Envoy
Member of Technical Staff, SecOps & Threat Detection Engineer
San Francisco, CA · Staff+
Sponsorship not specifiedDetected 13 days ago
PythonGoAWSAzureCloud PlatformsSite Reliability EngineeringCybersecuritySIEMSOC OperationsDetection EngineeringCiscoLeadershipCommunicationCollaborationMicrosoft Teams
About the role
- This role is responsible for defining how we detect, monitor, and respond to threats across our infrastructure, applications, and endpoints.
- Today, much of our security posture is reactive.
- You will work across Infrastructure, Platform, and Workplace teams to ensure we have full visibility into our environment and can confidently answer: "If we had a security incident, how quickly would we know?"
Responsibilities
- Own the design and evolution of our threat detection and security operations capability
- Design and implement detection-as-code practices, setting standards for how detection logic is built, tested, and maintained
- Drive visibility across all critical assets, ensuring endpoints, services, and identities are consistently monitored
- Lead the design and rollout of automated security controls, including secrets rotation for high-risk systems
- Partner with engineering teams to improve instrumentation and ensure systems emit high-quality security signals
- Define and track key metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive measurable improvements
- Deep experience working with logs, events, and telemetry to build meaningful, high-signal detections
Requirements
- 10+ years of experience in Security Engineering, SRE, or Infrastructure Engineering with a strong security focus
- A strong understanding of attacker behavior and the ability to translate threats into detection strategies
- Ability to operate in ambiguous environments and define structure where none exists
Nice to have
- Strong understanding of cloud environments (ideally AWS), including IAM, networking, and logging at scale
Skills
- More than 16,000 workplaces around the world trust Envoy to run secure, compliant, and connected operations across every location.
- Learn more at envoy.com http://envoy.com
- This is an L5 opportunity.
- Define detection strategy across cloud infrastructure, applications, and endpoints
- Experience working with endpoint detection and response tools such as SentinelOne or similar
Company info
- We are building a proactive, engineering-led security function focused on threat detection, visibility, and automation.
- We are looking for a Staff Security Engineer to own and evolve our Security Operations and Threat Detection capabilities.
This listing is sourced directly from Envoy's careers page and normalized into a canonical job model.