Detection and Response Engineer
Security Engineer · Mid · Full Time
Opens Modal's application page
Role
What you'll do.
Join Modal's security engineering team as a Detection and Response Engineer to build intelligent systems that identify, investigate, and respond to threats across our AI infrastructure platform. You'll design high-fidelity detections, lead incident investigations, and leverage LLMs to automate security analysis while working with world-class engineers at a rapidly scaling company backed by $355M in Series C funding. This role combines deep security expertise with software engineering excellence to protect infrastructure serving category-defining AI companies like Lovable, Ramp, and DoorDash.
Responsibilities
- Design and Build High-Fidelity Detections: Engineer sophisticated detection systems for attacks, abuse, and anomalous behavior across Modal's infrastructure and production systems. Continuously optimize detection accuracy and reduce false positives by incorporating telemetry analysis, threat intelligence feeds, and incident learnings to improve security signal quality across cloud infrastructure, containerized environments, and identity management systems.
- Lead Security Incident Response: Conduct comprehensive investigations spanning production infrastructure, cloud environments, and internal systems. Lead incident response efforts from detection through resolution, documenting findings and post-incident improvements. Build automation playbooks that accelerate investigation workflows, reduce mean time to resolution (MTTR), and ensure consistent incident handling practices across the security team.
- Develop Security Tooling and Automation: Engineer internal security tools that enhance detection, investigation, and response capabilities. Integrate large language models (LLMs) and AI-powered analysis to automate repetitive security analysis tasks, accelerate root cause investigation, and extract actionable insights from large-scale security telemetry datasets. Enhance the collection, normalization, and accessibility of security telemetry across the platform.
- Partner with Engineering Teams on Security Instrumentation: Collaborate with infrastructure, platform, and software engineering teams to ensure new systems are observable and secure by design. Provide guidance on security telemetry instrumentation, assist teams in deploying monitoring agents, and drive security improvements that reduce detection blind spots and make the platform more defensible over time.
- Improve Platform Resilience Through Security Engineering: Transform incident findings into platform-wide improvements that eliminate entire classes of future incidents. Work closely with engineering partners to identify systemic vulnerabilities, recommend architectural security improvements, and ensure every detected incident strengthens the overall resilience and security posture of Modal's infrastructure.
- Research and Implement AI-Focused Threat Detection: Develop detection capabilities for emerging threats targeting AI infrastructure and LLM-powered systems. Research AI-specific attack vectors, implement detections for novel abuse patterns, and stay current with the evolving threat landscape around machine learning model exploitation and infrastructure targeting AI workloads.
Qualifications
What we look for.
Technical
Production Systems Architecture
Proven experience designing, building, and maintaining production-grade systems at scale. Deep understanding of distributed systems concepts, service-oriented architectures, and operational resilience patterns required for building reliable detection and response infrastructure.
Cloud Infrastructure and Kubernetes
Strong hands-on experience with modern cloud platforms (AWS, GCP, or Azure) and Kubernetes orchestration. Understand container security models, cloud IAM policies, networking architectures, and operational security challenges specific to cloud-native distributed environments.
Linux Systems and Networking
Deep expertise in Linux operating systems, including kernel concepts, system administration, and troubleshooting. Solid understanding of networking protocols, TCP/IP stacks, DNS, TLS/SSL, and network traffic analysis techniques essential for infrastructure-level threat detection and forensic investigation.
Security Incident Investigation
Demonstrated experience investigating real security incidents in cloud-native or distributed computing environments. Ability to perform root cause analysis, collect forensic evidence, analyze logs and telemetry data, and reconstruct attacker activities from technical indicators and audit trails.
SQL and Data Analysis
Expert-level SQL proficiency for querying security telemetry databases, constructing complex detection queries, and performing ad-hoc threat hunting investigations. Experience with time-series data analysis, log correlation, and extracting security signals from high-volume event data streams.
Detection Engineering Fundamentals
Experience developing detections using diverse data sources including logs, metrics, behavioral signals, and event telemetry. Understanding of detection logic design, alert tuning methodologies, and techniques for reducing alert fatigue while maintaining detection sensitivity and specificity.
