40 threat detection engineer jobs at 34 companies in California

1mo
Save
Mark Applied
Hide
Engineer II, Threat Detection - Windows (Hybrid)
Sunnyvale or New York City or Austin or Redmond
$100k-$145k/yr HybridFull Time
CrowdStrike
CrowdStrikeNASDAQ: CRWD: AI-native platform for cybersecurity and threat protection.
4+ YOEAbility to analyze malware and intrusion telemetry, author behavioral detections for Windows endpoints, use Python/PowerShell for automation, and collaborate with threat intelligence; U.S. citizenship or green card required for CJIS eligibility.
PowerShell, Python, EDR, Regular expressions, MITRE ATT&CK
2mo
Save
Mark Applied
Hide
Threat Detection Engineer – Security Operations
Mountain View, California, United States
$113k-$140k/yr OnsiteFull Time
ID.me
ID.me: Private American digital identity wallet and identity-verification helping people securely access government, healthcare, and commercial services.
2+ YOE2+ years security engineering/ops experience; proficiency with Splunk/Elastic/Chronicle/Logstash, Python and SQL, YARA-L/Sigma detection formats, LLM APIs/AI literacy, cloud-scale log management, MITRE ATT&CK, and IaC (Terraform/Git).
Splunk, Elastic Stack, Logstash, Google Chronicle (SecOps), Python, SQL, YARA-L, Sigma, Kusto, Lucene, LLM APIs, OpenAI, Anthropic, Google Gemini, Snowflake, Terraform, GitHub, GitLab CI/CD, LangChain, LlamaIndex, SOAR, SIEM
1mo
Save
Mark Applied
Hide
Senior Detection Engineer
New York City or San Francisco or Austin or Seattle
$176k-$218k/yr OnsiteFull Time
Fluidstack
Fluidstack: Building and operating civilization-scale data center infrastructure for AI.
5+ YOE5+ years detection engineering or threat hunting experience; hands-on SIEM/EDR (Splunk, Elastic, CrowdStrike); detection logic mapped to MITRE ATT&CK; Python/SQL scripting; strong writing and incident response skills.
Splunk, Elastic, CrowdStrike, Python, SQL, MITRE ATT&CK, Sigma
2w
Save
Mark Applied
Hide
Network Threat Detection R&D Engineer
Palo Alto, California, United States
$144k-$230k/yr OnsiteFull Time
Broadcom Inc.
Broadcom Inc.NASDAQ: AVGO: Global technology leader in semiconductors and infrastructure software.
12+ YOEBachelor's and 12+ years, master's and 10+ years, or PhD and 7+ years; network security and IDS signature experience; Python, Docker, Kubernetes, AI systems, communication, and U.S. work authorization required.
Python, Docker, Kubernetes
1w
Save
Mark Applied
Hide
Threat Detection and Response Engineer
San Francisco or New York City or Los Angeles or Seattle or United Kingdom or Ireland or Poland or Germany or Australia
$175k-$260k/yr RemoteFull Time
Whatnot
Whatnot: Live shopping marketplace connecting buyers and sellers.
5+ YOE5+ years in cyber incident response or a related security field; bachelor's degree or equivalent; experience with SOAR, EDR, NDR, SIEM, AWS, and GCP; strong incident documentation and communication skills.
SOAR, Tines, EDR, NDR, SIEM, Chronicle, AWS, GCP
2mo
Save
Mark Applied
Hide
Cybersecurity Threat Engineer
Los Angeles, California, United States
OnsiteFull Time
Creative Artists Agency
Creative Artists Agency: Entertainment and sports talent agency.
6+ YOESenior cybersecurity professional with 6+ years experience in offensive and defensive security, vulnerability management, threat detection, incident response, cloud and infrastructure security, scripting (PowerShell, Python, JavaScript), and integrating automation and SIEM/SOAR tooling.
PowerShell, Python, JavaScript, MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP, CI/CD, Security Orchestration Automation and Response, Security Information and Event Management, Vulnerability Scanning, Security Threat Feeds, Red Team Tooling
1mo
Save
Mark Applied
Hide
Member of Technical Staff, SecOps & Threat Detection Engineer
San Francisco, California, United States
$265k-$310k/yr OnsiteFull Time
Envoy
Envoy: Workplace management software platform helping organizations manage visitors, spaces, communications, deliveries, and emergency operations.
