高级检测工程师II
Senior Detection Engineer II
我们正在改变零售行业
在Instacart,我们邀请世界通过食物传递爱,因为我们相信每个人都能获得他们喜爱的食物,并有更多时间与所爱之人一起享受。当其他人看到的只是简单的杂货配送需求时,我们看到了令人兴奋的复杂性和无限的机会,以满足我们社区的各种需求。我们致力于提供客户依赖的必要服务,让他们获取杂货和日用品,同时为Instacart个人购物者提供安全且灵活的收入机会。
Instacart已成为数百万人的生命线,我们正在组建一支团队,帮助我们将购物车向前推进。如果你准备好做出一生中最好的工作,欢迎加入我们的行列。
Instacart是灵活优先的团队
没有一种方法适用于所有人来完成最佳工作。我们的员工可以自由选择在家中、办公室或最喜欢的咖啡店完成最佳工作,同时通过定期的线下活动保持联系并建立社区。了解更多关于我们灵活的工作地点方式。
简介
Instacart的检测工程团队位于我们安全组织的核心,构建和运营系统,以识别、呈现并响应北美最大的杂货技术平台之一上的威胁。我们负责整个检测生命周期,从遥测数据收集和信号设计到自动化响应,覆盖一个复杂的、原生云环境,包括终端设备、云、容器和SaaS。
作为高级检测工程师II,你将成为团队的技术核心:开发高精度的检测逻辑,寻找新的攻击者技术,并提升我们对覆盖率、质量和规模的思考标准。你将与工程、红队、事件响应、欺诈和信任与安全团队紧密合作,确保我们的检测反映真实的对手行为,而不仅仅是签名。
我们采用“检测即代码”的理念:我们构建的一切都会被版本化、测试并通过可重复的流水线部署。我们非常重视减少噪音,通过自动化和SOAR提高分析师效率,并随着威胁环境的变化持续进化我们的覆盖范围。
如果你热衷于解决困难的取证问题,喜欢将攻击者TTP转化为持久的检测逻辑,并希望帮助塑造一个不断壮大的安全职能的未来,那么这个职位适合你。
职位描述
- 开发、
查看英文原文
We're transforming the grocery industry
At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.
Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.
Instacart is a Flex First team
There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.
Overview
Instacarts Detection Engineering team sits at the core of our Security organization, building and operating the systems that identify, surface, and respond to threats across one of North America's largest grocery technology platforms. We own the full detection lifecycle, from telemetry collection and signal design to automated response, across a complex, cloud-native environment spanning endpoint, cloud, container, and SaaS.
As a Senior Detection Engineer II, you'll be a technical anchor on the team: developing high-fidelity detection logic, hunting for novel attacker techniques, and raising the bar for how we think about coverage, quality, and scale. You'll work closely with Engineering, Red Team, Incident Response, Fraud, and Trust & Safety to ensure our detections reflect real-world adversary behavior; not just signatures.
We operate with a detection-as-code mindset: everything we build is versioned, tested, and deployed through repeatable pipelines. We care deeply about reducing noise, improving analyst efficiency through automation and SOAR, and continuously evolving our coverage as the threat landscape shifts.
If you're energized by hard forensic problems, enjoy translating attacker TTPs into durable detection logic, and want to help shape the future of a growing security function, this role is for you.
About the Job
- Develop, tune, document, and maintain detection logic across multiple log sources including endpoint, cloud, container, and SaaS products.
- Assist in cyber forensic investigations across a variety of log sources
- Optimize log ingestion pipelines and telemetry collection to ensure high-quality, actionable security data while managing volume and cost
- Design and build SOAR playbooks and automation workflows to streamline detection triage, enrichment, and response actions
- Mentor junior security analysts and detection engineers on threat hunting methodologies, detection logic development, and investigation techniques
About You
Minimum Qualifications
- 6+ years of experience in a detection engineering, incident response, or offensive security role.
- Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
- Deep understanding of attacker TTPs across modern zero trust environments, including identity compromise, token theft, and abuse of trust boundaries
- Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
- Experience implementing detection-as-code workflows including version control, peer review processes, automated testing, and CI/CD deployment pipelines
- Basic proficiency with Python, Golang, or other programming languages
- Relevant certifications: GCFA, GCFE, GNFA, GREM, OSCP, GCIA, or similar
Preferred Qualifications
- Background in offensive security or red teaming
- Knowledge of machine learning for threat detection
#LI-Remote
Instacart provides highly market-competitive compensation and benefits in each location where our employees work. This role is remote and the base pay range for a successful candidate is dependent on their permanent work location. Please review our Flex First remote work policy here.
Offers may vary based on many factors, such as candidate experience and skills required for the role. Additionally, this role is eligible for a new hire equity grant as well as annual refresh grants. Please read more about our benefits offerings here.
For US based candidates, the base pay ranges for a successful candidate are listed below.
CA, NY, CT, NJ
$230,000—$242,500 USD
WA
$220,000—$232,000 USD
OR, DE, ME, MA, MD, NH, RI, VT, DC, PA, VA, CO, TX, IL, HI
$211,000—$222,500 USD
All other states
$192,000—$202,500 USD