[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Liftoff logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c47aea9f-221.png)](https://jobicy.com/company/liftoff.md)Remote opportunity at[Liftoff](https://jobicy.com/company/liftoff.md)

# Security Engineer, Detection & Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/liftoff.md)Share12 Sep 2026Published53Listing views5Application actions12 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryLiftoff is seeking a senior Security Engineer to own and mature its detection and response capability across a large-scale mobile advertising platform. The role operates the Panther SIEM, develops detection content and security automation, investigates alerts, and leads incident response activities. A key strategic responsibility is leading adoption of AI-augmented SOC tooling while improving self-service processes, runbooks, and detection-as-code workflows. The engineer will collaborate closely with Engineering, IT, and the broader security team, including participation in an on-call rotation. Candidates need at least five years of relevant security engineering, security operations, detection engineering, or security-focused software engineering experience.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a high-seniority, hands-on security engineering role combining production SIEM ownership, incident leadership, software development, cloud security breadth, and a multi-year SOC modernization initiative. The scale of Liftoff's systems and the requirement to make risk-based decisions during investigations increase both technical and operational complexity.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$206,000US market range$180k–$250k0$275k

AI insightThe disclosed US base-salary bands span $172,000 to $240,000 yearly depending on approved work location; the aggregate midpoint is $206,000. A competitive US market base-salary range for a senior detection and response security engineer with SIEM ownership, incident-response leadership, cloud experience, and automation responsibilities is estimated at $180,000 to $250,000 annually, excluding equity and benefits.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[Security Operations](https://jobicy.com/jobs?search_keywords=Security%20Operations.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[Panther](https://jobicy.com/jobs?search_keywords=Panther.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[Detection as Code](https://jobicy.com/jobs?search_keywords=Detection%20as%20Code.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[AWS](https://jobicy.com/jobs?search_keywords=AWS.md)[AI-Augmented SOC](https://jobicy.com/jobs?search_keywords=AI-Augmented%20SOC.md)

Sample interview questionsHow would you assess and improve an existing SIEM detection program during your first 90 days?I would inventory critical log sources, data quality, existing rules, alert volumes, investigation outcomes, and coverage against the organization's highest-risk attack paths. I would prioritize gaps based on risk and operational value, then establish measurable improvements such as better telemetry coverage, reduced false-positive rates, documented ownership, and detection-as-code review workflows.

Describe how you would investigate a high-severity cloud security alert with limited initial context.

I would validate the alert and preserve relevant evidence, then scope the event using identity, API activity, network, endpoint, and workload telemetry. I would identify affected assets and credentials, assess potential impact, coordinate containment with system owners, and document decisions and findings for a post-incident review and follow-up detection improvements.

What principles guide your approach to security automation?

I automate repetitive, well-understood tasks that improve investigation speed or consistency, such as enrichment, evidence collection, alert routing, and containment recommendations. Automation should be observable, tested, safely permissioned, and designed with human approval for high-impact actions unless the response is clearly reversible and low risk.

How would you evaluate an AI-augmented SOC platform before adopting it broadly?

I would begin with defined use cases and success measures, such as triage time, quality of investigation summaries, false-positive reduction, and analyst trust. I would run a controlled pilot using representative alerts, assess integrations, data handling, accuracy, auditability, security controls, and operational cost, then decide whether to expand based on measurable results.

How do you build productive relationships with engineering teams when remediation work competes with feature delivery?

I frame findings in terms of concrete risk, affected systems, and practical remediation options rather than abstract security requirements. I provide clear documentation, reusable patterns, and self-service paths, collaborate on prioritization, and use post-incident lessons and detection data to show why improvements matter.

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize revenue across programmatic and direct demand.

Liftoff’s solutions, including Accelerate, Direct, Monetize, Intelligence, and Vungle Exchange, support over 6,600 mobile businesses across 74 countries in sectors such as gaming, social, finance, ecommerce, and entertainment. Founded in 2012 and headquartered in Redwood City, CA, Liftoff has a diverse, global presence.

The Liftoff Security team protects Liftoff’s customers, users, and employees. We architect Liftoff’s security posture, build the tools and systems that defend it, and partner with engineering teams as they ship new products and features. Our work spans the entire stack — infrastructure, web, mobile, and IT — and we approach security from a software engineering standpoint, scaling our impact through automation and well-designed tools.

### Now is the time to join! Here’s why:

* Build out our detection and response function. Liftoff has a mature security information and event management platform (SIEM), established detection content, and a working incident response program. Your charter is to take it to the next level — including leading our investment in AI-augmented SOC tooling.
* High visibility, high impact. Detection and response is a critical capability for Liftoff.
* Security-conscious engineering culture. Liftoff’s engineering org is a willing and capable partner on security work.
* Hands-on technical work. Stay deep in code, detections, and incidents.
* Breadth of work. Detection and response is the primary focus, but you’ll partner across the security team on cloud, infrastructure, and application security where the work demands it.
* Large-scale, interesting systems. Liftoff processes millions of requests per second across its demand-side platform (DSP), mobile software development kit (SDK), and ad exchange.

