Skip to main content
HubSpot

Principal Software Engineer, Security, Detection & Response

RemoteUnited States only
Published
Role
Security
Experience
Principal
Company size
Enterprise
$266.2k–$425.9k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Principal security-focused software engineer with 10–15 years in software development and information security. Needs detection engineering, threat intelligence, incident response, SIEM/security logging, EDR/SASE, CrowdStrike, and frameworks like NIST/SANS. Remote USA only.

Core skills

SIEMCrowdStrike FalconDetection Engineering

Required skills

SplunkEDRSASENIST 800-61SANSSTIXTAXII

What you'll do

  • Build detection foundations and response frameworks to improve security posture.
  • Drive development of automated detection systems and prioritize mitigations based on threats and coverage gaps.
  • Partner with engineering teams to supply data for purple team exercises and implement risk mitigation solutions.
  • Guide architecture for corporate security logging infrastructure and SIEM.
  • Contribute code to security automations and review designs for detection reliability.
  • Provide technical mentorship to engineers.
  • Act as a key contact for threat intelligence and incident response expertise.
  • Support incident response investigations and analyze bad actor behavior.
  • Work with product managers and legal/privacy partners to embed NIST and SANS incident response standards.
  • Produce actionable intelligence by filtering and correlating IOC data using platforms like Splunk and CrowdStrike.
  • Evaluate customer impact from threats and maintain industry contacts for intelligence sharing.

What they require

  • 10-15 years of experience in software development and information security, focused on detection engineering, threat intelligence, and incident response.
  • Proven experience designing and implementing automated detection systems and managing large-scale security logging infrastructure.
  • Expert knowledge of endpoint and network detection.
  • Hands-on experience with CrowdStrike Falcon for investigation and response.
  • Deep understanding of incident response methodologies and frameworks such as NIST 800-61 and SANS.
  • Ability to lead high-severity CritSits.
  • Experience correlating identity, cloud, and network telemetry to detect post-entry behavior and contain threats quickly.
  • Experience managing and ingesting Indicators of Compromise and mapping actor techniques to STIX/TAXII.
  • Excellent communication skills for technical and non-technical audiences.
  • Relevant industry certifications such as GCIH, GCFA, CISSP, or vendor-specific EDR certifications.

Benefits

  • Base salary, on-target commission for eligible roles, and annual bonus targets for eligible roles.
  • Eligibility for restricted stock units for some roles.
  • Overtime pay eligibility for some roles.
  • Benefits and perks package.
  • Flexible remote or office work options.
  • Disability accommodations available.

HubSpot is an AI-powered customer platform with software, integrations, and resources for customers to connect marketing, sales, and service. Its connected platform enables businesses to grow faster by focusing on customers.

🇬🇧 United KingdomCRMEnterprisehubspot.com

What people say about this company

3.9/ 5

  • Employees appreciate the company culture and values.
  • Many enjoy the flexibility and work-life balance offered.
  • Some employees mention high workloads and pressure.

Details

Apply routeDom
$266.2k–$425.9k/yr