Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer, Detection & Response - Monitoring & Triage

Block | Square

Security Engineer, Detection & Response - Monitoring & Triage

Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams — People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more — provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.

The Role

The Detection and Response Team (DART) identifies, investigates, and responds to threats across Block's endpoints, cloud infrastructure, identity systems, SaaS platforms, vendor environments, and products. We are an engineering-led team: we build detections, automate investigations and response workflows, and prioritize our work around real attacker behavior.

DART operates from an engineering-first, automation-first mindset. Our bar is simple: the alerts a human sees are the alerts a human has to see. We build investigation workflows and triage systems that resolve routine work before it becomes toil. The human work in this role centers on the alerts and investigations that require judgment: ambiguous signals, novel attacker behavior, high-impact incidents, and messy cross-environment investigations. You will help build that model by developing active and automated triage capabilities.

DART's Monitoring & Triage function is both the front line and the front door. You will own daily security intake and will often be the first person partners across Block talk to when something does not look right. That can mean a high-confidence endpoint detection, a walk-in concern from Legal or Compliance, or a critical vulnerability. You are expected to ask the right questions, scope the issue quickly, make sound decisions, and either drive the work to resolution or route it cleanly.

This is an operational security engineering role. The alert queue is your laboratory. The other half of this role is turning missing signal into better systems: sharper detections, richer context, stronger close-vs-escalate logic, and tighter responder-facing workflows. You're the right person for this role if you want to catch things, and then build things that catch things for you.

You Will
  • Own daily security intake across alert queues, Slack channels, and walk-in escalations from teams across Block, acting as the welcoming front door for security ops.
  • Investigate and drive resolution of security events end-to-end, including endpoint detections, cloud/SaaS alerts, malware, supply chain issues, and hands-on-keyboard activity.
  • Pivot across endpoint, identity, cloud, SaaS, network, DNS, and application telemetry to build timelines, test hypotheses, determine scope, and assess impact.
  • Run nuanced investigations across non-uniform environments where device posture, identity models, and telemetry differ significantly.
  • Consistently turn recurring investigative patterns into durable improvements: recommend new detections, automate triage workflows, refine automation logic, and clarify escalation paths.
  • Identify structural gaps surfaced during investigations (weak controls, missing telemetry, outdated runbooks) and push for durable fixes rather than one-off workarounds.
  • Define containment criteria, organize investigation threads, coordinate responders, drive status updates, and follow through on lessons learned.
  • Lead cross-team efforts that improve investigation quality, response readiness, and operational maturity; and present interesting findings to the broader team and participate in tabletop exercises and post-incident reviews.
You Have
  • 5+ years of experience in detection and response, incident response, security engineering, or equivalent depth of hands-on investigative experience.
  • Strong investigative judgment across endpoint, identity, cloud, SaaS, network, and application security signals; AWS and Kubernetes security fundamentals, cloud-native logging, networking, and Linux systems.
  • Experience leading incidents end-to-end, including scoping, containment, evidence collection, impact assessment, and stakeholder communication.
  • Strong SQL and log-query/analysis skills, with the ability to work effectively across large, messy telemetry sets without waiting for a perfect dashboard.
  • Current, practical working knowledge of attacker TTPs across macOS, Windows, and Linux with live response and forensics.
  • An established AI development workflow.
  • Experience building, tuning, or maintaining detections, investigation workflows, or internal security tooling.
  • An engineering mindset: you start looking for the detection, workflow, control, or automation change that will eliminate a manual pattern.
  • The ability to work independently across time zones, managing competing priorities with empathy, patience, and curiosity.
Nice-to-have qualities that stand out
  • Experience with threat intelligence and threat hunting.
  • Experience with malware analysis, forensic artifact collection, or reversing.
  • Experience working with human-in-the-loop automation or AI-assisted investigation systems

We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is a proud equal opportunity employer. We work hard to evaluate all employees and job applicants consistently, without regard to identity or other legally protected class. We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible.

Block, Inc. (NYSE: XYZ) builds technology to increase access to the global economy. Each of our brands unlocks different aspects of the economy for more people. Square makes commerce and financial services accessible to sellers. Cash App is the easy way to spend, send, and store money. Afterpay is transforming the way customers manage their spending over time. TIDAL is a music platform that empowers artists to thrive as entrepreneurs. Bitkey is a simple self-custody wallet built for bitcoin. Proto is a suite of bitcoin mining products and services. Together, we're helping build a financial system that is open to everyone.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer, Detection & Response - Monitoring & Triage in United States vacancy
  •  ...Senior Security Engineer - Detect & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security...  ...Marqeta's environment, proactively monitor for cyber threats, and serve as incident...  ...alerts through timely analysis, triage, and appropriate response actions... 
    Suggested
    Work at office
    Remote work

