Modal Logo

Modal

Detection and Response Engineer

Posted 3 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
150K-270K Annually
Mid level
In-Office
New York, NY, USA
150K-270K Annually
Mid level
Design and build high-fidelity detections, lead incident investigations and response automation, develop security tooling and telemetry, and partner with engineering teams to improve platform observability and resilience, leveraging AI/LLMs where useful.
The summary above was generated by AI
About Us:

AI needs a new infrastructure layer. We're building it at Modal.

Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.

Our customers include category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.

We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September.

Our team includes creators of popular open-source projects (e.g.,Seaborn,Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.

The Role:

We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform.

This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness.

You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.

What You'll Work On:Detection Engineering
  • Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems

  • Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents

  • Improve visibility across cloud infrastructure, containers, identity systems, and production services

Incident Response
  • Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems

  • Build playbooks and automation that reduce investigation time and improve response consistency

  • Drive post-incident improvements that eliminate entire classes of future incidents

Security Tooling & Automation
  • Build internal tooling that improves detection, investigation, and response workflows

  • Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry

  • Improve the collection, quality, and usability of security telemetry across the platform

Engineering Partnership
  • Partner with engineering teams to ensure new systems are observable and secure by default

  • Help teams instrument services with the telemetry needed for effective detection and response

  • Drive security improvements that make the platform easier to defend over time

What We're Looking For:
  • Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus

  • Strong software engineering skills with experience building production systems

  • Experience investigating security incidents in cloud-native or distributed environments

  • Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking

  • Experience building detections using logs, telemetry, behavioral signals, or large-scale event data

  • Strong SQL skills for investigating security events and developing detections

  • Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems

  • Strong written and verbal communication skills

Preferred Qualifications:
  • Experience building AI- or LLM-powered security tooling

  • Experience with SIEM, SOAR, or EDR platforms

  • Experience with Kubernetes security or large-scale cloud infrastructure

  • Experience with threat hunting, malware analysis, or digital forensics

  • Experience contributing to security operations in a high-growth engineering organization

Similar Jobs

15 Days Ago
In-Office
New York, NY, USA
230K-330K Annually
Senior level
230K-330K Annually
Senior level
Information Technology • Internet of Things
Design and build detection and telemetry pipelines, write high-signal detections for identity, cloud control plane, and exfiltration, own incident response/playbooks/on-call, close telemetry gaps with engineering, apply detection-as-code and metrics-driven response, and detect AI-specific abuse using AI augmentation.
Top Skills: Ai/MlAWSCloudtrailDetection-As-CodeGuarddutyVpc Flow Logs
17 Days Ago
Easy Apply
Hybrid
New York, NY, USA
Easy Apply
208K-312K Annually
Senior level
208K-312K Annually
Senior level
Artificial Intelligence • Cloud • Software
Detect, investigate, and respond to security incidents; maintain logging and SIEM operations; build detections and visibility; support PCI/SOC2/ISO audits; manage endpoint, email, and GitHub security; collaborate across teams and improve on-call and security tooling.
Top Skills: Api SecurityAWSBashEdrGitGoManaged SocPythonRustSecurity Automation PlatformsSecurity LoggingServerlessSIEMSQL
13 Days Ago
Hybrid
New York, NY, USA
230K-260K Annually
Senior level
230K-260K Annually
Senior level
Artificial Intelligence • Productivity • Software
Build and operate high-signal detections across cloud, identity, endpoints, and SaaS. Improve detection platforms, automation, and triage tooling (including LLM-based workflows). Translate threat TTPs into telemetry and detections, participate in incident response/on-call, track metrics like MTTD and alert quality, and drive detection engineering improvements across the org.
Top Skills: AWSAzureEdrEqlGCPKqlKubernetesLlmsPantherSIEMSigmaSoarSplYara-L

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account