> Markdown version of [/jobs/ext/2703979-security-engineer](https://www.wearedevelopers.com/jobs/ext/2703979-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Motsenbocker Advanced Developments, Inc. - **Location:** Los Angeles, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $200,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Systems Engineering, Software as a Service, Cloud Computing, Cyber Security, Continuous Integration, Linux, Intrusion Detection and Prevention, Security Information and Event Management, Software Engineering, Cloud Platform System, Prophet, Large Language Models, Production Code - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-detection-response-liftoff-7984378 ## About the Role * 5+ years in security engineering, security operations, detection engineering, or software engineering with a security focus. * Hands-on production SIEM operation - onboarding log sources, writing and maintaining detection content, and triaging alerts. * Write production-quality code for security automation and detection-as-code. * Experience leading or substantially contributing to security incident response. * Strong technical writing - design docs, runbooks, and post-incident reviews. * Demonstrated judgment in prioritizing security work using a risk-based approach. * Ability to quickly navigate large, unfamiliar codebases and reason about complex engineering systems. * Excellent verbal communication. * Willing to participate in an on-call rotation., * Hands-on experience with an AI-augmented SOC platform (Prophet Security, Dropzone AI, or equivalent), or with building large language model (LLM) augmented investigation and runbook tooling. * Experience operating in cloud environments at scale. * Cloud incident response experience, particularly in AWS. * Endpoint forensics for incident response on Mac and/or Linux. * Detection-as-code workflows in continuous integration and deployment (CI/CD) pipelines. * Mobile adtech or high-volume SaaS background. ## Description * Own day-to-day operation of Liftoff's SIEM (Panther) - log source ingestion, detection content, and the alert investigation pipeline. * Lead Liftoff's adoption of AI-augmented SOC tooling (e.g. Prophet, Dropzone, or equivalent) as a multi-year modernization investment. * Triage incoming security alerts and drive timely investigation and remediation with stakeholders across Engineering and IT. * Lead incident response - investigation, containment, and post-incident review - and mature processes and runbooks so response becomes predictable and repeatable. * Build tooling and automation that detects active threats, enriches alerts, and reduces manual investigation toil. * Partner with Engineering and IT to make detection and response self-service where possible - clear log-onboarding paths, documented detection proposals, accessible runbooks - so security scales without becoming a bottleneck. * Close the feedback loop between the team's offensive and proactive findings and detection coverage. * Partner across the security team on cloud, infrastructure, and application security work alongside your detection and response focus - every engineer on this team covers breadth beyond their primary focus. * Participate in the Security team's on-call rotation and incident response. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)