Staff Security Engineer, Cloud Detection & Response
About the role
We're searching for a Staff Cybersecurity Engineer to help mature Cloud & Enterprise Detection within our Detection & Response (D&R) team, under the Technical Assurance division.
Responsibilities
- Drive cross-functional projects to mature Aurora's detection infrastructure, log ingestion and normalization, detection-as-code pipelines with testing, versioning, and CI/CD for detection content, and scalable, cost-aware telemetry collection
- Expand detection coverage across cloud and corporate environments and prioritize coverage improvements
- Design, build, and tune detections for cloud control plane and workload activity, identity-based attacks, endpoint, SaaS threats, abuse of CI/CD and service-to-service communication paths
- Partner with Cloud Infrastructure, IT, and Platform Engineering to embed logging and detection requirements into system design, and represent D&R in cross-functional working groups and design reviews
- Integrate threat intelligence and adversary emulation into detection coverage priorities, and conduct proactive threat hunting across cloud, identity, endpoint, and SaaS data
- Respond to cloud and enterprise security incidents and participate in an on-call rotation, feeding lessons learned back into detection coverage and infrastructure improvements
- Collaborate with and mentor SOC engineers on cloud and enterprise detection practices, and contribute to quarterly planning for detection infrastructure and coverage initiatives
Requirements
- 10+ years of security experience; demonstrated experience leading cross-functional security projects or programs from scoping through delivery
- Strong technical foundation in threat detection, incident response
- Expertise with cloud security across one or more major providers, including cloud-native telemetry and detection sources
- Expertise with endpoint detection and response (EDR) and SaaS security monitoring, or comparable host and application telemetry depth
- Expertise authoring and maintaining detections (anomalous, network, host, identity, or cloud activity) and measuring detection coverage against adversary behavior
- Experience with incident management, driving cross-departmental collaboration for containment and remediation
- Experience with MITRE ATT&CK framework and modern adversarial techniques; understanding of NIST CSF
Desirable Qualifications
- Experience designing and implementing Zero Trust Architecture
- Experience scaling SOC, Detection Engineering with AI/LLM
- Experience building and architecting data lakes
- Experience with compliance frameworks (SOC 2, ISO 27001)
Qualifications
- Master's degree in Computer Science, Information Security, or related field
- CISSP or equivalent certification preferred
Benefits
For roles based in San Francisco, CA, Mountain View, CA, and Seattle, WA: The salary range for this position is $189,000 - $303,000 per year.
For roles based in Pittsburgh, PA: The salary range for this position is $171,000 - $273,000 per year.
Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions.
The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.
Schedule
At Aurora, we operate in a hybrid work environment where Aurorans are in office at least 3 days per week.
Pay
For roles based in San Francisco, CA, Mountain View, CA, and Seattle, WA: The salary range for this position is $189,000 - $303,000 per year.
For roles based in Pittsburgh, PA: The salary range for this position is $171,000 - $273,000 per year.
Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions.