- Job type
- Full-time
- Work mode
- Remote
- Level
- Not listed
- Department
- Information Technology
- Experience
- 3+ years experience
- Posted
- Sep 29, 2026
About the role
About the role
The Detection and Response Engineer at Paxos serves as a builder of the detections, hunts, and automations that protect our cloud infrastructure, crypto systems, endpoints, and network. You will write detections as code and automate response, and act as a purple teamer, emulating attacks alongside our Product Security teams to confirm our detections work. Our 24x7 SOC handles first-line triage, so your focus is the detection engineering, threat hunting, and validation that make our coverage effective. Strong hands-on investigation skills are expected, but they support this work rather than define it.
What you'll do
- Detection Coverage & Quality: Ship production-grade detections as code with measurable signal improvements—reducing false positives and closing gaps identified in purple team exercises.
- Validated Defenses: Run purple team exercises with other teams to confirm detection effectiveness and identify blind spots.
- Threat Hunting Program: Execute proactive hunts based on threat intelligence and convert findings into new detections and documented IOCs/TTPs.
- Operational Efficiency: Build automations to accelerate investigation and triage; create and maintain runbooks and incident write-ups that make response consistent and repeatable across the team.
- Detection Stack: Identify gaps and integrate best-in-class tools that increase team effectiveness and visibility across endpoints, cloud, network, and signing systems.
About you
- You bring 3+ years of experience in security operations, detection engineering, offensive security testing, or a related security engineering role, and you're comfortable owning tickets and incidents end-to-end within established runbooks, escalating clearly when you hit the edge of your knowledge.
- You have hands-on experience investigating and responding to security threats across endpoints, cloud environments, and network telemetry, using existing tooling (SIEM, EDR, ticketing systems) effectively rather than needing to build it from scratch.
- You bring strong analytical judgment and a calm, methodical approach to triaging alerts and driving incidents through resolution, and you flag gaps in process or coverage as you find them.
- You have hands-on experience tuning detections in SIEM and EDR platforms to improve signal quality and reduce false positives, and can write or adapt detection rules from an existing template or pattern.
- You have used adversary-emulation or purple-team tooling to validate that your detections actually fire, and you understand common attack paths well enough to know what a given detection should — and shouldn't — catch.
- You are a builder who looks for opportunities to automate repetitive work, including using AI and scripting (Python/Bash) to speed up investigations.
- You communicate clearly within your immediate team, contribute meaningfully to post-incident write-ups, and act on feedback that sharpens your investigative and detection work.
- You are prepared to participate in an on-call rotation and document incidents clearly and effectively to support continuous improvement.