6+ YOE6+ years in security/SRE/infrastructure with security focus; experience building detection, SIEM, EDR (SentinelOne), cloud (AWS), scripting (Python/Go), and strong incident detection and response skills.
LenelS2, Brivo, Genetec, Honeywell, Cisco Meraki, Okta, Microsoft Azure, Microsoft Teams, Slack, ServiceNow, DocuSign, Avigilon Alta, Descartes Visual Compliance, SentinelOne, SIEM, AWS, Python, Go
5d
Save
Mark Applied
Hide
Threat Intelligence Lead
Palo Alto, California, United States
$240k-$280k/yr OnsiteFull Time
Obsidian Security
Obsidian Security: Cybersecurity software securing enterprises' SaaS applications, identities, data, and AI agents across third-party applications.
6+ YOERequires 6+ years in threat intelligence, hunting, detection engineering, incident response, or security operations; cloud, SaaS, and endpoint hunting; MITRE ATT&CK; SIEM queries; Python; and intelligence-sharing tools.
Microsoft 365, Salesforce, MITRE ATT&CK, Okta, Google Workspace, Slack, Notion, Jira, Python, STIX/TAXII, MISP, OpenCTI
1mo
Save
Mark Applied
Hide
Security Analyst (Threat Detection)
Hawthorne, California, United States
$95k-$130k/yr OnsiteFull Time
SpaceX
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
2+ YOEBachelor's in STEM or 2+ years info security experience; OS auditing and network/host collection experience; incident response, detection development, and familiarity with Elastic/Splunk/SIEM; scripting and forensics preferred.
Elastic, Splunk, SIEM
3mo
Save
Mark Applied
Hide
Threat Intel Research Engineer
San Francisco or United States
$140k-$180k/yr HybridFull Time
DTEX Systems
DTEX Systems: DTEX is a cybersecurity helping organizations prevent insider threats with behavioral intelligence and risk-adaptive security.
3+ YOE3+ years full-stack development (Python, Django/Flask, React/TypeScript), deep system knowledge (Windows/Mac/Linux), cybersecurity and detection engineering experience, familiarity with data pipelines, RESTful APIs, AWS, QE/test automation and CI/CD, strong communication.
Python, Django, Flask, React, TypeScript, Elasticsearch, Spark, AWS, CI/CD, RESTful APIs
3d
Save
Mark Applied
Hide
Senior Security Engineer, Detection & Response
United States or San Francisco or California or Washington or Colorado or New York City or Illinois
$138k-$229k/yr OnsiteFull Time
Flexport
Flexport: Global logistics and supply chain technology platform.
5+ YOERequires 5–8 years in detection engineering, incident response, or threat hunting; programming proficiency; SIEM or detection pipeline experience; and hands-on security incident response.
Python, Go, Panther, Elastic, Splunk, CI/CD, MITRE ATT&CK, Kubernetes, Slack
1w
Save
Mark Applied
Hide
Threat Hunting Consultant
San Jose, California, United States
$110k-$150k/yr RemoteFull Time
Tata Consultancy Services
Tata Consultancy ServicesBSE: 532540: Global leader in IT services, consulting, and business solutions.
5+ YOERequires 5–7 years of cybersecurity experience, including 2+ years with Microsoft Defender for Endpoint, threat hunting, incident response, detection engineering, and strong communication and training abilities.
Microsoft Defender for Endpoint, Microsoft 365 Defender, Kusto Query Language (KQL), Splunk Enterprise Security, Splunk Processing Language (SPL), Splunk User Behavior Analytics (UBA), MITRE ATT&CK, Windows, Active Directory, Azure AD, Kerberos, NTLM, PowerShell, Python, NIST, SANS
2w
Save
Mark Applied
Hide
Senior Manager, Detection Response
San Francisco, California, United States
$270k-$290k/yr HybridFull Time
Strava
Strava: Consumer fitness and social-network app helping athletes track, analyze, share, and improve their activities worldwide.
Requires experience building or scaling detection engineering or security operations programs, incident command, threat intelligence, detection strategy, security vendors, automation or AI/ML, and executive communication.