    Marqueta Referrals

    United States
    11 hours ago
  •  ...Senior Security Engineer - Detection & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security...  ...Marqeta's environment, proactively monitor for cyber threats, and serve as...  ...security alerts through timely analysis, triage, and appropriate response actions... 
    Suggested
    Work at office
    Remote work

    Marqeta

    United States
    14 hours ago
  •  ...people-first approach and unwavering dedication to excellence. Job Responsibilities Detection as Code (DaC): Applying software engineering principles (version control, CI/CD, testing) to security rules. Threat Mapping: Mapping detection strategies against... 
    Suggested
    Remote work

    True Zero Technologies, LLC

    United States
    14 hours ago
  • $251k - $377k

     ...Spectacles ( . Snap Security teams protect the trust...  ...looking for a Security Engineering Manager to lead our Detection & Response team here at Snap! What...  ...scale our security monitoring efforts in a cost effective...  ...alerting pipeline and triage potential incidents... 
    Suggested
    Temporary work
    Live in
    Work at office
    Local area

    Snap

    Palo Alto, CA
    3 days ago
  •  ...Staff Detection And Response Engineer Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's...  ...Security's threat research into production detections, monitoring Cloud Infrastructure's GPU clusters for threats,... 
    Suggested
    Full time
    Remote work

    Writer Corporation

    United States
    12 hours ago
  • $157k - $185k

     ...are the rewards. The Security Operations (SecOps) team...  ...security threats. The team monitors production systems, endpoints...  ...SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and response readiness. The team's focus... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    4 days ago
  • $168k - $240k

     ...range of simple, reliable, and secure crypto products and...  ...The Department: Threat Detection & Response In the emerging industry...  ...security architecture and engineering to maintenance of cold storage...  ...implement security controls, monitoring systems, and response mechanisms... 
    Work at office
    Remote work
    Flexible hours

    Gemini

    New York, NY
    3 days ago
  • $136k - $184k

     ...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates...  ...combines automated triage workflows, AI-powered...  ...documenting patterns, proposing detection rules, providing...  ...provides 24/7 threat monitoring, investigation, and... 
    Internship
    Immediate start
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  •  ...- SOC Analyst - L2 (Threat Detection & Response) Job Description: Job...  ...support as needed for critical security events. We are seeking...  ...goes beyond traditional monitoring-you will work alongside AI-...  ...alerting systems to investigate, triage, and respond to security... 
    Contract work
    Remote work
    Shift work

    Maxonic

    United States
    4 days ago
  •  ...supports Walgreens' Threat Detection and Response function, focusing on...  ...and responding to security incidents across the...  ...end to end from triage through root cause analysis...  ...: Monitors, identifies, investigates...  ...to inform detection engineering and response operations... 
    Work at office
    Remote work

    Walgreens Boots Alliance

    Deerfield, IL
    4 days ago
  •  ...and compassion. JOB DESCRIPTION Join our Information Security team as an Information Security Engineer - Detection & Response, where you'll play a critical role in safeguarding the firm by monitoring and responding to security threats, managing and enhancing advanced... 
    Local area

    Alston & Bird

    Atlanta, GA
    3 days ago
  •  ...We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense...  ...on role: you will write detections, tune them, run...  ...lead incident response: triage, contain, eradicate, recover...  .... Define how we monitor *internal* AI usage (sanctioned... 
    Remote work

    Ondo Finance, Inc.

    United States
    4 days ago
  •  ...Security Engineer – Threat Detection At Snowflake, we are powering the era of the agentic...  ...threat detection and response to protect our customers...  ...primitives in how we detect, triage, and respond to threats....  ...of its native logging, monitoring, and security services.... 
    Remote work

    Snowflake Computing

    United States
    12 hours ago
  •  ...together. The Role: Monarch is hiring a Senior Security Engineer, Detection and Response to join our Security team within Foundations - the first...  ...to accelerate detection authoring, automate phishing triage, analyze logs, and build internal tooling. You'll also... 
    Work at office
    Remote work
    Work from home
    Weekend work

    Monarch Money

    United States
    13 hours ago
  • $182k - $202k

     ...of the world's largest community of security researchers to continuously discover...  ...accountability. Senior Security Engineer, Detection and Response Remote Location: Austin TX,...  ...approach-focused on engineering, not just triage. As a Senior Security Engineer, you... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    Austin, TX
    14 hours ago
  • $234.4k - $385k

     ...About the Team Security is at the foundation of OpenAI's mission to ensure...  ...About the Role As a Security Engineer on Detection & Response, you'll help protect OpenAI's most sensitive...  ...workflows that reduce toil (triage, enrichment, containment, evidence capture... 

