Senior Detection Engineer II

Instacart
CA$196,000 - CA$207,000Remote

About The Position

Instacart's Detection Engineering team is central to its Security organization, responsible for building and operating systems that identify, surface, and respond to threats across a large grocery technology platform. The team manages the full detection lifecycle, from telemetry collection and signal design to automated response, within a complex, cloud-native environment covering endpoint, cloud, container, and SaaS. As a Senior Detection Engineer II, you will be a technical leader, developing high-fidelity detection logic, hunting for novel attacker techniques, and improving coverage, quality, and scale. You will collaborate with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure detections accurately reflect real-world adversary behavior. The team operates with a detection-as-code philosophy, utilizing version control, testing, and repeatable deployment pipelines. Key focuses include reducing noise, enhancing analyst efficiency through automation and SOAR, and continuously adapting to the evolving threat landscape. This role is ideal for individuals energized by complex forensic problems, skilled in translating attacker TTPs into durable detection logic, and eager to shape a growing security function.

Requirements

  • 6+ years of experience in a detection engineering, incident response, or offensive security role.
  • Experience with 1 or more public cloud platforms (AWS, Azure, GCP).
  • Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries.
  • Proficient understanding of macOS internals and telemetry available to identify macOS specific threats.
  • Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines.
  • Basic proficiency with Python, Golang, or other programming languages.
  • Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar.

Nice To Haves

  • Background in offensive security or red teaming.
  • Knowledge of machine learning for threat detection.

Responsibilities

  • Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
  • Assist in cyber forensic investigations across a variety of log sources.
  • Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost.
  • Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions.
  • Mentor junior security analysts and detection engineers on threat hunting methodologies, detection logic development, and investigation techniques.

Benefits

  • Highly market-competitive compensation and benefits.
  • New hire equity grant.
  • Annual refresh grants.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service