Security Engineer, Detection & Response - Monitoring & Triage
Block | Square
Security Engineer, Detection & Response - Monitoring & Triage
Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams — People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more — provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.
The Role
The Detection and Response Team (DART) identifies, investigates, and responds to threats across Block's endpoints, cloud infrastructure, identity systems, SaaS platforms, vendor environments, and products. We are an engineering-led team: we build detections, automate investigations and response workflows, and prioritize our work around real attacker behavior.
DART operates from an engineering-first, automation-first mindset. Our bar is simple: the alerts a human sees are the alerts a human has to see. We build investigation workflows and triage systems that resolve routine work before it becomes toil. The human work in this role centers on the alerts and investigations that require judgment: ambiguous signals, novel attacker behavior, high-impact incidents, and messy cross-environment investigations. You will help build that model by developing active and automated triage capabilities.
DART's Monitoring & Triage function is both the front line and the front door. You will own daily security intake and will often be the first person partners across Block talk to when something does not look right. That can mean a high-confidence endpoint detection, a walk-in concern from Legal or Compliance, or a critical vulnerability. You are expected to ask the right questions, scope the issue quickly, make sound decisions, and either drive the work to resolution or route it cleanly.
This is an operational security engineering role. The alert queue is your laboratory. The other half of this role is turning missing signal into better systems: sharper detections, richer context, stronger close-vs-escalate logic, and tighter responder-facing workflows. You're the right person for this role if you want to catch things, and then build things that catch things for you.
You Will
- Own daily security intake across alert queues, Slack channels, and walk-in escalations from teams across Block, acting as the welcoming front door for security ops.
- Investigate and drive resolution of security events end-to-end, including endpoint detections, cloud/SaaS alerts, malware, supply chain issues, and hands-on-keyboard activity.
- Pivot across endpoint, identity, cloud, SaaS, network, DNS, and application telemetry to build timelines, test hypotheses, determine scope, and assess impact.
- Run nuanced investigations across non-uniform environments where device posture, identity models, and telemetry differ significantly.
- Consistently turn recurring investigative patterns into durable improvements: recommend new detections, automate triage workflows, refine automation logic, and clarify escalation paths.
- Identify structural gaps surfaced during investigations (weak controls, missing telemetry, outdated runbooks) and push for durable fixes rather than one-off workarounds.
- Define containment criteria, organize investigation threads, coordinate responders, drive status updates, and follow through on lessons learned.
- Lead cross-team efforts that improve investigation quality, response readiness, and operational maturity; and present interesting findings to the broader team and participate in tabletop exercises and post-incident reviews.
You Have
- 5+ years of experience in detection and response, incident response, security engineering, or equivalent depth of hands-on investigative experience.
- Strong investigative judgment across endpoint, identity, cloud, SaaS, network, and application security signals; AWS and Kubernetes security fundamentals, cloud-native logging, networking, and Linux systems.
- Experience leading incidents end-to-end, including scoping, containment, evidence collection, impact assessment, and stakeholder communication.
- Strong SQL and log-query/analysis skills, with the ability to work effectively across large, messy telemetry sets without waiting for a perfect dashboard.
- Current, practical working knowledge of attacker TTPs across macOS, Windows, and Linux with live response and forensics.
- An established AI development workflow.
- Experience building, tuning, or maintaining detections, investigation workflows, or internal security tooling.
- An engineering mindset: you start looking for the detection, workflow, control, or automation change that will eliminate a manual pattern.
- The ability to work independently across time zones, managing competing priorities with empathy, patience, and curiosity.
Nice-to-have qualities that stand out
- Experience with threat intelligence and threat hunting.
- Experience with malware analysis, forensic artifact collection, or reversing.
- Experience working with human-in-the-loop automation or AI-assisted investigation systems
We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is a proud equal opportunity employer. We work hard to evaluate all employees and job applicants consistently, without regard to identity or other legally protected class. We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible.
