Build detections that survive contact with reality.
TandemTrace is building the autonomous layer for the modern SOC. Our agents investigate alerts, correlate evidence, hunt for threats, and help security teams understand what happened across the tools they already use.
You will help turn adversary behavior and messy enterprise telemetry into reliable detection logic. You will also shape how AI proposes, tests, explains, and improves detections without confusing plausible output with verified security value.
The goal is not more rules. The goal is better security signal: grounded in attacker behavior, validated against evidence, measurable in production, and understandable by defenders.
Detection engineering with a feedback loop.
- Design and implement detections across endpoint, identity, cloud, network, email, and application telemetry.
- Develop detection-as-code workflows for versioning, testing, review, deployment, observability, and continuous improvement.
- Use AI in the engineering loop to accelerate research, query generation, translation, testing, explanation, and tuning while enforcing evidence-based validation.
- Build evaluation datasets and test harnesses that measure coverage, precision, robustness, drift, and false-positive behavior.
- Research attacker techniques and translate them into detection opportunities, telemetry requirements, hunt logic, and investigation context.
- Partner with product and engineering to make high-quality detection knowledge available to autonomous investigations and customer environments.
Behavior, telemetry, code, and models.
Senior judgment. Hands-on execution.
- Substantial hands-on detection-engineering experience in enterprise security operations, security products, or both.
- A strong record of shipping and improving detections using real production telemetry and measurable operational feedback.
- Deep understanding of attacker behavior and the telemetry required to observe it across multiple layers of the environment.
- Strong coding and automation ability, especially with Python and modern software-development practices.
- Practical experience applying AI or machine learning to security data, detection workflows, investigations, or engineering productivity.
- Healthy skepticism and clear writing. You expose assumptions, document tradeoffs, and make technical decisions inspectable.
Help define how AI improves detection itself.
Most security teams have more detection content than they can validate, maintain, and connect to real investigations. This role is an opportunity to work on that problem at the system level, combining detection craft with autonomous reasoning and continuous operational feedback.
You will work directly with an experienced cybersecurity founder and a compact product team. Your work will influence the product’s detection knowledge, evaluation standards, threat-hunting capabilities, and technical credibility with serious security teams.