Senior Security Engineer, Detection Engineering

NVIDIA Ltd.
Santa Clara, CA, United States
21 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$168,000.0 - $270,250.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Code Review Collaborative Software Cyber Security Continuous Integration Intrusion Detection and Prevention Python (Programming Language) Metadata
+13 more
Performance Tuning Kusto Query Language Security Information and Event Management SQL Databases Test Data Data Logging Scripting Cyber Threat Analysis Git Information Technology Cybercrime Microsoft Sentinel Splunk

Job description

NVIDIA Security is seeking a Senior Detection Engineer to join the Detection and Automation Engineering team. On this team, we build reliable detection coverage that helps responders identify real threats quickly, reduce unnecessary noise, and protect NVIDIA’s enterprise, cloud, developer, AI, and production environments. Do you enjoy turning sophisticated security signals into detections responders can trust? Can you read an incident write-up, a red-team result, or an unusual authentication pattern and decide what is worth alerting on? We want someone who can move from hypothesis to tested production content and explain the tradeoffs clearly.

We work closely with incident response, threat intelligence, security operations, cloud security, and engineering teams. We protect enterprise, cloud, identity, endpoint, collaboration, developer, AI, and production environments. We care about detections that are explainable, measured, maintainable, and useful during real investigations.

What You’ll Be Doing:

  • Build and tune high-confidence detections across platforms such as Splunk, Microsoft Sentinel / Defender, CrowdStrike, cloud-native logs, identity telemetry, endpoint data, SaaS platforms, and developer systems.
  • Translate incidents, hunts, threat intelligence, red-team findings, and vulnerability context into detection logic we can test and operate.
  • Investigate real telemetry before we alert on it, including field behavior, timing, joins, baselines, and the false positives a responder will actually see.
  • Drive the full detection lifecycle: design, query development, validation, peer review, documentation, deployment, tuning, monitoring, and retirement.
  • Strengthen detection-as-code workflows, including test data, quality checks, metadata, rollout safety, coverage tracking, and detection health reporting.
  • Partner with responders to cut noise, add useful context, improve severity decisions, and build follow-up detections after investigations.
  • Shape logging, normalization, enrichment, and retention requirements when the telemetry we need is missing or hard to use.
  • Coach analysts and engineers through design reviews, query reviews, and clear guidance on what makes a detection credible.

Requirements

  • 8+ years of experience in detection engineering, security engineering, threat hunting, incident response, SOC engineering, or information security monitoring.
  • A degree in Computer Science, Cybersecurity, Engineering, or equivalent experience
  • Hands-on experience building and tuning detections in a major SIEM or security analytics platform.
  • Strong query and scripting skills, especially SPL, KQL, SQL, Python, or similar languages used to analyze security telemetry and automate repetitive work.
  • Practical understanding of attacker behavior across identity, endpoint, cloud, network, email, collaboration tools, developer infrastructure, secrets, and data theft.
  • Ability to move from raw logs to a production-ready detection, including field semantics, thresholds, joins, baselines, false positives, missing data, and triage context.
  • Comfortable working with Git, code review, automated checks, CI/CD, documentation, and operational ownership of the content you ship.
  • Clear communication and sound judgment. You should be able to explain why a detection matters, what it misses, what we should do next, and when we should choose not to alert.

Benefits & conditions

  • You have led or materially improved a detection-as-code program across more than one security platform.
  • Background in cloud, identity, Kubernetes, CI/CD, supply-chain, or AI-tooling attack paths well enough to design detections without waiting for a complete recipe.
  • Detected abuse in developer systems, package ecosystems, secrets workflows, AI coding tools, agents, bots, or model-serving infrastructure.
  • Worked closely with incident response, threat hunting, red team, purple team, malware analysis, or forensics teams.
  • Built validation methods such as replay tests, synthetic telemetry, attack emulation, detection unit tests, or coverage reporting.

Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 168,000 USD - 270,250 USD for Level 4, and 196,000 USD - 310,500 USD for Level 5.

You will also be eligible for equity and benefits .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:47 min

Comparing Egeria to alternative open metadata solutions

Ferd Scheepers · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

2:08 min

Creating standard APIs via the Egeria open metadata project

Ferd Scheepers · World Congress 2022

Videos

See all

Related articles

See all