Block, Inc. (NYSE: XYZ) builds technology to increase access to the global economy. Each of our brands unlocks different aspects of the economy for more people. Square makes commerce and financial services accessible to sellers. Cash App is the easy way to spend, send, and store money. Afterpay is transforming the way customers manage their spending over time. TIDAL is a music platform that empowers artists to thrive as entrepreneurs. Bitkey is a simple self-custody wallet built for bitcoin. Proto is a suite of bitcoin mining products and services. Together, we're helping build a financial system that is open to everyone.
- ...Senior Security Engineer - Detect & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security... ...Marqeta's environment, proactively monitor for cyber threats, and serve as incident... ...alerts through timely analysis, triage, and appropriate response actions...SuggestedWork at officeRemote work
- ...Senior Security Engineer - Detection & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security... ...Marqeta's environment, proactively monitor for cyber threats, and serve as... ...security alerts through timely analysis, triage, and appropriate response actions...SuggestedWork at officeRemote work
- ...people-first approach and unwavering dedication to excellence. Job Responsibilities Detection as Code (DaC): Applying software engineering principles (version control, CI/CD, testing) to security rules. Threat Mapping: Mapping detection strategies against...SuggestedRemote work
$251k - $377k
...Spectacles ( . Snap Security teams protect the trust... ...looking for a Security Engineering Manager to lead our Detection & Response team here at Snap! What... ...scale our security monitoring efforts in a cost effective... ...alerting pipeline and triage potential incidents...SuggestedTemporary workLive inWork at officeLocal area- ...Staff Detection And Response Engineer Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's... ...Security's threat research into production detections, monitoring Cloud Infrastructure's GPU clusters for threats,...SuggestedFull timeRemote work
$157k - $185k
...are the rewards. The Security Operations (SecOps) team... ...security threats. The team monitors production systems, endpoints... ...SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and response readiness. The team's focus...Work at officeFlexible hoursShift work3 days per week$168k - $240k
...range of simple, reliable, and secure crypto products and... ...The Department: Threat Detection & Response In the emerging industry... ...security architecture and engineering to maintenance of cold storage... ...implement security controls, monitoring systems, and response mechanisms...Work at officeRemote workFlexible hours$136k - $184k
...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates... ...combines automated triage workflows, AI-powered... ...documenting patterns, proposing detection rules, providing... ...provides 24/7 threat monitoring, investigation, and...InternshipImmediate startFlexible hours- ...- SOC Analyst - L2 (Threat Detection & Response) Job Description: Job... ...support as needed for critical security events. We are seeking... ...goes beyond traditional monitoring-you will work alongside AI-... ...alerting systems to investigate, triage, and respond to security...Contract workRemote workShift work
- ...supports Walgreens' Threat Detection and Response function, focusing on... ...and responding to security incidents across the... ...end to end from triage through root cause analysis... ...: Monitors, identifies, investigates... ...to inform detection engineering and response operations...Work at officeRemote work
- ...and compassion. JOB DESCRIPTION Join our Information Security team as an Information Security Engineer - Detection & Response, where you'll play a critical role in safeguarding the firm by monitoring and responding to security threats, managing and enhancing advanced...Local area
- ...We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense... ...on role: you will write detections, tune them, run... ...lead incident response: triage, contain, eradicate, recover... .... Define how we monitor *internal* AI usage (sanctioned...Remote work
- ...Security Engineer – Threat Detection At Snowflake, we are powering the era of the agentic... ...threat detection and response to protect our customers... ...primitives in how we detect, triage, and respond to threats.... ...of its native logging, monitoring, and security services....Remote work
- ...together. The Role: Monarch is hiring a Senior Security Engineer, Detection and Response to join our Security team within Foundations - the first... ...to accelerate detection authoring, automate phishing triage, analyze logs, and build internal tooling. You'll also...Work at officeRemote workWork from homeWeekend work
$182k - $202k
...of the world's largest community of security researchers to continuously discover... ...accountability. Senior Security Engineer, Detection and Response Remote Location: Austin TX,... ...approach-focused on engineering, not just triage. As a Senior Security Engineer, you...ApprenticeshipLocal areaRemote workFlexible hoursShift work$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure... ...About the Role As a Security Engineer on Detection & Response, you'll help protect OpenAI's most sensitive... ...workflows that reduce toil (triage, enrichment, containment, evidence capture...$167.5k - $235k
...Senior Security Engineer (Detection & Response) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual environment... ...Lead security event & incident handling, including triage, investigation, containment guidance, and post‑incident...Casual workLocal area- ...Security Engineer Saronic Technologies is a leader in revolutionizing... ...team with strong detection engineering... ...playbooks that accelerate response, and work across a... ...coverage, not just alert triage. You'll own... ...tuning, performance monitoring, and retirement Build...Permanent employmentTemporary workWork at office
- ...Security Engineer Costco IT is responsible for the technical future of Costco Wholesale, the... ...mechanisms to detect security incidents in order... ...system audit and log file monitoring, security policies, and... ...accurate, and complete. Triages, prioritizes, investigates...Temporary workWorldwide
$320k - $405k
...Security Software Engineer, Detection & Response Platform San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC About Anthropic Anthropic... ...ground up Background in implementing security monitoring solutions (SIEM, log aggregation, EDR) Background...Work at officeVisa sponsorshipFlexible hoursShift work$189k - $330.75k
...addresses. About the role We are seeking a Staff Security Engineer to join our Detection and Response team (DART). This role is for a security engineer... ...real security operations problems - automated alert triage, investigation acceleration, detection generation,...Work at office3 days per week$66k - $106k
...Cloud Security Monitoring and Reporting Engineer (Journeyman) Job Locations US Requisition ID... ...Clearance Secret Responsibilities Peraton is seeking a Cloud Security... ...procedures, including initial triage of security events, documentation...Contract workRemote workShift work- ...Due to continuing growth, we are seeking a Security Engineer focused on securing and monitoring a Microsoft 365-centric environment. This role is responsible for detecting and responding to threats across Entra ID (Azure AD), Microsoft Defender, Intune-managed endpoints...Work at office
$156k - $316.8k
...Responsibilities The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our... ...trustworthy experience. As part of the Threat Detection and Response function, the Detection Engineering team focuses on improving our...Temporary workWork experience placementLocal area- ...Cybersecurity Analyst - Threat Detection and Response Location: 100% Remote Duration: 6+ months... ...you will lead the implementation of security solutions for our clients and support... ...activities and post-mortem Proactive monitoring of internal and external-facing...Contract workTemporary workH1bWork at officeImmediate startRemote work
- ...fill the role of a SIEM Administrator/Security Monitoring Engineer for our existing government client... ...Administrator / Security Monitoring Engineer is responsible for the deployment, configuration,... ...optimization. Develop and tune detection logic, correlation rules, and...Full timePart timeFor contractorsInterim roleLocal areaRemote work
- ...Associate Security Engineer, Cyber Monitoring Aiken, SC Type: Contract Category: Security Industry... ...alert monitoring, basic incident triage, email security review, log... ...Pay Rate: $23-$25 per hour W2. Responsibilities: Monitor network security alerts...Hourly payContract workLocal areaRemote workEarly shift
$200k - $240k
...global presence. The Liftoff Security team protects Liftoff's... ...it, and partner with engineering teams as they ship new products... ...HERE'S WHY: * Build out our detection and response function. Liftoff has a... ...modernization investment. * Triage incoming security alerts and...Full timeRemote work- ...qualified candidates for an Associate Computer Security Engineer- Cyber Monitoring opportunity for our customer in Aiken,... ...NIST Core Cyber. Framework: Identify, Detect, Respond and Recover. Safety is a primary responsibility in each job performed. Obtain safety...Remote work
$75k - $95k
...Associate Computer Security Engineer - Cyber Monitoring Location US-SC-Aiken ID... ...protection of critical infrastructure. Responsibilities Duties: Under regular supervision... ...Cyber. Framework: Identify, Detect, Respond and Recover. Safety is...Full timeContract workTemporary workWork experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Detection & Response - Monitoring & Triage. Be the first to apply!
- information system security engineer United States
- staff security engineer United States
- senior application security engineer United States
- sr information security engineer United States
- security engineering manager United States
- electronic security engineer United States
- java security engineer United States
- security operations engineer United States
- junior network security engineer United States
- cloud security engineer United States

