Staff Security Engineer, Detection & Response

Maven Clinic•New York, NY
•$221,000 - $299,000•Hybrid

About The Position

This role will own the Incident Detection and Response program, including threat modeling systems and codebase, and directing investigations when incidents occur. The engineer will join a team with AppSec and infrastructure focus, guiding technical direction and decision-making. A significant portion of the time will be dedicated to finding bugs in code and SDLC gaps before they escalate into incidents, and then either implementing fixes or managing their resolution. The role also involves understanding and managing the security risks associated with the increasing use of AI, LLMs, AI-generated code, and agents.

Requirements

  • 6+ years of security experience combining hands-on software or AppSec depth with detection and SIEM engineering ownership.
  • Comfortable reading production code across multiple languages and stacks to assess exploitability.
  • Experience building threat models of codebases, reasoning about attack surface, trust boundaries, and data flow.
  • A track record of finding and fixing systemic weaknesses.
  • Strong communication skills with credibility to direct investigations and influence peers.

Nice To Haves

  • Hands-on experience with AI-assisted security operations tooling (e.g., AI SOC platforms, LLM-based triage, agentic escalation systems).
  • Interest or experience in securing AI and LLM-powered systems (e.g., prompt injection, model misuse, agentic tool abuse).
  • Prior exposure to golden-path or secure-by-default infrastructure initiatives.
  • Experience with container or image security and the patching lifecycle.
  • A relevant certification such as GCIH, GCFA, GCDA, OSCP, or CISSP.

Responsibilities

  • Lead investigations hands-on, including pulling logs, building incident narratives, and advising leaders on next steps.
  • Read production code to understand system behavior during investigations.
  • Hunt for bugs in the codebase and weaknesses in the SDLC.
  • Propose and implement fixes, or manage their resolution with relevant teams.
  • Partner with the Product Security Engineer on systemic gaps.
  • Own and tune detection logic in 7AI, validating investigations and escalations.
  • Set criteria for alert triggers.
  • Close gaps in logging and visibility to ensure tooling has adequate data.
  • Understand and manage security risks associated with LLMs and AI tooling.

Benefits

  • Employer-covered health, dental, and insurance plan options
  • Access to the full Maven platform and specialists (mental health, reproductive health, family planning, pediatrics)
  • Whole-self care through wellness partnerships
  • Hybrid work
  • In-office meals
  • Work together days
  • 16 weeks 100% paid parental leave
  • New parent stipend (for employees with 1+ year tenure)
  • Annual professional development stipend
  • Access to a personal career coach through Maven for Mavens
  • 401K matching for US-based employees, with immediate vesting
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service