Senior Security Engineer, Detection
1 day ago
Aircall is a unicorn AI-powered customer communications platform used by 22,000+ companies worldwide to drive revenue, faster resolutions, and scale. We're redefining what a customer communications platform can be—by combining voice, SMS, WhatsApp, and AI into one seamless workspace.
Our momentum comes from a simple but powerful idea: help every customer-facing team work smarter, not harder. Aircall's AI Voice Agent automates routine calls, AI Assist streamlines post-call tasks, and AI Assist Pro delivers real-time guidance that helps people do their best work. The result—companies grow revenue, deliver faster resolutions, and scale service.
We've built a product customers love and a business that scales fast. Aircall operates in nine global offices (Paris, New York, San Francisco, Sydney, Madrid, London, Berlin, Seattle, and Mexico City), and is backed by world-class investors. Our teams are shipping AI innovation faster than ever and expanding across new product lines and markets.
At Aircall, you'll join a company in motion—ambitious, profitable, and product-driven—where impact is visible, decisions are fast, and growth is real.
How We Work at Aircall:
At Aircall, we believe in customer obsession, continuous learning, and delivering extraordinary outcomes. We value open collaboration, taking ownership, and making smart, informed decisions with speed and precision. If you thrive in a fast-paced, team-driven environment where curiosity, trust, and impact matter, you'll fit right in
As a Senior Security Engineer, Detection and Response you will contribute to develop, scale, and evolve Aircall's threat detection and response capabilities. Take ownership of building detections from scratch, leading investigations, and driving the maturity of our detection program.
Responsibilities
- Lead end-to-end development of detection logic: from threat modeling and hypothesis to writing, testing, tuning, and deploying detection rules and alerts (across logs, telemetry, host, network, cloud).
- Build detection pipelines, orchestration, triage logic, and automation for alert handling and response (e.g. SOAR, playbooks).
- Conduct threat hunts proactively in corporate and production environments, discovering anomalies and attacker behaviors before they escalate.
- Lead incident response: investigate, contain, remediate, and perform root cause analysis. Drive post-incident reviews and feed lessons learned back into detection strategy.
- Assess and fill gaps in visibility—work with engineering teams to ensure logging, instrumentation, and context are sufficient to detect relevant threats.
- Evolve detection maturity: turn simple signature-based alerts into more advanced behavioral, statistical, ML-driven, and adversary-informed detections, in line with detection engineering maturity models.
- Author and maintain detection documentation, runbooks, alert definitions, tuning guidelines, and metrics.
- Collaborate cross-functionally (Engineering, Product, Fraud, Privacy and Legal) to align detection and response work with product lifecycles and system architecture.
- Be part of on-call rotations or threat-response rotations; escalate, coordinate, and remove blockers during high-severity events.
- Stay up to date on attacker techniques (MITRE ATT&CK, red team reports, threat intel) and propose new detection patterns or responses accordingly.
- Participate in hiring, interview evaluation of Security and Infrastructure engineering candidates, and team growth.
Minimum Qualifications
- 5+ years of hands-on experience in security operations, detection engineering, incident response, threat hunting, or similar fields (or equivalent combination).
- Deep knowledge of adversarial tactics, techniques, and procedures (TTPs), threat actor behavior, kill-chain or MITRE ATT&CK framework.
- Proven experience building detections from scratch (versus just tuning commercial alerts)—i.e. you can turn a hypothesis or a threat intel indicator into a production-quality detection with low false positive rate.
- Hands-on experience with SIEM or log analytics platforms (e.g. Elasticsearch, Splunk, Datadog, AWS Athena, OpenSearch or equivalent), and alerting/monitoring tooling.
- Proficiency with a programming or scripting language (e.g. Python, Go, or similar along with IaC - Terraform, Ansible) to build detection pipelines, automations, triage logic, or tooling
- Experience in digital forensics, host-based detection, endpoint telemetry, process/network visibility, cloud observability (logs, metrics, traces).
- Comfortable working in cloud-first environments (AWS, GCP, Azure) and instrumenting detection across cloud workloads, containers, serverless, etc.
- Experience responding to incidents (investigating logs, creating timelines, root cause, containment) in production environments.
- Familiarity with security automation / orchestration (SOAR), playbooks, response automation, and alert triage workflows.
- Strong communication skills; ability to translate complex detection logic, trade-offs and risk to engineers and leadership.
- High degree of autonomy, initiative, and ownership; ability to drive entire initiatives with minimal oversight.
Preferred Qualifications
- Experience with data analysis, statistics, anomaly detection, or relevant ML/heuristic techniques is a strong plus.
