
Detection Engineer
- Role
- Security
- Employment
- Full-time
- Company size
- Startup
Open to Anywhere in APAC + GB · Prefers Australia, United Kingdom, Philippines +1. Set where you work from to check your eligibility.
The listing prefers candidates in Australia, United Kingdom, Philippines, and Singapore.
No BS summary
Security Detection & Response Engineer for APAC-based candidates who can operate in GMT+10 timezones. Needs incident response, detection engineering, Google SecOps/Chronicle SIEM, SaaS endpoint monitoring, GCP security monitoring, and scripting with Python or Bash.
Core skills
Required skills
About ElevenLabs
ElevenLabs is an AI research and product company transforming how we interact with technology.
We launched in January 2023 with the first human-like AI voice model. Today, we serve millions of users and thousands of businesses - from fast-growing startups to large enterprises like Deutsche Telekom and Meta. Our investors are some of the world's most prominent, including Andreessen Horowitz, ICONIQ Growth and Sequoia. We've raised $781M in funding and our last valuation was $11B - multiples of 11, always.
We have expanded from voice into three main platforms:
- ElevenAgents enables businesses to deliver seamless and intelligent customer experiences, with the integrations, testing, monitoring, and reliability necessary to deploy voice and chat agents at scale.
- ElevenCreative empowers creators and marketers to generate and edit speech, music, image, and video across 70+ languages.
- ElevenAPI gives developers access to our leading AI audio foundational models.
Everything we do is the result of the creativity and commitment of our team - builders doing the best work of their lives. We are researchers, engineers, and operators. IOI medalists and ex-founders. If you want to work hard and create lasting positive impact, we want to hear from you.
How we work
- High-velocity: Rapid experimentation, lean autonomous teams, and minimal bureaucracy.
- Impact not job titles: We don’t have job titles. Instead, it’s about the impact you have. No task is above or beneath you.
- AI first: We use AI to move faster with higher-quality results. We do this across the whole company—from engineering to growth to operations.
- Excellence everywhere: Everything we do should match the quality of our AI models.
- Global team: We prioritize your talent, not your location.
What we offer
- Innovative culture: You’ll be part of a generational opportunity to define the trajectory of AI, surrounded by a team pushing the boundaries of what’s possible.
- Growth paths: Joining ElevenLabs means joining a dynamic team with countless opportunities to drive impact - beyond your immediate role and responsibilities.
- Learning & development: ElevenLabs proactively supports professional development through an annual discretionary stipend.
- Social travel: We also provide an annual discretionary stipend to meet up with colleagues each year, however you choose.
- Annual company offsite: Each year, we bring the entire team together in a new location - past offsites have included Croatia and Italy.
- Co-working: If you’re not located near one of our main hubs, we offer a monthly co-working stipend.
About the role
As a Security Detection & Response Engineer at ElevenLabs, you'll be on the front lines of our security operations, playing a critical role in building and maintaining our detection and incident response capabilities. You'll have an automation mindset, constantly looking for ways to scale our security efforts and reduce manual work, leveraging frontier AI models. This role is perfect for someone passionate about security frameworks and best practices, driven by ownership, and eager to continuously improve our security posture. You’ll be instrumental in developing best-in-class security practices as we scale.
Requirements
- Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts.
- Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts.
- Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle). This includes data onboarding, parsing, rule creation, and dashboarding.
- Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta and general SaaS applications.
- Experience with cloud security monitoring, particularly in Google Cloud (GCP) with familiarity in GCP Security Command Center (SCC).
- Solid scripting skills (e.g., Python, Bash) for automating detection and response tasks, data parsing, and security tooling integration.
- Deep understanding of common attack techniques, threat intelligence, and the ability to translate them into actionable detections.
- Familiarity with security frameworks and best practices (e.g., MITRE ATT&CK, NIST Cybersecurity Framework).
- Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations.
Location
This role is remote, so it can be executed from anywhere in the APAC region with the ability to operate in [GMT+10] timezones. We’re particularly looking for candidates based in Singapore, Australia or the Philippines.
We are an equal opportunity employer and do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, veteran status, disability or other legally protected statuses.