AI, AI/ML
1mo
Save
Mark Applied
Hide
Senior Detection and Response Engineer
Torrance, California, United States
$120k-$190k/yr OnsiteFull Time
Northwood Space
Northwood Space: Northwood is an end-to-end ground infrastructure provider for space missions, delivering hardware, software, and network services.
5+ YOE5+ years SOC/IR experience, SIEM and forensics skills, Python/PowerShell for automation, endpoint and Linux forensics, ability to obtain TS/SCI, threat hunting and incident response for distributed satellite infrastructure.
Splunk, Sentinel, Chronicle, Volatility, YARA, Python, PowerShell, CrowdStrike, SentinelOne, MITRE ATT&CK, AWS, Azure, SOAR
1mo
Save
Mark Applied
Hide
Security Engineer, Cyber Threat Intelligence
Austin or San Diego
OnsiteFull Time
Saronic
Saronic: Developing autonomous surface vessels for defense and maritime applications.
4+ YOE4+ years in CTI/threat hunting/detection engineering, intelligence lifecycle fluency, software engineering for automation, MITREATT&CK/STIX/TAXII familiarity, ability to obtain U.S. security clearance.
MITRE ATT&CK, STIX, TAXII, Sigma, YARA, SIEM, MISP, LLMs
1mo
Save
Mark Applied
Hide
Security Operations Analyst – Detection Engineering & Threat Hunting
San Jose, California, United States
$112k-$236k/yr OnsiteFull Time
TikTok
TikTok: Short-form mobile video and social media platform.
Experience in 24/7 security operations, SIEM/EDR proficiency, detection engineering and threat hunting, scripting for automation, and knowledge of attacker tactics and MITRE ATT&CK.
SIEM, Splunk, Chronicle, Elastic, EDR, SentinelOne, CrowdStrike, Sigma, EQL, KQL, YARA, SOAR, GitOps, CI/CD, Python, PowerShell, MITRE ATT&CK, MaGMa
1mo
Save
Mark Applied
Hide
Cybersecurity Senior Specialist - Threat Hunter
Rosemead, California, United States
$144k-$216k/yr HybridFull Time
Southern California Edison
Southern California Edison: Electric utility serving Southern, Central, and Coastal California.
5+ YOE5+ years IT/cybersecurity experience, US citizenship required. Experience in threat hunting, incident response, detection engineering, MITRE ATT&CK mapping, telemetry analysis, EDR/SIEM/NDR tools, scripting/automation (PowerShell, Python, KQL, Splunk SPL, SQL), and relevant certifications.
PowerShell, Python, KQL, Splunk SPL, SQL, EDR/XDR, SIEM, NDR, Threat intelligence platforms, Security orchestration tools, MITRE ATT&CK
1mo
Save
Mark Applied
Hide
Security Software Engineer II, Detection and Response
San Francisco or United States
$124k-$255k/yr RemoteFull Time
Pinterest
PinterestNYSE: PINS: A visual discovery engine for finding inspiration.
Bachelor's degree or equivalent experience; security engineering expertise in cloud environments, intrusion detection, incident response, SIEM queries, threat intelligence, scripting, networking, and AI-assisted workflows.
SIEM, EDR, Osquery, Python, Go, Ruby, AI
3mo
Save
Mark Applied
Hide
Security Engineer, Level 5, Detection & Response
Los Angeles or Palo Alto or Santa Monica
$178k-$313k/yr OnsiteFull Time
Snap Inc.
Snap Inc.NYSE: SNAP: Technology focused on augmented reality and communication.
6+ YOE6+ years security experience; BS in CS/Engineering; strong Python/Go; OS/cloud proficiency; incident response and threat hunting.
Python, Go, Kubernetes, AWS, Google Cloud Platform, macOS, Windows, Linux
3mo
Save
Mark Applied
Hide
Security Engineer, Level 5, Detection & Response
Los Angeles or Palo Alto or Santa Monica
$178k-$313k/yr HybridFull Time
Snap Inc.
Snap Inc.NYSE: SNAP: Technology focused on augmented reality and communication.
6+ YOE6+ years in security fields; strong Python/Go; cloud and OS internals knowledge; threat hunting and incident response.
Python, Go, macOS, Windows, Linux, Kubernetes, AWS, Google Cloud Platform