> Markdown version of [/jobs/ext/2720689-security-corp-it-team](https://www.wearedevelopers.com/jobs/ext/2720689-security-corp-it-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security & Corp IT Team - **Company:** Fluidstack Ltd - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Build Automation, Software as a Service, Cloud Computing, Cyber Security, Data Centers, Query Languages, Intrusion Detection and Prevention, Python (Programming Language), Open Source Technology, Security Information and Event Management, SQL Databases, Cloud Platform System, Mitre Att&ck, Purple Team (Cyber Security), Splunk - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-detection-engineer-fluidstack-8777877 ## About the Role The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would. * 5+ years in detection engineering or threat hunting inside a mature security operations org (cloud-native infrastructure, SaaS, or fintech). * Deep hands-on experience with SIEM and EDR tooling: Splunk, Elastic, CrowdStrike, or equivalent, including query languages and pipeline tuning, not just console use. * You've written and maintained detection logic mapped to MITRE ATT&CK against real adversary behavior, and you can point to detections that caught something. * Strong scripting and automation skills (Python, SQL, or similar) and a detection-as-code workflow you'd defend: tests, review, and rollback included. * You know the difference between a noisy rule and a broken one, and you tune or kill detections before responders learn to ignore them. * You operate well with minimal process: you can scope your own work, ship without a mature SOC around you, and build the process you need as you go. * You write clearly enough that your runbooks and incident reports work when you're asleep. * Bonus: experience securing physical infrastructure or OT/data center environments, purple team experience, or contributions to open-source detection content (Sigma, detection rule repos). ## Description * Build detection and response coverage across corporate, cloud, and data center environments that are growing faster than any off-the-shelf playbook assumes. * Secure the systems and networks that frontier AI labs depend on, where downtime and compromise both carry real cost. * Stand up security tooling, identity, and endpoint management for a company that adds people, sites, and vendors every month. * Turn incident learnings and threat intel into durable detection logic instead of one-off fixes. Role Scope * Own the detection engineering program end to end: threat modeling, detection design, deployment, tuning, and retirement, with coverage mapped to MITRE ATT&CK and gaps documented rather than assumed away. * Build detection-as-code pipelines so every rule is version-controlled, tested, and peer-reviewed before it ships, and false-positive rates are measured, not guessed. * Run threat hunts against real adversary behavior in our cloud, SaaS, and data center environments, and convert findings into repeatable detections. * Drive SIEM and EDR pipeline health: log source onboarding, normalization, and alert quality good enough that on-call responders trust what pages them. * Lead triage and response for the alerts you build, and close out incidents with root-cause writeups that change the detection stack, not just the ticket queue. * Build automation that removes manual triage steps, so the team's alert load scales slower than the company does. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Building the Nervous System of AI - Michael Kagan (NVIDIA)](https://www.wearedevelopers.com/videos/2133-building-the-nervous-system-of-ai-michael-kagan-nvidia) - [How Your Bundle Size Affects The Climate](https://www.wearedevelopers.com/videos/308-how-your-bundle-size-affects-the-climate) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)