What you'll do
- Build and maintain detection and incident response capabilities
- Scale security efforts and reduce manual work through automation and frontier AI models
- Develop best-in-class security practices as the company scales
- Triage security alerts
- Conduct security investigations
- Lead incident response efforts
- Develop, tune, and maintain security detection rules and alerts
- Handle Google SecOps Chronicle data onboarding, parsing, rule creation, and dashboarding
- Monitor security across JAMF MDM for macOS endpoints, Google Workspace, Okta, and general SaaS applications
- Monitor cloud security in Google Cloud and GCP Security Command Center
- Automate detection and response tasks, data parsing, and security tooling integration
- Translate common attack techniques and threat intelligence into actionable detections
- Build and maintain detection and incident response capabilities.
- Scale security efforts and reduce manual work through automation and frontier AI models.
- Develop best-in-class security practices as the company scales.
- Triage security alerts.
- Conduct security investigations.
- Lead incident response efforts.
- Develop, tune, and maintain security detection rules and alerts.
- Onboard data, parse data, create rules, and build dashboards in Google SecOps/Chronicle.
- Monitor security across macOS endpoints, Google Workspace, Okta, and SaaS applications.
- Monitor cloud security in Google Cloud.
- Automate detection and response tasks, data parsing, and security tooling integration.
- Translate common attack techniques and threat intelligence into actionable detections.
- Triage security alerts, conduct investigations, and lead response efforts.
- Develop, tune and maintain security detection rules and alerts.
- Onboard data, parse sources, create rules and dashboards in Chronicle.
- Automate detection and response tasks using scripting and AI models.
What they require
- Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts
- Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts
- Hands-on experience with SIEM infrastructure, specifically with Google SecOps Chronicle, including data onboarding, parsing, rule creation, and dashboarding
- Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta, and general SaaS applications
- Experience with cloud security monitoring, particularly in Google Cloud with familiarity in GCP Security Command Center
- Solid scripting skills, such as Python or Bash, for automating detection and response tasks, data parsing, and security tooling integration
- Deep understanding of common attack techniques and threat intelligence, with ability to translate them into actionable detections
- Familiarity with security frameworks and best practices, such as MITRE ATT&CK and NIST Cybersecurity Framework
- Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations
- Ability to operate in GMT+10 timezones
- Remote candidate based anywhere in the APAC region; particularly seeking candidates based in Singapore, Australia, or the Philippines
- Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts.
- Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts.
- Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle).
- Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta and general SaaS applications.
- Experience with cloud security monitoring, particularly in Google Cloud (GCP) with familiarity in GCP Security Command Center (SCC).
- Solid scripting skills for automating detection and response tasks, data parsing, and security tooling integration.
- Deep understanding of common attack techniques, threat intelligence, and the ability to translate them into actionable detections.
- Familiarity with security frameworks and best practices.
- Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations.
- This is an in-country role with a strong preference for a candidate in London.
- Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle) — data onboarding, parsing, rule creation, and dashboarding.
- Proficiency in security monitoring across JAMF MDM (macOS), Google Workspace, Okta and general SaaS applications; cloud security monitoring in GCP and familiarity with GCP Security Command Center (SCC).
- Solid scripting skills (Python, Bash); deep understanding of attack techniques, threat intelligence, and familiarity with MITRE ATT&CK and NIST Cybersecurity Framework.
Benefits
- Innovative culture with an opportunity to define the trajectory of AI
- Growth paths with opportunities to drive impact beyond immediate role and responsibilities
- Annual discretionary stipend for learning and development
- Annual discretionary stipend to meet up with colleagues each year
- Annual company offsite in a new location
- Monthly co-working stipend if not located near one of the main hubs
- Innovative culture and opportunity to define the trajectory of AI.
- Growth paths and opportunities to drive impact beyond immediate role and responsibilities.
- Annual discretionary professional development stipend.
- Annual discretionary stipend to meet up with colleagues each year.
- Annual company offsite in a new location.
- Monthly co-working stipend if not located near one of the main hubs.
- Annual discretionary stipend for learning & development.
- Annual discretionary stipend for social travel to meet colleagues.
- Annual company offsite.
- Monthly co-working stipend.
- Innovative culture and growth opportunities.
Powering the best enterprises, creators, and developers. From ElevenAgents for customer experience, ElevenCreative for content creation, to the leading AI voice generator.