Leah 10/11 Selective EA Testing - Greenhouse Logo

Leah 10/11 Selective EA Testing - Greenhouse

Detection Engineer II

Posted 15 Days Ago
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in United States
171K-181K Annually
Junior
Easy Apply
Remote
Hiring Remotely in United States
171K-181K Annually
Junior
Design, implement, and maintain detection logic across endpoint, cloud, container, and SaaS telemetry. Perform threat hunting and forensic investigations, optimize telemetry pipelines, build SOAR playbooks and automation, and mentor other engineers while operating detection-as-code with testing and CI/CD.
The summary above was generated by AI

We're transforming the grocery industry

At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.

Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.

Instacart is a Flex First team

There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.

Overview

Instacart's Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North America's largest grocery technology platforms. We own the full detection lifecycle, from telemetry collection and signal design to automated response, across a complex, cloud-native environment spanning endpoint, cloud, container, and SaaS.

As a Detection Engineer, you'll be a technical anchor on the team: developing high-fidelity detection logic, hunting for novel attacker techniques, and raising the bar for how we think about coverage, quality, and scale. You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure our detections reflect real-world adversary behavior (and not just signatures).

We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed through repeatable pipelines. We care deeply about reducing noise, improving analyst efficiency through automation and SOAR, and continuously evolving our coverage as the threat landscape shifts.

If you're energized by hard forensic problems, enjoy translating attacker TTPs into durable detection logic, and want to help shape the future of a growing security function, this role is for you.

About the Job

  • Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
  • Assist in cyber forensic investigations across a variety of log sources
  • Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost
  • Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions
  • Mentor/knowledge share with other detection engineers on threat hunting methodologies, detection logic development, and investigation techniques

About You

Minimum Qualifications

  • 2+ years of experience in a detection engineering, incident response, or offensive security role.
  • Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
  • Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries
  • Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
  • Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines
  • Basic proficiency with Python, Golang, or other programming/scripting languages
  • Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar

Preferred Qualifications

  • Background in offensive security or red teaming
  • Knowledge of machine learning for threat detection

#LI-remote

Instacart provides highly market-competitive compensation and benefits in each location where our employees work. This role is remote and the base pay range for a successful candidate is dependent on their permanent work location. Please review our Flex First remote work policy here.

Offers may vary based on many factors, such as candidate experience and skills required for the role. Additionally, this role is eligible for a new hire equity grant as well as annual refresh grants. Please read more about our benefits offerings here.
For US based candidates, the base pay ranges for a successful candidate are listed below.

CA, NY, CT, NJ
$171,000$180,500 USD
WA
$164,000$173,000 USD
OR, DE, ME, MA, MD, NH, RI, VT, DC, PA, VA, CO, TX, IL, HI
$157,000$165,500 USD
All other states
$142,000$150,000 USD

Similar Jobs

15 Days Ago
Remote
United States
171K-181K Annually
Junior
171K-181K Annually
Junior
eCommerce • Hardware • Mobile • Software
Build, tune, and maintain detection logic across endpoint, cloud, container, and SaaS telemetry. Perform threat hunting and forensics, optimize log ingestion, create SOAR playbooks and automation, and mentor other engineers while operating detection-as-code pipelines.
Top Skills: Automated TestingAWSAzureCi/CdContainersDetection-As-CodeEndpoint TelemetryGCPGoLog IngestionmacOSPythonSaaSSoarVersion Control
Yesterday
In-Office or Remote
United States
Mid level
Mid level
Healthtech
Provide in-person VIP technical support, training, and troubleshooting for Starbucks partners across Windows, macOS, and mobile devices. Manage walk-up requests and tickets, perform root-cause analysis, document solutions, run ad-hoc queries, support production systems, and collaborate cross-functionally to deliver and improve technology solutions.
Top Skills: AgileAndroidiOSKnowledge BaseLeanmacOSScrumWikiWindows
Yesterday
Remote
United States
Senior level
Senior level
Healthtech
Lead a multi-unit portfolio of Starbucks stores: develop district strategies, coach and develop Store Managers, drive financial/operational/customer-service goals, and support store operations and staffing.

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account