The Senior Detection Engineer will architect scalable detection systems, develop automation for security response, and collaborate cross-functionally to enhance security measures.
As our next Senior Detection Engineer, you won’t just be monitoring dashboards—you’ll be at the forefront of building our security operations as code. You will lead the charge in architecting scalable detection systems and developing the automation that defines how we protect our infrastructure. This is a technical, hands-on role combining security engineering, automation development, and strategic incident response where your technical decisions directly shape how we detect, investigate, and respond to threats at scale. You won’t just be managing alerts; you’ll be shaping the very trajectory of our security posture in a lean, engineering-first environment.
On a typical day, you might:
- Design and deploy sophisticated detection logic across our entire technology stack using detection-as-code principles like YARA-L, Sigma, and KQL.
- Build automated response workflows that independently enrich, triage, and remediate security alerts, effectively eliminating manual toil through advanced SOAR principles.
- Investigate complex security signals—such as novel attack patterns or phishing campaigns—that require deep human judgment and strategic intuition.
- Collaborate cross-functionally with DevOps and Security Engineering teams to adapt detection logic to infrastructure changes before security blind spots can emerge.
- Leverage AI and LLMs as force multipliers to accelerate threat hunting, generate new detection hypotheses, and automate repetitive investigative tasks.
- Lead post-incident reviews with engineering partners, transforming security findings into preventative architectural changes that harden our long-term defense.
- Prototype and test emerging detection capabilities and data sources, ensuring we stay ahead of the threat landscape while participating in an on-call rotation to defend our most critical systems.
What is needed:
- 5+ years of hands-on experience in detection engineering, incident response, or security operations within high-growth technology environments.
- Advanced programming proficiency in Python, with a proven ability to build production-quality security automations and custom integrations from scratch.
- Deep expertise in Cloud Security (AWS), including a comprehensive understanding of IAM, VPC, CloudTrail, and Lambda attack vectors.
- Mastery of detection logic in at least two major languages, such as YARA-L, Sigma, KQL, or SPL.
- A track record of building SOAR workflows or equivalent automation platforms that measurably reduce operational overhead at scale.
- Exceptional communication skills, with the ability to distill complex security risks into actionable insights and influence technical decisions across the organization.
- Experience using AI/LLMs as a strategic tool for threat analysis, investigation automation, and increasing the velocity of security work.
- A self-directed, engineering-first mindset, ideally with a background in SRE, DevOps, or platform engineering and a history of contributing to open-source security projects.
About ActiveCampaign:
ActiveCampaign is the autonomous marketing platform for people at the heart of the action. It empowers teams to automate their campaigns with AI agents that imagine, activate, and validate–freeing them from step-by-step workflows and unlocking limitless ways to orchestrate their marketing.
With AI, goal-based automation, and 1,000+ app integrations, agencies, marketers, and owners can build cross-channel campaigns in minutes–fine-tuned with billions of data points to drive real results for their unique business.
ActiveCampaign is the trusted choice to help businesses unlock a new world of boundless opportunities–where ideas become impact and potential turns into real results.
As a global multicultural company, we are proud of our inclusive culture which embraces diverse voices, backgrounds, and perspectives. We don’t just celebrate our differences, we believe our diversity is what empowers our innovation and success. You can find out more about our DEI initiatives here.
Perks and benefits:
At ActiveCampaign, we prioritize employees’ well-being and professional growth by cultivating a culture centered on collaboration and innovation. When you join our team, you’ll not only have the opportunity to make a significant impact, but also enjoy a range of benefits tailored to support your personal and career development.
Here are some of the benefits we offer:
-Comprehensive Health & Wellness: Top-tier benefits package that includes a fully-covered High Deductible Health Plan (HDHP), complimentary access to telehealth services, and a free subscription to Calm.
-Growth & Development: Access to LinkedIn Learning, professional development programs, and career growth opportunities in a fast-growing organization.
-Generous Paid Time Off: Recharge and take the time you need to maintain work-life balance with open PTO.
-Total Rewards: Generous 401(k) matching with immediate vesting, quarterly perks with commuter and lunch benefits for hub based employees or a stipend for remote workers, and a four-week paid sabbatical with bonus after five years.
-Collaborative Culture: Work alongside brilliant, passionate colleagues in an environment that values innovation, teamwork, and mutual support.
ActiveCampaign is an equal opportunity employer. We recruit, hire, pay, grow and promote no matter of gender, race, color, sexual orientation, religion, age, protected veteran status, physical and mental abilities, or any other identities protected by law.
Our Employee Resource Groups (ERGs) strive to foster a diverse inclusive environment by supporting each other, building a strong sense of belonging, and creating opportunities for mentorship and professional growth for their members.
Similar Jobs
Cloud • Information Technology
The Senior SIEM Detection Engineer will design, implement, and maintain detection content for cloud-based SIEM solutions, enhance detection capabilities, and collaborate with teams to improve security monitoring and incident response.
Top Skills:
Elastic AgentElastic SecurityElasticsearchFilebeatKibanaLogstashPythonSIEM
Mobile • Security • Software • Cybersecurity
Design and maintain datasets, build and evaluate domain-specific ML and vision-language models for real-time privileged access threat detection; deploy and optimize Python/Docker inference services integrated with WebSocket/WebRTC and protocol-level interfaces; monitor and document production models.
Top Skills:
AWSAws BedrockAzureClaudeDatabase ProtocolsDockerGCPGeminiGitGptGraph Data StructuresHugging FaceLlm FrameworksPythonQwenRdpSshVision-Language ModelsVncWebrtcWebsocket
Healthtech • Database
The Senior Detection Engineer will manage SIEM platforms like Splunk, support compliance frameworks, and integrate security platforms across environments.
Top Skills:
AWSCrowdstrike FalconEdrSIEMSplunk Enterprise Security
What you need to know about the Los Angeles Tech Scene
Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

.png)

