Senior Detection Engineer

FluidstackNew York, NY
$176,000 - $218,000

About The Position

Fluidstack is building civilization-scale infrastructure for AI, aiming to deliver 10 to 100s of GWs of compute faster than anyone else. The Security & Corp IT Team protects the infrastructure behind this buildout, from corporate endpoints to environments running frontier AI workloads. This role involves owning the detection engineering program end-to-end, building detection-as-code pipelines, running threat hunts, driving SIEM and EDR pipeline health, leading triage and response, and building automation to scale alert load. Fluidstack operates with extreme ownership, full autonomy, velocity, first principles, and a passion for the problem space. The Security & Corp IT team faces challenges such as building detection and response coverage across rapidly growing environments, securing systems critical to AI labs, implementing security tooling for a fast-growing company, and turning incident learnings into durable detection logic.

Requirements

  • 5+ years in detection engineering or threat hunting inside a mature security operations org (cloud-native infrastructure, SaaS, or fintech).
  • Deep hands-on experience with SIEM and EDR tooling: Splunk, Elastic, CrowdStrike, or equivalent, including query languages and pipeline tuning, not just console use.
  • You've written and maintained detection logic mapped to MITRE ATT&CK against real adversary behavior, and you can point to detections that caught something.
  • Strong scripting and automation skills (Python, SQL, or similar) and a detection-as-code workflow you'd defend: tests, review, and rollback included.
  • You know the difference between a noisy rule and a broken one, and you tune or kill detections before responders learn to ignore them.
  • You operate well with minimal process: you can scope your own work, ship without a mature SOC around you, and build the process you need as you go.
  • You write clearly enough that your runbooks and incident reports work when you're asleep.

Nice To Haves

  • Experience securing physical infrastructure or OT/data center environments
  • Purple team experience
  • Contributions to open-source detection content (Sigma, detection rule repos)

Responsibilities

  • Own the detection engineering program end to end: threat modeling, detection design, deployment, tuning, and retirement, with coverage mapped to MITRE ATT&CK and gaps documented rather than assumed away.
  • Build detection-as-code pipelines so every rule is version-controlled, tested, and peer-reviewed before it ships, and false-positive rates are measured, not guessed.
  • Run threat hunts against real adversary behavior in our cloud, SaaS, and data center environments, and convert findings into repeatable detections.
  • Drive SIEM and EDR pipeline health: log source onboarding, normalization, and alert quality good enough that on-call responders trust what pages them.
  • Lead triage and response for the alerts you build, and close out incidents with root-cause writeups that change the detection stack, not just the ticket queue.
  • Build automation that removes manual triage steps, so the team's alert load scales slower than the company does.

Benefits

  • We are committed to pay equity and transparency.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service