Blumira Logo

Blumira

Incident Detection Engineer

Posted 6 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
110K-130K
Mid level
Remote
Hiring Remotely in United States
110K-130K
Mid level
As an Incident Detection Engineer, you'll design new detections, optimize existing ones, analyze log data, and maintain testing environments, collaborating with teams to enhance security effectiveness.
The summary above was generated by AI
About Blumira and Our Culture

At Blumira, our mission is to make detection and response fast, simple, and accessible - especially for small and medium-sized businesses that have too often been overlooked, priced out, or underserved by existing security solutions. By protecting them, we’re also protecting their customers and helping make the internet a safer place for everyone.

We’ve built a powerful platform, assembled a strong team, and we’re focused on delivering practical, effective security that meets the real-world needs of our customers. To keep moving forward, we’re looking for curious, driven individuals—like you!

Join a collaborative, inclusive team that values your unique perspective and supports your growth as you help strengthen our detection capabilities. You’ll learn and grow alongside experienced SaaS security leaders while making a meaningful impact as we continue to evolve and scale Blumira’s Incident Detection Engineering team.

About the Opportunity

Are you passionate about applying your hands-on cybersecurity experience to uncover meaningful insights and identify potential risks in operational data? Do you enjoy building environments for testing, research, and exploration—where experimentation is encouraged and learning is part of the process? If you’re eager to approach security challenges with curiosity and creativity, you’ll feel right at home on Blumira’s Incident Detection Engineering team.

This role gives you the opportunity to go deep on security challenges while applying a broad range of technical skills to solve diverse problems. Blumira ingests data from a wide variety of sources—from traditional firewalls to modern cloud APIs—and your ability to provide context and clarity across this range will help us deliver real value to our customers.

Success in this role requires a high level of attention to detail—whether you're analyzing log data, simulating threats, or fine-tuning detection logic, precision is key to building reliable and effective detections. You’ll be responsible for building and maintaining research and testing environments, monitoring and improving the performance of existing detections, and creating new ones based on evolving attacker behaviors. Staying on top of the latest adversary tactics, techniques, and procedures (TTPs) is a core part of the role and critical to fueling our detection pipeline.

Key Responsibilities 
  • Design and implement new detections and remediation logic based on evolving attacker tactics, techniques, and procedures (TTPs).
  • Monitor, evaluate, and optimize the performance and accuracy of existing detections.
  • Collaborate with teammates to design, build, automate, and manage detection engineering tools and testing environments.
  • Provide configuration recommendations to improve the visibility and quality of ingested logs.
  • Develop and maintain standards for log ingestion and device/service configurations to ensure consistent and reliable data intake, in partnership with engineering teams.
  • Support Security Operations, Technical Account Management, and Sales Engineering teams by responding to inquiries related to configuration and setup.
  • Champion best practices that benefit both system administrators and non-security use cases, strengthening our role as practitioners for the broader IT community.
Required Key Skills and Qualifications
  • Strong problem-solving skills with a technical foundation in operating systems (Linux, Windows, macOS), networking, cloud environments (AWS, GCP, Azure), or data analysis.
  • Clear and effective communicator, capable of collaborating across teams and translating technical concepts for diverse audiences.
  • Familiarity with query languages such as SQL, KQL, SPL, or similar tools used for data exploration and analysis.
  • Proficient in working with structured data formats like JSON and YAML, including reading, interpreting, and modifying configuration or detection rule files.
  • Hands-on experience with Python, Bash scripting, or a similar scripting language. Familiarity with APIs, and a solid understanding of the MITRE ATT&CK framework.
  • Prior experience in incident response, threat hunting, digital forensics, or detection engineering is a strong plus.
Bonus
  • Start-up experience
  • SIEM/EDR/Detection & Response platform experience
Perks and Benefits: 
  • Competitive compensation and stock equity plan
  • Unlimited PTO
  • A flexible work environment that supports working from home
  • Comprehensive benefits package that includes medical, dental, vision, and life insurance, as well as 401(k)

Salary: $110,000 - $130,000


Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

Please note that this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time, with or without notice.

This position requires prolonged periods of sitting at a desk and working on a computer.

This position may require occasional travel. The frequency and duration of travel will vary depending on business needs.

Blumira is an inclusive employer. We are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition or any protected category prohibited by local, state or federal laws.

Top Skills

AWS
Azure
Bash
GCP
JSON
Kql
Linux
macOS
Mitre Att&Ck
Python
Spl
SQL
Windows
Yaml

Similar Jobs

2 Hours Ago
Remote
USA
218K-257K Annually
Senior level
218K-257K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Identify security gaps, conduct assessments, collaborate with engineering on smart contracts, lead automation efforts, and publish findings on vulnerabilities in blockchain systems.
Top Skills: BlockchainCryptographyDistributed Ledger TechnologyEipsEvm ChainsRestakingSmart ContractsZero-Knowledge Proofs
2 Hours Ago
Remote
USA
152K-179K Annually
Mid level
152K-179K Annually
Mid level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
As a Security Engineer in Vulnerability Response at Coinbase, you'll manage vulnerabilities, automate processes, and collaborate with teams to enhance security measures.
Top Skills: AirflowAWSDockerGCPGitPythonSQL
2 Hours Ago
Remote
Hybrid
USA
65K-187K Annually
Senior level
65K-187K Annually
Senior level
Machine Learning • Payments • Security • Software • Financial Services
As a Security Engineer at PNC, you will manage cryptographic key operations, automate certificate management, and troubleshoot TLS issues while ensuring data security and compliance.
Top Skills: AWSAzureMicrosoft 365Power AutomatePower BIPowershellPython

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account