Programming and Scripting
Production-level programming experience with languages commonly used in security automation such as Python, Go, or similar. Ability to write maintainable code for automation scripts, detection logic, and security tools that integrate with complex system architectures.
Large Language Models and AI Integration
Working knowledge of large language model capabilities, limitations, and practical applications in security contexts. Interest and experience applying LLMs and AI techniques to automate security analysis, improve investigation velocity, and extract intelligence from unstructured security data.
System Instrumentation and Observability
Experience designing and implementing telemetry collection strategies for security-focused monitoring. Familiarity with common observability patterns, event schema design, and instrumenting systems to provide rich signals for detection and investigation purposes.
Education
Computer Science or Related Field
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent practical experience. Strong foundational knowledge in computer systems, security principles, and software engineering fundamentals.
Security Certifications (Preferred)
Professional security certifications such as CISSP, CEH, GCIA, or equivalent demonstrate structured security knowledge and commitment to professional development in the field.
Experience
Detection Engineering or Security Engineering Background
3-6 years of professional experience in detection engineering, security engineering, incident response, or software engineering with significant security focus. Experience building detection rules, security systems, or incident response tooling in production environments.
Cloud-Native Incident Response
Hands-on experience investigating and responding to security incidents in cloud-native or distributed system environments. Demonstrated ability to trace attack paths through complex multi-cloud or multi-service architectures.
High-Growth Organization Experience
Background working in rapidly scaling technology organizations where you've experienced the unique security challenges of growing infrastructure complexity, increased attack surface, and evolving threat landscapes.
Production Infrastructure Exposure
Direct experience working with or defending production infrastructure systems, including exposure to container security, Kubernetes environments, and large-scale distributed system monitoring and management.
Skills
Required
Python
Advanced Python programming for security automation scripts, detection rule development, and analysis tooling. Proficiency with Python ecosystem libraries for data analysis and system integration.
SQL
Expert SQL skills for constructing complex detection queries, investigating security events in large datasets, and performing threat hunting across centralized log repositories and security data warehouses.
Linux Administration
Deep understanding of Linux systems administration, kernel concepts, process management, file systems, and permission models. Expertise troubleshooting and analyzing Linux-based infrastructure security issues.
Cloud Platforms (AWS/GCP/Azure)
Hands-on operational experience with at least one major cloud platform including infrastructure components, security primitives, identity and access management, and cloud-native security monitoring.
Kubernetes
Practical experience with Kubernetes deployment, management, and security. Understanding of container orchestration security models, network policies, RBAC, and detection challenges in containerized environments.
Log Analysis and Telemetry
Expertise analyzing security logs and telemetry data from multiple sources. Proficiency with log parsing, correlation techniques, and extracting security signals from high-volume structured and unstructured data.
Incident Response Fundamentals
Demonstrated incident response capabilities including evidence collection, timeline reconstruction, root cause analysis, and communication during security investigations and incident handling procedures.
Security Operations
Experience operating security tools and platforms, managing alert workflows, tracking security metrics, and implementing security monitoring best practices in production environments.
Preferred
LLM and AI Security Applications
Nice to haveHands-on experience building or deploying AI-powered security tools, including applications of large language models for threat analysis, alert enrichment, and automated investigation acceleration.
SIEM/SOAR/EDR Platforms
Nice to haveProduction experience with Security Information and Event Management (SIEM), Security Orchestration Automation and Response (SOAR), or Endpoint Detection and Response (EDR) platforms. Understanding of detection rule creation, alert routing, and automation workflows in these systems.
Kubernetes Security
Nice to haveAdvanced Kubernetes security expertise including container escape detection, workload isolation, supply chain security in Kubernetes environments, and detection of malicious container behavior at scale.
Threat Hunting
Nice to haveExperience conducting proactive threat hunting investigations to identify malicious activity that may evade automated detections. Proficiency with threat intelligence sources and hunting hypotheses development.
Malware Analysis and Forensics
Nice to haveKnowledge of malware analysis techniques, digital forensics principles, and ability to analyze malicious artifacts, reverse engineer samples, or investigate compromised systems for evidence of attacks.
