# Senior Detection and Response Engineer

**Company**: Anduril
**Location**: Costa Mesa, California, United States
**Work arrangement**: onsite
**Experience**: senior
**Job type**: full-time
**Salary**: $166,000-$220,000 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/andurilindustries/jobs/5124512007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_1af961d3-bc7

## Description

About the Team

Anduril's Information Security team is looking for a Senior Detection and Response Engineer to focus on building world-class defensive controls to protect the infrastructure around our advanced defense technology products. This is a role with wide berth that will have the latitude to design and implement cutting-edge security architecture.

What You'll Do

Collaborate with Counter Intelligence and Insider Threat teams to develop key signals and capabilities to identify nefarious activity

Support internal tooling that surfaces detections to partner teams in real-time, including API integrations, audit-trail instrumentation, and data-source health

Collaborate with Counter Intelligence, SecOps, Insider Threat, and other key stakeholders to architect and implement detection and response frameworks for Anduril's products, assets, and other custom applications

Build and optimize tailored detection signatures and response automation using detection-as-code principles

Lead threat modeling scenarios with cross-functional partners to understand weaknesses across OT, Cloud, Network, Endpoints, and other key worlds incorporating findings into security controls and/or detection signatures

Lead large-scale baselines of data, collaborating across many teams to emit signals to incorporate into detections, new telemetry ingestion, and/or security controls

Contribute directly to the development and advancement of our detection-as-code, data engineering, automation, and infrastructure capabilities

Design and tune User and Entity Behavior Analytics (UEBA) capabilities , including baselining, anomaly detection, and risk scoring , to surface insider threat and counterintelligence signals across identity, endpoint, and data-access telemetry

Work cross-collaboratively with different teams to mature the detection and response of threat actors in key worlds, developing data baselines, automation, and engineering capabilities to scale this capability across the business

Required Qualifications

Experience programming in one or more general-purpose languages (Python, Go, Rust, SQL, etc.)

Experience conducting data analysis in large-scale data lake environments

Experience deploying infrastructure as code (Terraform, CDK, CloudFormation, etc)

Experience working in a traditional software development lifecycle (i.e. Github, CI/CD, unit testing)

Extensive experience utilizing AWS / Azure security controls and services

Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure

Deep understanding of adversarial tradecraft with an emphasis on counterintelligence and insider threat tactics, techniques, and procedures (TTPs)

Strong communication skills, both written and verbal, and experience collaborating with internal and external stakeholders

Must be able to obtain and hold a U.S. Top Secret security clearance

Preferred Qualifications

Experience working directly with counterintelligence, insider threat, or special investigations teams in a cleared environment

Experience deploying infrastructure using Kubernetes (EKS) and/or Docker containers (ECS)

Experience proactively threat hunting using threat and counter-intelligence signals to identify potential risks and weaknesses in telemetry

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

## Skills

### Required
- Python
- Go
- Rust
- SQL
- Terraform
- CDK
- CloudFormation
- AWS
- Azure
- endpoint
- network
- identity
- application
- cloud infrastructure

### Nice to have
- Kubernetes
- Docker
- threat hunting
- counter-intelligence
- insider threat

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/andurilindustries/jobs/5124512007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