    OpenAI

    New York, NY
    3 days ago
  • $167.5k - $235k

     ...Senior Security Engineer (Detection & Response) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual environment...  ...Lead security event & incident handling, including triage, investigation, containment guidance, and post‑incident... 
    Casual work
    Local area

    Justworks

    New York, NY
    1 day ago
  •  ...Security Engineer Saronic Technologies is a leader in revolutionizing...  ...team with strong detection engineering...  ...playbooks that accelerate response, and work across a...  ...coverage, not just alert triage. You'll own...  ...tuning, performance monitoring, and retirement Build... 
    Permanent employment
    Temporary work
    Work at office

    Saronic

    Austin, TX
    16 days ago
  •  ...Security Engineer Costco IT is responsible for the technical future of Costco Wholesale, the...  ...mechanisms to detect security incidents in order...  ...system audit and log file monitoring, security policies, and...  ...accurate, and complete. Triages, prioritizes, investigates... 
    Temporary work
    Worldwide

    Costco

    Issaquah, WA
    1 day ago
  • $320k - $405k

     ...Security Software Engineer, Detection & Response Platform San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC About Anthropic Anthropic...  ...ground up Background in implementing security monitoring solutions (SIEM, log aggregation, EDR) Background... 
    Work at office
    Visa sponsorship
    Flexible hours
    Shift work

    Anthropic

    New York, NY
    1 day ago
  • $189k - $330.75k

     ...addresses. About the role We are seeking a Staff Security Engineer to join our Detection and Response team (DART). This role is for a security engineer...  ...real security operations problems - automated alert triage, investigation acceleration, detection generation,... 
    Work at office
    3 days per week

    Rippling

    Austin, TX
    7 hours ago
  • $66k - $106k

     ...Cloud Security Monitoring and Reporting Engineer (Journeyman) Job Locations US Requisition ID...  ...Clearance Secret Responsibilities Peraton is seeking a Cloud Security...  ...procedures, including initial triage of security events, documentation... 
    Contract work
    Remote work
    Shift work

    Peraton

    Reston, VA
    2 days ago
  •  ...Due to continuing growth, we are seeking a Security Engineer focused on securing and monitoring a Microsoft 365-centric environment. This role is responsible for detecting and responding to threats across Entra ID (Azure AD), Microsoft Defender, Intune-managed endpoints... 
    Work at office

    Platform Accounting

    Salt Lake City, UT
    3 days ago
  • $156k - $316.8k

     ...Responsibilities The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our...  ...trustworthy experience. As part of the Threat Detection and Response function, the Detection Engineering team focuses on improving our... 
    Temporary work
    Work experience placement
    Local area

    Tik Tok

    San Jose, CA
    3 days ago
  •  ...Cybersecurity Analyst - Threat Detection and Response Location: 100% Remote Duration: 6+ months...  ...you will lead the implementation of security solutions for our clients and support...  ...activities and post-mortem Proactive monitoring of internal and external-facing... 
    Contract work
    Temporary work
    H1b
    Work at office
    Immediate start
    Remote work

    ShiftCode Analytics

    United States
    14 hours ago
  •  ...fill the role of a SIEM Administrator/Security Monitoring Engineer for our existing government client...  ...Administrator / Security Monitoring Engineer is responsible for the deployment, configuration,...  ...optimization. Develop and tune detection logic, correlation rules, and... 
    Full time
    Part time
    For contractors
    Interim role
    Local area
    Remote work

    NANA Regional Corp

    Alexandria, VA
    4 days ago
  •  ...Associate Security Engineer, Cyber Monitoring Aiken, SC Type: Contract Category: Security Industry...  ...alert monitoring, basic incident triage, email security review, log...  ...Pay Rate: $23-$25 per hour W2. Responsibilities: Monitor network security alerts... 
    Hourly pay
    Contract work
    Local area
    Remote work
    Early shift

    Eliassen Group

    Aiken, SC
    5 days ago
  • $200k - $240k

     ...global presence. The Liftoff Security team protects Liftoff's...  ...it, and partner with engineering teams as they ship new products...  ...HERE'S WHY: * Build out our detection and response function. Liftoff has a...  ...modernization investment. * Triage incoming security alerts and... 
    Full time
    Remote work

    Liftoff

    California
    2 days ago
  •  ...qualified candidates for an Associate Computer Security Engineer- Cyber Monitoring opportunity for our customer in Aiken,...  ...NIST Core Cyber. Framework: Identify, Detect, Respond and Recover.  Safety is a primary responsibility in each job performed. Obtain safety... 
    Remote work

    UDR Consulting

    Aiken, SC
    1 day ago
  • $75k - $95k

     ...Associate Computer Security Engineer - Cyber Monitoring Location US-SC-Aiken ID...  ...protection of critical infrastructure. Responsibilities Duties: Under regular supervision...  ...Cyber. Framework: Identify, Detect, Respond and Recover. Safety is... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work

    Omega Technical

    Aiken, SC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer, Detection & Response - Monitoring & Triage. Be the first to apply!