### Responsibilities:

* Own day-to-day operation of Liftoff’s SIEM (Panther) — log source ingestion, detection content, and the alert investigation pipeline.
* Lead Liftoff’s adoption of AI-augmented SOC tooling (e.g. Prophet, Dropzone, or equivalent) as a multi-year modernization investment.
* Triage incoming security alerts and drive timely investigation and remediation with stakeholders across Engineering and IT.
* Lead incident response — investigation, containment, and post-incident review — and mature processes and runbooks so response becomes predictable and repeatable.
* Build tooling and automation that detects active threats, enriches alerts, and reduces manual investigation toil.
* Partner with Engineering and IT to make detection and response self-service where possible — clear log-onboarding paths, documented detection proposals, accessible runbooks — so security scales without becoming a bottleneck.
* Close the feedback loop between the team’s offensive and proactive findings and detection coverage.
* Partner across the security team on cloud, infrastructure, and application security work alongside your detection and response focus — every engineer on this team covers breadth beyond their primary focus.
* Participate in the Security team’s on-call rotation and incident response.

### Minimum Qualifications:

* 5+ years in security engineering, security operations, detection engineering, or software engineering with a security focus.
* Hands-on production SIEM operation — onboarding log sources, writing and maintaining detection content, and triaging alerts.
* Write production-quality code for security automation and detection-as-code.
* Experience leading or substantially contributing to security incident response.
* Strong technical writing — design docs, runbooks, and post-incident reviews.
* Demonstrated judgment in prioritizing security work using a risk-based approach.
* Ability to quickly navigate large, unfamiliar codebases and reason about complex engineering systems.
* Excellent verbal communication.
* Willing to participate in an on-call rotation.

### Desirable Qualifications:

* Hands-on experience with an AI-augmented SOC platform (Prophet Security, Dropzone AI, or equivalent), or with building large language model (LLM) augmented investigation and runbook tooling.
* Experience operating in cloud environments at scale.
* Cloud incident response experience, particularly in AWS.
* Endpoint forensics for incident response on Mac and/or Linux.
* Detection-as-code workflows in continuous integration and deployment (CI/CD) pipelines.
* Mobile adtech or high-volume SaaS background.

Compensation:

The following are our base salary ranges for this role:

* SF Bay Area, Los Angeles/Orange County, NYC, Seattle: $200,000 – $240,000
* All other California and Washington state locations, Austin, Boston, Denver, Portland: $184,000 – $220,000
* All other cities and towns in our approved states: $172,000 – $206,000

Location:

This role is eligible for full-time remote work in one of our entities: CA, CO, ID, IL, FL, GA, MA, MI, MN, MO, NJ, NV, NY, OR, PA, TX, UT, and WA.

We are a remote-first company with US hubs in Redwood City, Los Angeles, and New York City.

Travel Expectations:

We offer several opportunities for in-person team gatherings, including but not limited to project meetings, regional meetups, and company-wide events. We expect our employees to attend these gatherings at least once per quarter. These gatherings provide essential opportunities for collaboration, communication, and team building.

#LI-REMOTE
#LI-EL1

Liftoff offers a fast-paced, collaborative, and innovative work environment where employees are empowered to grow and make an impact. We’re shaping the future of the mobile app ecosystem—join us and help accelerate what’s next.

Liftoff’s compensation strategy includes competitive salaries, equity, and benefits designed to support employee well-being and performance. We benchmark compensation based on role, level, and location to ensure fairness and market alignment. Benefits may include medical coverage, wellness stipends, and additional perks based on your country of residence.

Liftoff is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and applicants regardless of race, ethnicity, national origin, age, marital status, disability, sexual orientation, gender identity, religion, veteran status, or any other characteristic protected by applicable law.

Agency and Third Party Recruiter Notice:

Liftoff does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings. No fee will be paid to third parties who submit unsolicited candidates directly to our hiring managers or Recruiting Team. All candidates must be submitted via our Applicant Tracking System by approved Liftoff vendors who have been expressly requested to make a submission by our Recruiting Team for a specific job opening. No placement fees will be paid to any firm unless such a request has been made by the Liftoff Recruiting Team and such a candidate was submitted to the Liftoff Recruiting Team via our Applicant Tracking System.

Show more

[Apply now >](https://jobicy.com/jobs/153102-security-engineer-detection-response.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 12

### [Manager, Security Incident Response](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Sep 12

### [Offensive Security Engineer](https://jobicy.com/jobs/149060-offensive-security-engineer.md)

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The…

*
![Rithum logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/fe3986d8-221-1.jpeg)
Rithum  Sep 12

### [Staff Information Security Engineer – AI First](https://jobicy.com/jobs/153112-staff-information-security-engineer-ai-first.md)

Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers,…

*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…