Skip to main content
ElevenLabs
ElevenLabs

Detection Engineer

RemoteAPAC+United Kingdom· Prefers Australia, United Kingdom, Philippines +1
Published
Role
Security
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to Anywhere in APAC + GB · Prefers Australia, United Kingdom, Philippines +1. Set where you work from to check your eligibility.

The listing prefers candidates in Australia, United Kingdom, Philippines, and Singapore.

No BS summary

Security Detection & Response Engineer for APAC-based candidates who can operate in GMT+10 timezones. Needs incident response, detection engineering, Google SecOps/Chronicle SIEM, SaaS endpoint monitoring, GCP security monitoring, and scripting with Python or Bash.

Core skills

Google SecOpsChronicleGCP Security Command Center

Required skills

JAMF MDMGoogle WorkspaceOktaGCPPython/BashMITRE ATT&CKNIST Cybersecurity FrameworkSIEMJAMF

What you'll do

  • Build and maintain detection and incident response capabilities
  • Scale security efforts and reduce manual work through automation and frontier AI models
  • Develop best-in-class security practices as the company scales
  • Triage security alerts
  • Conduct security investigations
  • Lead incident response efforts
  • Develop, tune, and maintain security detection rules and alerts
  • Handle Google SecOps Chronicle data onboarding, parsing, rule creation, and dashboarding
  • Monitor security across JAMF MDM for macOS endpoints, Google Workspace, Okta, and general SaaS applications
  • Monitor cloud security in Google Cloud and GCP Security Command Center
  • Automate detection and response tasks, data parsing, and security tooling integration
  • Translate common attack techniques and threat intelligence into actionable detections
  • Build and maintain detection and incident response capabilities.
  • Scale security efforts and reduce manual work through automation and frontier AI models.
  • Develop best-in-class security practices as the company scales.
  • Triage security alerts.
  • Conduct security investigations.
  • Lead incident response efforts.
  • Develop, tune, and maintain security detection rules and alerts.
  • Onboard data, parse data, create rules, and build dashboards in Google SecOps/Chronicle.
  • Monitor security across macOS endpoints, Google Workspace, Okta, and SaaS applications.
  • Monitor cloud security in Google Cloud.
  • Automate detection and response tasks, data parsing, and security tooling integration.
  • Translate common attack techniques and threat intelligence into actionable detections.
  • Triage security alerts, conduct investigations, and lead response efforts.
  • Develop, tune and maintain security detection rules and alerts.
  • Onboard data, parse sources, create rules and dashboards in Chronicle.
  • Automate detection and response tasks using scripting and AI models.

What they require

  • Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts
  • Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts
  • Hands-on experience with SIEM infrastructure, specifically with Google SecOps Chronicle, including data onboarding, parsing, rule creation, and dashboarding
  • Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta, and general SaaS applications
  • Experience with cloud security monitoring, particularly in Google Cloud with familiarity in GCP Security Command Center
  • Solid scripting skills, such as Python or Bash, for automating detection and response tasks, data parsing, and security tooling integration
  • Deep understanding of common attack techniques and threat intelligence, with ability to translate them into actionable detections
  • Familiarity with security frameworks and best practices, such as MITRE ATT&CK and NIST Cybersecurity Framework
  • Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations
  • Ability to operate in GMT+10 timezones
  • Remote candidate based anywhere in the APAC region; particularly seeking candidates based in Singapore, Australia, or the Philippines
  • Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts.
  • Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts.
  • Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle).
  • Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta and general SaaS applications.
  • Experience with cloud security monitoring, particularly in Google Cloud (GCP) with familiarity in GCP Security Command Center (SCC).
  • Solid scripting skills for automating detection and response tasks, data parsing, and security tooling integration.
  • Deep understanding of common attack techniques, threat intelligence, and the ability to translate them into actionable detections.
  • Familiarity with security frameworks and best practices.
  • Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations.
  • This is an in-country role with a strong preference for a candidate in London.
  • Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle) — data onboarding, parsing, rule creation, and dashboarding.
  • Proficiency in security monitoring across JAMF MDM (macOS), Google Workspace, Okta and general SaaS applications; cloud security monitoring in GCP and familiarity with GCP Security Command Center (SCC).
  • Solid scripting skills (Python, Bash); deep understanding of attack techniques, threat intelligence, and familiarity with MITRE ATT&CK and NIST Cybersecurity Framework.

Benefits

  • Innovative culture with an opportunity to define the trajectory of AI
  • Growth paths with opportunities to drive impact beyond immediate role and responsibilities
  • Annual discretionary stipend for learning and development
  • Annual discretionary stipend to meet up with colleagues each year
  • Annual company offsite in a new location
  • Monthly co-working stipend if not located near one of the main hubs
  • Innovative culture and opportunity to define the trajectory of AI.
  • Growth paths and opportunities to drive impact beyond immediate role and responsibilities.
  • Annual discretionary professional development stipend.
  • Annual discretionary stipend to meet up with colleagues each year.
  • Annual company offsite in a new location.
  • Monthly co-working stipend if not located near one of the main hubs.
  • Annual discretionary stipend for learning & development.
  • Annual discretionary stipend for social travel to meet colleagues.
  • Annual company offsite.
  • Monthly co-working stipend.
  • Innovative culture and growth opportunities.

Powering the best enterprises, creators, and developers. From ElevenAgents for customer experience, ElevenCreative for content creation, to the leading AI voice generator.

🇺🇸 United StatesAI Research And ProductMid-sizeelevenlabs.io
Also posted in 2 other channels
Salary not disclosed