Modal
Detection and Response Engineer
Full-timeNot specifiedNew YorkNot disclosedApply by 16 Oct 2026
Overview
We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade.
What you'll do
- This is an engineering role focused on automation.
- You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness.
- You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.
- WHAT YOU'LL WORK ON: DETECTION ENGINEERING
- Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
- Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
- Improve visibility across cloud infrastructure, containers, identity systems, and production services INCIDENT RESPONSE
- Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
Requirements
- Experience building AI- or LLM-powered security tooling
- Experience with SIEM, SOAR, or EDR platforms
- Experience with Kubernetes security or large-scale cloud infrastructure
- Experience with threat hunting, malware analysis, or digital forensics
- Experience contributing to security operations in a high-growth engineering organization
Skills
GoKubernetesLLMRAG