Senior Detection and Response Engineer

FaireSan Francisco, CA
$174,500 - $240,000Hybrid

About The Position

As our first Detection & Response engineer, you'll build that capability from the ground up focused on our enterprise environment. Looking for and monitoring threats within identity systems our employees authenticate through, the laptops they work on, the SaaS applications that run the business, our enterprise network, and the internal infrastructure behind it. You'll decide what we monitor, build the pipelines and detections that monitor it, and write the playbooks we run when something fires. This is a zero-to-one role and it will suit someone who enjoys building with a lot of autonomy.

Requirements

  • Deep hands-on experience in detection engineering, incident response, or security operations, with a track record of building capability
  • Depth in corporate attack surfaces such as identity providers and SSO, endpoint and EDR telemetry, email security, SaaS logs, device management signals, and corporate network access.
  • Strong proficiency in Python and query language such as SQL.
  • The ability to build and maintain detection-as-code pipelines yourself rather than specify them for someone else to build.
  • Practical experience with SIEM, EDR, and security analytics platforms
  • Investigative depth on endpoints and in cloud and SaaS environments, so you can reconstruct what happened across an IdP, a laptop, and a SaaS admin console, and say what you know versus what you're inferring.
  • Excellent written communication and a collaborative approach to influence. You'll explain to engineers why a detection matters and to leadership what an incident actually means.

Nice To Haves

  • Experience as a founding security hire
  • Insider threat or data loss detection experience
  • An offensive security background against corporate identity and endpoint paths
  • Incident commander experience
  • Endpoint or cloud forensics depth
  • A clear view on what belongs in a SIEM versus a data warehouse.

Responsibilities

  • Shape the technical direction for detection and response at Faire. Define what good looks like, build the roadmap that gets us there, and make the case for the tooling and support it needs.
  • Build detection engineering for Faire's enterprise environment end to end. Telemetry pipelines, detection content, alert routing, and enrichment.
  • Bring a threat-informed point of view. Track how adversaries operate against companies like ours and translate that into detections, hunts, and tabletop exercises that test whether we'd catch it.
  • Own detections and data pipelines written as IaaC.
  • Automate triage, enrichment, and response so alert volume can grow without a proportional increase in analyst time.
  • Work with IAM, CPE, NetEng, and IT Infrastructure Engineering to get the telemetry you need.
  • Partner with Enterprise Security to translate detection findings into control improvements, and hand root causes to the teams that own them with enough context that they actually get fixed.

Benefits

  • Competitive pay
  • Equity
  • Comprehensive benefits designed to support your life inside and outside of work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service