
Senior Security Engineer (Detection Engineer)
CoreWeave
Visa & sponsorship
- US persons only (ITAR / export control): a legal requirement, not employer policy.
Job description
-
Design cutting-edge detection strategies at scales most security engineers only dream about
-
Collaborate with talented peers in an innovative environment focused on excellence
-
Enjoy the autonomy and encouragement to innovate and influence CoreWeave’s security landscape directly
-
Developing and implementing advanced threat detection capabilities to proactively identify and mitigate cyber threats
-
Crafting precise and efficient custom detection logic tailored to evolving threat landscapes
-
Leading and/or participating in real-time security incident response, threat containment, and remediation
-
Conducting proactive threat-hunting exercises to uncover hidden vulnerabilities and anticipate threats
-
Collaborating closely with cross-functional teams to enhance security visibility and detection effectiveness
-
Continuously researching and staying informed about emerging threats, attack vectors, and detection methodologies
-
Participating in strategic security initiatives, contributing your expertise to security architecture and controls
-
Engaging in security assessments to uphold our high standards for security and compliance
-
Occasionally, drawing the owl - figuring out innovative solutions while navigating ambiguous situations
-
Please note that this role is not a typical 9-5 job. There may be instances where real-time incident response requires active participation outside business hours
-
On-call hours (including weekends and holidays) and all-hands-on-deck participation during active incidents are expected. If crafting sophisticated detection strategies and staying ahead of threats in a dynamic, innovative environment excites you, we’d love to connect!- Proven ability to deliver impactful projects spanning multiple technical domains and teams
-
Competency in writing detections in multiple languages (Python, Bash, Go, JavaScript, etc.)
-
Strong foundational knowledge of Linux or macOS internals and their relevant event sources (eBPF, Endpoint Security Framework)
-
Experience collaborating closely with Purple and Red Teams, leveraging findings to enhance detection capabilities
-
Proficiency in at least one query language (e.g., SQL, Splunk Query Language, HiveQL)
-
Familiarity with Kubernetes fundamentals and enthusiasm to deepen your expertise
-
Extensive experience crafting custom alert logic within industry-standard tooling, like KQL, SQL, etc
-
Practical experience applying and contributing to the Incident Response Lifecycle methodology
-
Solid understanding of modern TTP frameworks such as MITRE ATT&CK and Cyber Kill Chain
-
Deep understanding of Kubernetes-specific detection and security challenges
-
Contributions to the open-source security community or experience developing detection tooling
-
Experience leveraging advanced analytics or machine learning techniques in detection engineering
-
This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency