1

Detection Engineer Jobs in California (NOW HIRING)

Detection Engineer

San Francisco, CA · On-site

$150 - $200/hr

We are a team of ex-Google engineers who built the world's largest defensive moats: Safe Browsing (5B+ users) and reCAPTCHA (5M+ sites) . We've seen how global-scale detection works--and we know why ...

Lead detection engineering for Fluidstack's IT surface, including cross-domain detections where IT bridges OT or physical surfaces. * Author and tune production detections as code, with peer review ...

Your Charter Build and scale detection engineering, threat monitoring, and incident response capabilities across 1X's cloud, enterprise, robotics, and infrastructure environments. This role is ...

next page

Showing results 1-20

Detection Engineer information

What does a detection engineer do?

A Detection Engineer is responsible for identifying, analyzing, and mitigating security threats by developing detection rules, monitoring security systems, and responding to potential incidents. They work with security tools like SIEMs, EDRs, and IDS/IPS to detect malicious activity and improve threat detection capabilities. Additionally, they collaborate with security teams to enhance defensive strategies and automate detection processes.

What are the key skills and qualifications needed to thrive as a detection engineer?

To thrive as a Detection Engineer, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with threat detection and response, often supported by a degree in computer science or a related field. Proficiency with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like GIAC or CISSP are commonly required. Attention to detail, proactive problem-solving abilities, and effective communication enhance effectiveness in this role. These skills are crucial as Detection Engineers must accurately identify security threats, collaborate with teams, and minimize potential risks to the organization.

What kind of projects or tasks does a detection engineer typically work on?

As a Detection Engineer, you can expect to work on designing, implementing, and refining security detection strategies to identify potential threats and vulnerabilities in company systems. Daily responsibilities often include developing detection logic, analyzing security alerts, conducting threat hunting exercises, and collaborating with incident response teams. You may also work closely with other cybersecurity professionals to evaluate the effectiveness of existing security measures and recommend improvements. This dynamic environment offers opportunities to work on complex technical challenges while directly contributing to the organization’s overall security posture.

What are the most commonly searched types of Detection Engineer jobs in California?

The most popular types of Detection Engineer jobs in California are:

What cities in California are hiring for Detection Engineer jobs?

Cities in California with the most Detection Engineer job openings:

Infographic showing various Detection Engineer job openings in California as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

$116 - $174/hr

Other

Posted 8 days ago


Job description

23andMe is looking for an experienced detection engineer to join our Security Operations Team. You will bring critical thinking skills, hands-on experience with Enterprise Security design and the ability to work with and influence cross-functional teams (Engineering, IT, NetOps and Architecture).

You’ll be leveraging your experience and expertise with enterprise security tools and industry best practices to secure our customer data and corporate assets.

What You’ll Do
  • Work within the Security Operations Team to identify threats within the environment through traditional threat hunting techniques
  • Work collaboratively to speed up response time and to determine the state of the potential threat / alert
  • Assist the security organization to identify automation opportunities and work to implement those integrations and automation improvements within the security tooling
  • Participate in an on-call rotation with additional bonus opportunities
  • Leverage multiple security techniques and tools daily, including but not limited to use of tools for: intrusion detection, endpoint detection and response, and SIEM
  • Actively threat hunt within security tools and determine steps to triage and filter the true events from background noise
  • Create and use threat hunting playbooks
  • Create and use security operations runbooks to respond to alerts
  • Design and implement new security playbooks and automation
  • Define, design, and build threat detection methodologies; help to improve the security posture of the company
  • Lead by example and share your creativity, wit and experience across the team, working on a variety of tasks ranging from threat detection within multiple enterprise security tools, assessing threats and providing targeted responses and monitoring the corporate environment for potential risks
  • Integrate, configure and maintain SIEM tools
  • Train and mentor security engineers and analysts to utilize SIEM technology
  • Manage and improve our incident response workflow, implement mitigation plans in cooperation with Engineering, SecOps, AppSec, and IT teams
  • Help teams to leverage the existing and emerging logging and monitoring solutions, extract security events from the logs with filter/correlation tools, evaluate misconfiguration and intrusion detection signals, automate as much as possible
  • Improve our vulnerability management program: setup and integrate security scans, triage and mitigate vulnerabilities, communicate required actions to relevant teams
  • Implement, monitor and support Product, corporate IT and infrastructure security solutions, including: configure, manage and optimize logging, monitoring, correlation and alerting tools, and the orchestration through a security information and event management (SIEM) solution
  • Data Loss Prevention (DLP) solution focusing on PII and Intellectual Property related data
  • Detect and respond: Deploy Threat Intelligence products and develop threat reports
  • Assist with the design, development, delivery, documentation, training, and reporting on security control mechanisms (e.g. WAF, endpoint‑protection/AV/EDR, etc.)
  • Evaluate security technologies; work closely with vendors to ensure timely delivery of products, services, and feature requests
  • Risk and evidence‑based approach: Identify, assess, and prioritize security risks to Product, Infrastructure, Enterprise data and systems, including external threats, internal threats, and exposure to third‑party vulnerabilities
  • Other duties as assigned
What You’ll Bring
  • Passion for security
  • Familiarity with how attacks are conducted against network infrastructure, web applications and employees
  • Hands‑on experience with SIEM, EDR, osquery/FleetDM, and other security tools, with the ability to triage alerts effectively to identify potential threats
  • Some knowledge and capability with one or more scripting and programming languages (e.g., bash, Go, Python, etc.)
  • Working knowledge of operating systems (e.g., MacOS, Windows, Linux)
  • Hands‑on experience with information security tools in Google Workspace, Cloudflare, Okta, and AWS
  • Strong understanding of security concepts such as incident response, cloud security monitoring, network security monitoring, host based analysis, MITRE ATT&CK, Cyber Kill Chain, CIA triad, and Zero Trust
  • Sound familiarity with AWS security concepts
  • Ability to communicate well and work with others
  • Ability to think critically about challenging problems to determine the most effective method to solve and address
  • A minimum of 3 years of experience with managing large scale enterprise security infrastructure including security solution design and hands‑on engineering
  • B.S./M.S. in computer science, engineering, information systems, IT, Information Security, or a related technical field
EEO Statement

At 23andMe, we value a diverse, inclusive workforce and we provide equal employment opportunity for all applicants and employees. All qualified applicants for employment will be considered without regard to an individual’s race, color, sex, gender identity, gender expression, religion, age, national origin or ancestry, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, genetic information, military or veteran status, or any other basis protected by federal, state or local laws. If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at accommodations-ext@23andme.com. 23andMe will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.

Pay Transparency

23andMe takes a market‑based approach to pay, and amounts will vary depending on your geographic location. The salary range reflected here is for a candidate based in the San Francisco Bay Area. The successful candidate’s starting pay will be determined based on job‑related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.

San Francisco Bay Area Base Pay Range: $116,000 – $174,000 USD

#J-18808-Ljbffr