Paxos logo
Paxos

Security Engineer, Detection and Response

USARemotePosted 5 days ago

Apply opens Paxos's site. When you're back, we'll ask whether you applied.

Job type
Full-time
Work mode
Remote
Level
Not listed
Department
Information Technology
Experience
3+ years experience
Posted
Sep 29, 2026

About the role

About the role

The Detection and Response Engineer at Paxos serves as a builder of the detections, hunts, and automations that protect our cloud infrastructure, crypto systems, endpoints, and network. You will write detections as code and automate response, and act as a purple teamer, emulating attacks alongside our Product Security teams to confirm our detections work. Our 24x7 SOC handles first-line triage, so your focus is the detection engineering, threat hunting, and validation that make our coverage effective. Strong hands-on investigation skills are expected, but they support this work rather than define it.

What you'll do

  • Detection Coverage & Quality: Ship production-grade detections as code with measurable signal improvements—reducing false positives and closing gaps identified in purple team exercises.
  • Validated Defenses: Run purple team exercises with other teams to confirm detection effectiveness and identify blind spots.
  • Threat Hunting Program: Execute proactive hunts based on threat intelligence and convert findings into new detections and documented IOCs/TTPs.
  • Operational Efficiency: Build automations to accelerate investigation and triage; create and maintain runbooks and incident write-ups that make response consistent and repeatable across the team.
  • Detection Stack: Identify gaps and integrate best-in-class tools that increase team effectiveness and visibility across endpoints, cloud, network, and signing systems.

About you

  • You bring 3+ years of experience in security operations, detection engineering, offensive security testing, or a related security engineering role, and you're comfortable owning tickets and incidents end-to-end within established runbooks, escalating clearly when you hit the edge of your knowledge.
  • You have hands-on experience investigating and responding to security threats across endpoints, cloud environments, and network telemetry, using existing tooling (SIEM, EDR, ticketing systems) effectively rather than needing to build it from scratch.
  • You bring strong analytical judgment and a calm, methodical approach to triaging alerts and driving incidents through resolution, and you flag gaps in process or coverage as you find them.
  • You have hands-on experience tuning detections in SIEM and EDR platforms to improve signal quality and reduce false positives, and can write or adapt detection rules from an existing template or pattern.
  • You have used adversary-emulation or purple-team tooling to validate that your detections actually fire, and you understand common attack paths well enough to know what a given detection should — and shouldn't — catch.
  • You are a builder who looks for opportunities to automate repetitive work, including using AI and scripting (Python/Bash) to speed up investigations.
  • You communicate clearly within your immediate team, contribute meaningfully to post-incident write-ups, and act on feedback that sharpens your investigative and detection work.
  • You are prepared to participate in an on-call rotation and document incidents clearly and effectively to support continuous improvement.