasonable sick time indicate generous time‑off provisions. Some roles also accrue substantial vacation days annually.
  • Parental & Family Support Paid parental leave and family‑forming reimbursement demonstrate meaningful support for growing families. Coverage for adoption, surrogacy, egg freezing, and genetic testing extends support beyond standard plans.

Aurora Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Mountain View, CA
1,579 Employees
Year Founded: 2017

What We Do

Founded in 2017 by experts in the self-driving industry, Aurora is on a mission to deliver the benefits of self-driving technology safely, quickly, and broadly. To move both people and goods, the company is building the Aurora Driver, a platform that brings together software, hardware and data services to autonomously operate passenger vehicles, light commercial vehicles, and heavy-duty trucks. Aurora is backed by Sequoia Capital, Baillie Gifford, funds and accounts advised by T. Rowe Price Associates, among others, and is partnered with industry leaders including Toyota, Uber, Volvo, and PACCAR. Aurora tests its vehicles in the Bay Area, Pittsburgh, and Dallas. The company has offices in those areas as well as in Bozeman, MT; Seattle, WA; Louisville, CO; and Wixom, MI. To learn more, visit aurora.tech. Aurora is backed by Amazon and Sequoia, among others, and has partnerships with leading transportation companies including PACCAR, Uber, FCA, and Hyundai Group. It tests its vehicles in the Bay Area, Pittsburgh, and Dallas and has offices in those cities as well as in Bozeman, Seattle, Denver, and Detroit. Aurora hires people who want to build the future of transportation. Join us!

Similar Jobs

CoreWeave Logo CoreWeave

Senior Software Engineer

Cloud • Information Technology • Machine Learning
In-Office
4 Locations
1450 Employees
182K-242K Annually

Samsara Logo Samsara

Sr. Manager, Business Operations

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
119K-180K Annually

Eve Logo Eve

Account Executive

Legal Tech • Software • Generative AI
Easy Apply
Remote or Hybrid
United States
180 Employees
340K-384K Annually

The Aerospace Corporation Logo The Aerospace Corporation

Test Engineering Intern - Summer 2027

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Remote or Hybrid
United States
4600 Employees
25-45 Hourly

Similar Companies Hiring

Cox Enterprises Thumbnail
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Atlanta, Georgia
30000 Employees
UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account