Senior Security Engineer, Detection & Response

Aircall.ioSan Francisco, CA

About The Position

Aircall is a rapidly growing, AI-powered customer communications platform used by over 22,000 companies globally. We are innovating in the customer communication space by integrating voice, SMS, WhatsApp, and AI into a unified workspace. Our mission is to help teams work smarter. Aircall's AI features automate routine tasks, streamline post-call work, and provide real-time guidance to enhance performance. Headquartered in Paris with a significant North American presence in Seattle, we have teams across multiple international locations. We are backed by top investors and are experiencing rapid AI innovation. Joining Aircall means becoming part of a dynamic, product-driven company with a focus on execution, impact, and growth. We are customer-obsessed, data-driven, and value ownership, continuous learning, and thoughtful speed. Our collaborative and fast-paced environment emphasizes trust and impact.

Requirements

  • 5+ years of hands-on experience in security operations, detection engineering, incident response, threat hunting, or similar fields, or an equivalent combination of education and experience.
  • Production-grade Python and Terraform expertise.
  • Demonstrated ability to build detections managed in code, logging pipelines, and custom security tools to scale security operations.
  • Experience pointing to services or Lambdas built and Terraform modules owned and maintained in production.
  • Deep knowledge of adversarial tactics, techniques, and procedures, threat actor behavior, and the ATT&CK framework.
  • Proven experience building detections from scratch, not just tuning commercial alerts, to achieve production-quality detections with a low false positive rate.
  • Hands-on experience with SIEM or log analytics platforms and data lake technologies (e.g., OpenSearch, Elasticsearch, Clickhouse, Sentinel, Splunk, Datadog, AWS Athena, Azure Synapse, Databricks).
  • Experience with alerting/monitoring tooling.
  • Cloud-first experience with Azure, GCP, or AWS.
  • Experience provisioning and owning production security infrastructure in AWS (VPCs, IAM, networking, private service endpoints) beyond just instrumenting detections.
  • Experience in digital forensics, host-based detection, endpoint telemetry, process and network visibility, and cloud observability.
  • Experience responding to incidents in production environments, including log investigation, timeline building, root cause establishment, and containment.
  • Familiarity with security automation and orchestration, playbooks, response automation, and alert triage workflows.
  • Comfort acting as the primary owner of a domain, leading detection and response engineering, setting priorities, and driving initiatives with minimal oversight.
  • Strong communication skills, with the ability to translate complex detection logic, trade-offs, and risks to both engineers and leadership.
  • A high degree of autonomy, initiative, and ownership.

Nice To Haves

  • Experience building on or securing LLM and agent systems (e.g., Azure Foundry, Bedrock/AgentCore, LangGraph, guardrails, policy-based authorization, prompt-injection defense, agent evaluation).
  • Purple/Red team, App Sec, or Production security experience to develop proof of concepts, simulate attacks, and test control effectiveness.
  • Vulnerability management program ownership (e.g., Wiz or comparable CSPM, bug bounty triage, SLA enforcement).
  • Experience with fraud and abuse investigation in a multi-tenant SaaS product (e.g., account takeover, credential stuffing, trial and promo abuse, toll fraud).
  • Contributions to open-source detection tooling or public speaking at security conferences.

Responsibilities

  • Lead the strategic direction of Aircall's Detection and Response (DART) program.
  • Develop detection logic from threat modeling and hypothesis generation through to writing, testing, simulation, tuning, and deployment of rules and alerts across various data sources (logs, telemetry, host, network, cloud).
  • Manage the security data platform end-to-end, including operating and extending the SIEM, ingestion pipelines, parsers, enrichment, and normalization, all defined as infrastructure-as-code.
  • Oversee the cost and capacity of the security data platform, making decisions regarding data retention versus spend.
  • Experiment with and build novel security tools at the forefront of the industry to address significant security challenges.
  • Expand and deploy new AI- and agent-based security tooling for alert triage, investigation, and detection building, including its authorization model, guardrails, evaluation harness, and tracing.
  • Proactively conduct threat hunts in company-wide and production environments to identify anomalies and attacker behaviors.
  • Lead incident response efforts, including investigation, containment, remediation, and root cause analysis.
  • Drive post-incident reviews and integrate lessons learned into the detection strategy.
  • Assess security for new product features, including AI- and LLM-backed services, and identify opportunities for detections or protections.
  • Author and maintain comprehensive documentation for detections, runbooks, alert definitions, tuning guidelines, and metrics.
  • Collaborate cross-functionally with Engineering, Product, Fraud, Privacy, and Legal teams.
  • Participate in on-call and threat-response rotations, escalating, coordinating, and removing blockers during high-severity events.
  • Stay current with attacker techniques (MITRE ATT&CK, red team reports, threat intelligence) and propose new detection patterns or responses.
  • Participate in the hiring and interview evaluation process for Security and Infrastructure engineering candidates, contributing to team growth.

Benefits

  • Competitive salary package
  • Benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service