All remote jobs
Open role
Remote opportunity atQuora

Detection & CorpSec Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
17Listing views
1Application actions
28 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

This senior Detection & Corporate Security Engineer role builds SIEM-based detection capabilities and corporate security controls for Quora and Poe. The engineer will develop detections, canary mechanisms, incident-response runbooks, and investigations spanning malware analysis, log review, and timeline reconstruction. The role also partners closely with IT on endpoint protection, identity, device compliance, VPN access, and Zero-Trust infrastructure. It requires strong production Python skills, security engineering judgment, and the ability to advise both technical and non-technical stakeholders in a fast-moving remote-first organization.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThe position combines detection engineering, incident response, endpoint and identity security, and corporate infrastructure ownership. It requires at least five years of relevant experience plus production-quality Python and the judgment to operate effectively in a small, high-ownership security team.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$210,960
US market range$165k–$250k
AI insightThe disclosed US base salary range is $172,279 to $249,640 USD yearly, with a midpoint of $210,959.50. A competitive US-market estimate for a senior hybrid detection and corporate security engineering role is approximately $165,000 to $250,000 annually, varying by location, cloud/security specialization, and scope of incident-response ownership.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you design a SIEM program for both corporate and production environments?

I would begin with an asset inventory and threat model to prioritize telemetry from identity providers, endpoints, cloud infrastructure, VPNs, SaaS applications, and production services. I would normalize high-value logs, define retention and access controls, implement detections mapped to likely attack paths, and tune them using real investigation outcomes. I would measure coverage, alert fidelity, mean time to investigate, and gaps in telemetry over time.

Describe your approach to investigating a suspected endpoint compromise.

I would first contain the risk proportionately, preserve volatile evidence, and collect endpoint, identity, network, and cloud logs. I would establish a timeline, determine initial access and persistence mechanisms, assess credential theft or data exfiltration, and identify affected users and systems. I would then document findings, eradicate the threat, validate recovery, and convert lessons learned into detections and response runbooks.

What makes a detection rule useful rather than noisy?

A useful detection is tied to a specific adversary behavior and has enough contextual enrichment to support a clear analyst decision. I validate rules against historical data and safe simulations, define severity based on impact and confidence, and tune exclusions carefully rather than suppressing broad classes of activity. Each alert should identify the relevant user, asset, behavior, supporting evidence, and recommended investigative steps.

How would you partner with IT to improve employee-fleet security without creating unnecessary friction?

I would jointly define minimum standards for managed devices, EDR coverage, disk encryption, patching, identity protections, and secure access, then phase implementation based on risk. Clear exception processes, user communication, and measurable compliance reporting help maintain trust and operational adoption. I would also seek automation and self-service options so security controls are reliable without becoming a recurring burden on employees or IT.

How have you used Python to improve security operations?

I use Python to automate repetitive investigations, enrich alerts with identity and asset context, parse and normalize logs, and integrate security tools through APIs. For production tooling, I use code review, tests, error handling, observability, and documentation so the automation is maintainable by the broader engineering team. I prioritize automations that reduce analyst toil while preserving human review for high-impact decisions.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.]

About Quora:

Quora’s mission is to grow the world’s collective intelligence. To do so, we have two platforms:

  • Quora: a global knowledge sharing platform with over 300M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

  • Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-5.6-Sol, Claude-Opus-5, Claude-Fable-5, Claude-Sonnet-5, Kimi-K3, and thousands of others. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

About the Team and Role:

Quora’s Security team is responsible for protecting the company’s most critical assets from both external threats and insider risks. We’re a small, high-ownership team with a pragmatic, builder-oriented approach: we build where commercial solutions don’t fit, leverage AI to work efficiently at scale, and move fast to stay ahead of real-world threats.

We’re looking for a Detection & Corporate Security Engineer to strengthen both our preventative and detection capabilities across corporate and production environments. This is a genuinely hybrid role: you’ll build and maintain detection systems while also owning the corporate security controls that protect our employee fleet and internal infrastructure. You’ll work closely with our IT team, collaborate with existing security engineers on production-side coverage, and serve as a trusted security advisor to non-technical teams across the organization.

Responsibilities:

  • Build and maintain a SIEM to collect and analyze logs from across corporate and production systems; write and deploy detections and alerts to identify malicious behavior

  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets

  • Investigate security incidents end-to-end — including malware analysis, exfiltration assessment, and timeline reconstruction — and build runbooks to scale response capabilities

  • Partner with IT to define and enforce security standards across the employee device fleet, including endpoint protection, managed device requirements, OS compliance, and VPN access controls

  • Drive the PoC and implementation of Zero-Trust VPN and other corporate security infrastructure

  • Provide security guidance and advisory support to non-engineering functions across the organization

Minimum Requirements:

  • Availability for meetings and impromptu communication during Quora’s “coordination hours” (Mon-Fri: 9am-3pm Pacific Time)

  • 5+ years of experience in security engineering, detection engineering, or a closely related field

  • Hands-on experience building or maintaining SIEM infrastructure and writing detection rules

  • Experience with endpoint security tools (e.g. CrowdStrike or similar EDR platforms)

  • Strong Python engineering skills with a track record of writing production code reviewed and shipped alongside software engineering teams

  • Experience conducting security incident investigations, including malware analysis, log review, and timeline reconstruction and threat modeling

  • Experience with corporate security controls, identity management, endpoint protection, and access control enforcement

Preferred Requirements:

  • Experience with SIEM/SOAR options such as Elastic/Splunk or alternatives

  • Familiarity with identity platforms such as Okta

  • Strong understanding of authentication technology such as OAuth, Yubikey and Passkey

  • Experience with Zero-Trust network architecture or VPN implementation

  • Demonstrated use of AI coding tools to build or automate security workflows

  • Experience in a small security team or fast-paced startup environment

  • Familiarity with AWS and cloud-native security tooling

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

Additional Information:

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting pay, including but not limited to experience, location, education, and business needs.

  • US candidates only: For US based applicants, the salary range is $172,279 – $249,640 USD + equity + benefits.

  • Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $220,272 – $255,347 CAD + equity + benefits. For all other locations in Canada, the salary range is $205,587 – $238,324 CAD + equity + benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice

#LI-JC1
#LI-REMOTE

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu