[All remote jobs](https://jobicy.com/jobs.md)Open role[![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)](https://jobicy.com/company/quora.md)Remote opportunity at[Quora](https://jobicy.com/company/quora.md)

# Detection & CorpSec Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/quora.md)Share29 Aug 2026Published22Listing views2Application actions28 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryThis senior Detection & Corporate Security Engineer role builds SIEM-based detection capabilities and corporate security controls for Quora and Poe. The engineer will develop detections, canary mechanisms, incident-response runbooks, and investigations spanning malware analysis, log review, and timeline reconstruction. The role also partners closely with IT on endpoint protection, identity, device compliance, VPN access, and Zero-Trust infrastructure. It requires strong production Python skills, security engineering judgment, and the ability to advise both technical and non-technical stakeholders in a fast-moving remote-first organization.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThe position combines detection engineering, incident response, endpoint and identity security, and corporate infrastructure ownership. It requires at least five years of relevant experience plus production-quality Python and the judgment to operate effectively in a small, high-ownership security team.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$210,960US market range$165k–$250k0$275k

AI insightThe disclosed US base salary range is $172,279 to $249,640 USD yearly, with a midpoint of $210,959.50. A competitive US-market estimate for a senior hybrid detection and corporate security engineering role is approximately $165,000 to $250,000 annually, varying by location, cloud/security specialization, and scope of incident-response ownership.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Corporate Security](https://jobicy.com/jobs?search_keywords=Corporate%20Security.md)[Endpoint Security](https://jobicy.com/jobs?search_keywords=Endpoint%20Security.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Zero Trust](https://jobicy.com/jobs?search_keywords=Zero%20Trust.md)[Identity and Access Management](https://jobicy.com/jobs?search_keywords=Identity%20and%20Access%20Management.md)

Sample interview questionsHow would you design a SIEM program for both corporate and production environments?I would begin with an asset inventory and threat model to prioritize telemetry from identity providers, endpoints, cloud infrastructure, VPNs, SaaS applications, and production services. I would normalize high-value logs, define retention and access controls, implement detections mapped to likely attack paths, and tune them using real investigation outcomes. I would measure coverage, alert fidelity, mean time to investigate, and gaps in telemetry over time.

Describe your approach to investigating a suspected endpoint compromise.

I would first contain the risk proportionately, preserve volatile evidence, and collect endpoint, identity, network, and cloud logs. I would establish a timeline, determine initial access and persistence mechanisms, assess credential theft or data exfiltration, and identify affected users and systems. I would then document findings, eradicate the threat, validate recovery, and convert lessons learned into detections and response runbooks.

What makes a detection rule useful rather than noisy?

A useful detection is tied to a specific adversary behavior and has enough contextual enrichment to support a clear analyst decision. I validate rules against historical data and safe simulations, define severity based on impact and confidence, and tune exclusions carefully rather than suppressing broad classes of activity. Each alert should identify the relevant user, asset, behavior, supporting evidence, and recommended investigative steps.

How would you partner with IT to improve employee-fleet security without creating unnecessary friction?

I would jointly define minimum standards for managed devices, EDR coverage, disk encryption, patching, identity protections, and secure access, then phase implementation based on risk. Clear exception processes, user communication, and measurable compliance reporting help maintain trust and operational adoption. I would also seek automation and self-service options so security controls are reliable without becoming a recurring burden on employees or IT.

How have you used Python to improve security operations?

I use Python to automate repetitive investigations, enrich alerts with identity and asset context, parse and normalize logs, and integrate security tools through APIs. For production tooling, I use code review, tests, error handling, observability, and documentation so the automation is maintainable by the broader engineering team. I prioritize automations that reduce analyst toil while preserving human review for high-impact decisions.

[[Quora is a privately held, “remote-first” company](https://www.quora.com/q/quora/Remote-First-at-Quora). This position can be performed remotely from anywhere in Canada or the United States. Please visit [careers.quora.com/eligible-countries](http://careers.quora.com/eligible-countries) for details regarding employment eligibility by country.]

### About Quora:

Quora’s mission is to grow the world’s collective intelligence. To do so, we have two platforms:

*

[Quora](http://quora.com): a global knowledge sharing platform with over 300M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

*

[Poe](https://poe.com/): a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-5.6-Sol, Claude-Opus-5, Claude-Fable-5, Claude-Sonnet-5, Kimi-K3, and thousands of others. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

### About the Team and Role:

Quora’s Security team is responsible for protecting the company’s most critical assets from both external threats and insider risks. We’re a small, high-ownership team with a pragmatic, builder-oriented approach: we build where commercial solutions don’t fit, leverage AI to work efficiently at scale, and move fast to stay ahead of real-world threats.

We’re looking for a Detection & Corporate Security Engineer to strengthen both our preventative and detection capabilities across corporate and production environments. This is a genuinely hybrid role: you’ll build and maintain detection systems while also owning the corporate security controls that protect our employee fleet and internal infrastructure. You’ll work closely with our IT team, collaborate with existing security engineers on production-side coverage, and serve as a trusted security advisor to non-technical teams across the organization.

### Responsibilities:

*

Build and maintain a SIEM to collect and analyze logs from across corporate and production systems; write and deploy detections and alerts to identify malicious behavior

*

Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets

*

Investigate security incidents end-to-end — including malware analysis, exfiltration assessment, and timeline reconstruction — and build runbooks to scale response capabilities

*

Partner with IT to define and enforce security standards across the employee device fleet, including endpoint protection, managed device requirements, OS compliance, and VPN access controls

*

Drive the PoC and implementation of Zero-Trust VPN and other corporate security infrastructure

*

Provide security guidance and advisory support to non-engineering functions across the organization

### Minimum Requirements:

*

Availability for meetings and impromptu communication during Quora’s “[coordination hours](https://quora.com/coordination_hours)” (Mon-Fri: 9am-3pm Pacific Time)

*

5+ years of experience in security engineering, detection engineering, or a closely related field

*

Hands-on experience building or maintaining SIEM infrastructure and writing detection rules

*

Experience with endpoint security tools (e.g. CrowdStrike or similar EDR platforms)

*

Strong Python engineering skills with a track record of writing production code reviewed and shipped alongside software engineering teams

*

Experience conducting security incident investigations, including malware analysis, log review, and timeline reconstruction and threat modeling

*

Experience with corporate security controls, identity management, endpoint protection, and access control enforcement

### Preferred Requirements:

*

Experience with SIEM/SOAR options such as Elastic/Splunk or alternatives

*

Familiarity with identity platforms such as Okta

*

Strong understanding of authentication technology such as OAuth, Yubikey and Passkey

*

Experience with Zero-Trust network architecture or VPN implementation

*

Demonstrated use of AI coding tools to build or automate security workflows

*

Experience in a small security team or fast-paced startup environment

*

Familiarity with AWS and cloud-native security tooling

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

### Additional Information:

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting pay, including but not limited to experience, location, education, and business needs.

*

US candidates only: For US based applicants, the salary range is $172,279 – $249,640 USD + equity + benefits.

*

Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $220,272 – $255,347 CAD + equity + benefits. For all other locations in Canada, the salary range is $205,587 – $238,324 CAD + equity + benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: [https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice](https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice)

#LI-JC1
#LI-REMOTE

Show more

[Apply now >](https://jobicy.com/jobs/151966-detection-corpsec-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora  Aug 29

### [Senior Infrastructure Security Software Engineer](https://jobicy.com/jobs/151970-senior-infrastructure-security-software-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

*
![Veeam Software logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/f7716b71-221.jpg)
Veeam Software  Aug 28

### [Cyber-Security Operations Analyst III, Product AppSec](https://jobicy.com/jobs/151951-cyber-security-operations-analyst-iii-product-appsec.md)

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Engineer I, Information Technology](https://jobicy.com/jobs/151867-security-engineer-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Analyst I, Information Technology](https://jobicy.com/jobs/151862-security-analyst-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass  Aug 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Lead Security Operations Engineer](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Aug 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Senior Application Security Manager](https://jobicy.com/jobs/151788-senior-application-security-manager.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 27

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Aug 27

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….