- Experience evaluating detection efficacy (precision, recall, signal-to-noise, tuning over time)
- Experience evolving detection maturity models (from basic rules to advanced behavioral detections)
- Open source detection tooling contributions
$165,000 - $210,000 a year
This is not including equity and other benefits. The actual salary offered will carefully consider a wide range of factors, including your skills, qualifications, and experience.
Why join us?
Key moment to join Aircall in terms of growth and opportunities
Our people matter, work-life balance is important at Aircall
Fast-learning environment, entrepreneurial and strong team spirit
45+ Nationalities: cosmopolite & multi-cultural mindset
Competitive salary package & equity
Medical, dental, and vision insurance is 100% covered
401k plan with company matching
Unlimited PTO — take the time you need to come to work feeling great
Wellness, internet, and childcare reimbursements
Generous parental leave policy
DE&I Statement:
At Aircall, we believe diversity, equity and inclusion – irrespective of origins, identity, background and orientations – are core to our journey.
We pride ourselves on promoting active inclusion within our business to foster a strong sense of belonging for all. We're working to create a place filled with diverse people who can enrich and learn from one another. We're committed to ensuring that everyone not only has a seat at the table but is valued and respected at it by providing equal opportunities to develop and thrive.
We will constantly challenge ourselves to make sure that we live up to our ambitions around diversity, equity and inclusion, and keep this conversation open. Above all else, we understand and acknowledge that we have work to do and much to learn.
Want to know more about candidate privacy? Find our Candidate Privacy Notice here.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
-
Senior Security Engineer
3 days ago
Seattle, Washington, United States GuidePoint Security Full timeGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...
-
Seattle, Washington, United States Amazon Full timeDescriptionWe are open to hiring candidates to work out of one of the following locations:Arlington, VA, USAAs a Senior Security Engineer in the Defensive Security team, you will play a pivotal role in integrating threat intelligence data into our security detections, developing cross-organizational tooling, and providing undifferentiated fraud emulation,...
-
Senior Endpoint Security Engineer
5 days ago
Seattle, Washington, United States Truveta Full timeSenior Endpoint Security EngineerTruveta is the world's first health provider led data platform with a vision of Saving Lives with Data. Our mission is to enable researchers to find cures faster, empower every clinician to be an expert, and help families make the most informed decisions about their care. Achieving Truveta' s ambitious vision requires an...
-
Security Engineer
1 week ago
Seattle, Washington, United States Amazon Full timeDescriptionWe are open to hiring candidates to work out of one of the following locations:Annapolis Junction, MD, USA | Herndon, VA, USA | Seattle, WA, USAJoin Amazon's elite Security organization as a Security Engineer within our Enterprise Protection Program, where you'll play a crucial role in safeguarding our company against insider risks.As part of the...
-
Senior Engineer, Information Security
3 days ago
Seattle, Washington, United States Gates Foundation Full timeThe FoundationWe are the largest nonprofit fighting poverty, disease, and inequity around the world. Founded on a simple premise: people everywhere, regardless of identity or circumstances, should have the chance to live healthy, productive lives. We believe our employees should reflect the rich diversity of the global populations we aim to serve. We provide...
-
Sr. AI Detect
6 days ago
Seattle, Washington, United States Docusign Full timeCompany OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...
-
Senior Application Security Engineer II
2 days ago
Seattle, Washington, United States Axon Full timeJoin Axon and be a Force for Good.At Axon, we're on a mission to Protect Life. We're explorers, pursuing society's most critical safety and justice issues with our ecosystem of devices and cloud software. Like our products, we work better together. We connect with candor and care, seeking out diverse perspectives from our customers, communities and each...
-
Senior Application Security Engineer II
2 days ago
Seattle, Washington, United States Axon Full timeJoin Axon and be a Force for Good.At Axon, we're on a mission to Protect Life. We're explorers, pursuing society's most critical safety and justice issues with our ecosystem of devices and cloud software. Like our products, we work better together. We connect with candor and care, seeking out diverse perspectives from our customers, communities and each...
-
Sr. Staff Security Engineer
2 days ago
Seattle, Washington, United States Uber Full timeAbout The TeamThe security organization at Uber is dedicated to enabling safe and secure innovation while protecting the communities we serve both online and in the physical world. Our team is responsible for protecting both people and their data across intersections of the digital and physical world. The primary objective for Uber's Engineering Security...
-
Senior Application Security Engineer
2 weeks ago
Seattle, Washington, United States Brex Full time $192,000 - $240,000Why join usBrex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce...