Senior Detection and Response Engineer
Seattle, Washington, United States
Full Time Senior-level / Expert Clearance required USD 154K - 231K
Anduril
Anduril Industries, Inc. is an American defense technology company that specializes in advanced autonomous systems.Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
Anduril's Information Security team is looking for a Senior Detection and Response Engineer to lead the development and maturation of our Security Operations (SecOps) capabilities. This is a role with wide berth that will have the latitude to design and implement cutting edge security architecture.
WHAT YOU'LL DO
-
Develop and maintain core SecOps capabilities focusing on threat hunting, purple teaming, detection engineering, runbook automation, and more
-
Lead incident response and investigations across the SecOps function
-
Lead threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other facets incorporating findings into security controls and/or detection signatures
-
Develop detection signatures to capture adversarial behavior across a variety of facets including AWS, Endpoints, SaaS applications, network logs, and more
-
Lead threat hunting initiatives, collaborating with various engineering and product teams to emit signals to incorporate into detections, new telemetry ingestion, and/or security controls
-
Build and maintain large-scale data pipelines, ensuring reliability, timeliness, and accuracy of data being ingested across cloud, SaaS, enterprise, and product environments
-
Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders
REQUIRED QUALIFICATIONS
-
Extensive experience operating in and around SecOps functions
-
Experience automating triage and response of detections, cases, and incidents
-
Experience developing detection signatures to detect and prevent adversarial behavior
-
Programming experience in one or more general purpose languages (Python, SQL, Go, Rust, etc)
-
Experience building and refining SIEM tools, large-scale data pipelines, and logging architecture
-
Experience deploying infrastructure as code (Terraform, CDK, CloudFormation, etc)
-
Experience working in a traditional software development lifecycle (i.e. Github, CI/CD, unit testing)
-
Experience conducting incident response in the Cloud (AWS, Azure, GCP)
-
Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure
-
Strong knowledge of attacker tactics, techniques, and procedures (TTPs)
-
Strong communication skills and experience collaborating with internal and external stakeholders
-
Must be able to obtain and hold a U.S. Top Secret security clearance
PREFERRED QUALIFICATIONS
-
Experience proactively hunting using threat intelligence to identify potential risks and weaknesses in telemetry
-
Experience building custom security tooling to augment capabilities not found off-the-shelf
-
Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
- Platinum Healthcare Benefits: For U.S. roles, we offer top tier platinum coverage (medical, dental, vision) that are 100% covered by Anduril for you and 90% covered for your dependents.
- For UK roles, Private Medical Insurance (PMI): Anduril will cover the full cost of the insurance premium for an employee and dependents.
- For AUS roles, Private health plan through Bupa: Coverage is fully subsidized by Anduril.
- Basic Life/AD&D and long-term disability insurance 100% covered by Anduril, plus the option to purchase additional life insurance for you and your dependents.
- Extremely generous company holiday calendar including a holiday hiatus in December, and highly competitive PTO plans.
- 16 weeks of paid Caregiver & Wellness Leave to care for a family member, bond with your baby, or tend to your own medical condition.
- Family Planning & Parenting Support: Fertility (eg, IVF, preservation), adoption, and gestational carrier coverage with additional benefits and resources to provide support from planning to parenting.
- Mental Health Resources: We provide free mental health resources 24/7 including therapy, life coaching, and more. Additional work-life services, such as free legal and financial support, available to you as well.
- A professional development stipend is available to all Andurilians.
- Daily Meals and Provisions: For many of our offices this means breakfast, lunch and fully stocked micro-kitchens.
- Company-funded commuter benefits available based on your region.
- Relocation assistance (depending on role eligibility).
- 401(k) retirement savings plan - both a traditional and Roth 401(k). (US roles only)
The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process.
Anduril is an equal-opportunity employer committed to creating a diverse and inclusive workplace. The Anduril team is made up of incredibly talented and unique individuals, who together are disrupting industry norms by creating new paths towards the future of defense technology. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws, including the CA Fair Chance Initiative for Hiring Ordinance. We actively encourage members of recognized minorities, women, Veterans, and those with disabilities to apply, and we work to create a welcoming and supportive environment for all applicants throughout the interview process. If you are someone passionate about working on problems that have a real-world impact, we'd love to hear from you!
To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.
Tags: Automation AWS Azure CI/CD Clearance Cloud GCP GitHub Incident response Log analysis Monitoring Privacy Python Rust SaaS SDLC SecOps Security Clearance SIEM SQL Terraform Threat intelligence Top Secret TTPs
Perks/benefits: Career development Competitive pay Equity / stock options Fertility benefits Health care Insurance Medical leave Relocation support Team events Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.