Senior Detection & Response Engineer
Costa Mesa, CA - USA
Job Summary
ABOUT THE TEAM
Andurils Information Security team is looking for a Senior Detection and Response Engineer to focus on building world class defensive controls to protect the infrastructure around our advanced defense technology products. This is a role with wide berth that will have the latitude to design and implement cutting edge security architecture.
ABOUT THE JOB
WHAT YOULL DO
- Provide technical leadership vision and strategy for the advancement of the Detection and Response capability at Anduril
- Collaborate with product security and engineering teams to architect and implement detection and response frameworks for Andurils products assets and other custom applications
- Build and optimize tailored detection signatures response playbooks and response automation using detection-as-code principles
- Lead threat modeling scenarios with cross-functional partners to understand weaknesses across OT Cloud Network Endpoints and other key worlds incorporating findings into security controls and/or detection signatures
- Lead large-scale baselines of data collaborating across many teams to emit signals to incorporate into detections new telemetry ingestion and/or security controls
- Contribute directly to the development and advancement of our detection-as-code data engineering automation and infrastructure capabilities
- Work cross-collaboratively with different teams to mature the detection and response of threat actors in key worlds developing data baselines automation and engineering capabilities to scale this capability across the business
REQUIRED QUALIFICATIONS
- Programming experience in one or more general purpose languages (Python SQL Go Rust etc)
- Experience conducting data analysis in large-scale data lake environments
- Experience deploying infrastructure as code (Terraform CDK CloudFormation etc)
- Experience working in a traditional software development lifecycle (i.e. Github CI/CD unit testing)
- Extensive experience utilizing AWS / Azure security controls and services
- Broad range of practical security knowledge across the spectrum of endpoint network identity application and cloud infrastructure
- Strong knowledge of attacker tactics techniques and procedures (TTPs)
- Strong communication skills and experience collaborating with internal and external stakeholders
- Must be able to obtain and hold a U.S. Top Secret security clearance
PREFERRED QUALIFICATIONS
- Experience deploying infrastructure using Kubernetes (EKS) and/or Docker containers (ECS)
- Experience proactively threat hunting using threat intelligence to identify potential risks and weaknesses in telemetry
Although we list out what we generally look for we are very likely missing other attributes and skills that you have that could make you a great fit but are not currently listed. Research has shown this especially applies to women and other marginalized groups who tend to apply if they check 100% of every box versus men who apply if they hit roughly 60%. The point were getting at it doesnt hurt to take a chance and apply!
US Salary Range
$166000 - $220000 USD
The salary range for this role is an estimate based on a wide range of compensation factors inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience education and/or training critical skills and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Andurils total compensation package. Additionally Anduril offers top-tier benefits for full-time employees including:
Benefits
At Anduril we invest in our people. Our comprehensive competitive benefits package (available at little to no cost to employees) ensures youre supported in health recovery and whatever comes next.For more information Explore Our Benefits.
Protecting Yourself from Recruitment Scams
Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. Weve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.
To ensure your safety and help you navigate your job search with confidence please keep the following critical points in mind:
No Financial Requests:Anduril will never solicit payment or demand personal financial details (such as banking information credit card numbers or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.
- Please always verify communications:
- Direct from Anduril: If you receive an email from one of our recruiters it will only come from an
@address. - Via Agency Partner: If contacted by a recruiting agency for an Anduril role their email will clearly identify their agency. If you suspect any suspicious activity please verify the agencys authenticity by reaching out to .
- Direct from Anduril: If you receive an email from one of our recruiters it will only come from an
Exercise Caution with Unsolicited Outreach:If you receive any communication that appears suspicious contains grammatical errors or makes unusual requests do not engage. Always confirm the senders email domain is @ before providing any personal information or clicking on links.
What to Do If You Suspect Fraud:Should you encounter any questionable or fraudulent outreach claiming to be from Anduril please report it immediately to. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.
Data Privacy
To view Andurils candidate data privacy policy please visit submitting your application you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk integrity and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists adverse media public-record information and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology intellectual property and organizational security.
Required Experience:
Senior IC