Go Programming
Nice to haveProficiency with Go for building high-performance security tooling, particularly for systems that need to handle large volumes of telemetry or run as agents on production infrastructure.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 150,000 – 270,000
Equity·Stock options
Benefits
Equity Compensation
Meaningful stock option grants as part of compensation package, enabling participation in company growth and value creation at a rapidly scaling $4.65B valuation company
Comprehensive Health Insurance
Medical, dental, and vision coverage for employees and their families, with Modal covering the majority of premiums
Flexible Work Arrangement
Work-from-home flexibility and remote-friendly culture that empowers you to structure your schedule around optimal productivity
Unlimited PTO
Unlimited paid time off policy reflecting trust in employee judgment and commitment to work-life balance
Professional Development Budget
Annual budget for conferences, training, certifications, and learning materials to support continuous skill development and industry engagement
Wellness Programs
Mental health support, wellness initiatives, and fitness benefits to promote overall employee health and well-being
Parental Leave
Generous parental leave policies supporting both birth and adoptive parents with time away from work
401(k) Matching
Company-matched 401(k) retirement savings plan to support long-term financial security
Home Office Setup
Equipment stipend to set up an ergonomic and comfortable home office environment
Learning and Development
Access to online learning platforms, security certification programs, and technical training resources
Process
Interview steps.
- 01
Initial Screening Call
30-minute conversation with a recruiter to discuss your background, security experience, and interest in the Detection and Response Engineer role at Modal. We'll discuss your experience with incident response, detection engineering, and working with infrastructure-level security systems.
- 02
Technical Deep Dive Interview
60-90 minute technical discussion with a member of Modal's security team covering detection engineering principles, incident response methodologies, and hands-on system design. Expect questions about designing detections, investigating production incidents, and working with distributed systems telemetry.
- 03
System Design Exercise
Technical assignment focused on detection and response system design. You may be asked to design a detection system for specific threats, outline incident response workflows, or architect a security tooling solution addressing real-world challenges in cloud-native environments.
- 04
Infrastructure and Security Engineering Alignment
Interview with infrastructure and platform engineering partners to discuss collaboration approaches, security requirements gathering, and how you'd work to make systems secure by design. Focus on communication, partnership models, and driving architectural security improvements.
- 05
Security Leadership and Cultural Fit
Conversation with security leadership to explore your approach to threat prioritization, working in high-growth environments, and building security culture. Discussion of how you approach continuous improvement and cross-functional collaboration within security and engineering organizations.
- 06
Offer and Reference Checks
Following successful interviews, reference checks are conducted and we move into offer negotiation. Modal's team will discuss compensation, equity, benefits, and start date expectations.
Full posting
Original listing.
About Us:
AI needs a new infrastructure layer. We're building it at Modal.
Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.
Our customers include category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.
We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September.
Our team includes creators of popular open-source projects (e.g.,Seaborn,Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.
The Role:
We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform.
This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness.
You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.
What You'll Work On:
Detection Engineering
Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
Improve visibility across cloud infrastructure, containers, identity systems, and production services
Incident Response
Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
Build playbooks and automation that reduce investigation time and improve response consistency
Drive post-incident improvements that eliminate entire classes of future incidents
Security Tooling & Automation
Build internal tooling that improves detection, investigation, and response workflows
Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry
Improve the collection, quality, and usability of security telemetry across the platform
Engineering Partnership
Partner with engineering teams to ensure new systems are observable and secure by default
Help teams instrument services with the telemetry needed for effective detection and response
Drive security improvements that make the platform easier to defend over time
What We're Looking For:
Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus
Strong software engineering skills with experience building production systems
Experience investigating security incidents in cloud-native or distributed environments
Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking
Experience building detections using logs, telemetry, behavioral signals, or large-scale event data
Strong SQL skills for investigating security events and developing detections
Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems
Strong written and verbal communication skills
Preferred Qualifications:
Experience building AI- or LLM-powered security tooling
Experience with SIEM, SOAR, or EDR platforms
Experience with Kubernetes security or large-scale cloud infrastructure
Experience with threat hunting, malware analysis, or digital forensics
Experience contributing to security operations in a high-growth engineering organization
Redirects to Modal's application page.
Other roles
More at Modal.
Systems Engineering Manager
Manager
Infrastructure Security Engineer
Senior
Forward Deployed Engineer - ML
Senior
Forward Deployed Engineer - ML
Senior
Systems Engineering Manager
Manager