Modal

Detection and Response Engineer

Full-timeNot specifiedNew YorkNot disclosedApply by 16 Oct 2026
Apply now
WA

Overview

We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade.

What you'll do

  • This is an engineering role focused on automation.
  • You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness.
  • You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient.
  • WHAT YOU'LL WORK ON: DETECTION ENGINEERING
  • Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
  • Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
  • Improve visibility across cloud infrastructure, containers, identity systems, and production services INCIDENT RESPONSE
  • Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems

Requirements

  • Experience building AI- or LLM-powered security tooling
  • Experience with SIEM, SOAR, or EDR platforms
  • Experience with Kubernetes security or large-scale cloud infrastructure
  • Experience with threat hunting, malware analysis, or digital forensics
  • Experience contributing to security operations in a high-growth engineering organization

Skills

GoKubernetesLLMRAG

Related roles