Detection Engineering Lead

Dropzone AI
Dropzone AI

United States · Remote

USD 200k-250k / year

Posted on Jul 21, 2026

About Dropzone AI

Dropzone’s mission is to scale cybersecurity beyond human limits, and augment every single human security engineer/analyst with an army of AI security specialists. Humans alone cannot sufficiently protect our digital future, and AI augmentation is the only way for defenders to reclaim the high ground. We are an award winning company disrupting the $200B+ cybersecurity market.

Powered by Gen AI advancements, our technology offloads repetitive day-to-day work and frees human analysts to focus on real threats and higher-value projects. We are venture-backed, and our team has a rare blend of deep experience across cybersecurity, AI/ML, and SaaS product development. Join us if you want to be on the ground floor of using Gen AI to transform cyber defense. Learn more at www.dropzone.ai.

About the role

We're looking for a highly experienced Senior / Principal Detection Engineer to help shape the future of AI-driven security operations. This is a senior-to-principal level role for an individual who combines deep detection engineering expertise with a passion for innovation, customer impact, and advancing the state of security operations.

As the Detection Engineering Lead, you will serve as one of Dropzone AI's foremost experts in adversary tradecraft, threat detection, detection efficacy evaluation, and SIEM content. You will work closely with product management and engineering teams to ensure our AI detection engineer can draft new detection contents and improve existing detection rules as well as the best detection engineer on the planet.

This role is part of the R&D team and you will focus on building the best software that replicates your expert intuitions and techniques. This is not a service or consulting role and you will not be performing hands-on detection engineering service to our customers.

What you'll do

Detection Engineering Leadership

  • Reimagine how having unlimited detection engineering capacity could change Detection and Response teams and how future security practitioners interact with an AI detection engineer
  • Prototype, validate, and continuously improve an AI agent that programmatically generates detection content across diverse security environments.
  • Experiment autonomous agentic loops between detection engineering and other D&R functions such as threat intelligence and threat hunting

Product Development

  • Partner with engineering teams to encode expert detection knowledge into our product.
  • Design scoring rubrics on AI generated detection content for SIEM, EDR, NDR, cloud, identity, and SaaS security platforms.
  • Provide guidance on detection methodologies used by mature SOCs.
  • Establish best practices for detection quality, tuning, testing, and lifecycle management.
  • Influence product roadmap decisions based on customer and operational needs.

Threat Research & Innovation

  • Stay current on emerging threats, attacker techniques, and defensive strategies.
  • Conduct original research into detection opportunities and gaps.
  • Develop novel approaches for AI-assisted threat detection.

Requirements

  • 5+ years of experience in detection engineering.
  • Deep expertise with two or more major SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, Chronicle, Sumo Logic, etc.).
  • Strong understanding of endpoint, cloud, identity, network, and SaaS telemetry.
  • Expertise in MITRE ATT&CK, adversary emulation, and detection coverage analysis.
  • Experience building and tuning high-fidelity detections at scale.
  • Strong understanding of modern attacker tradecraft across Windows, Linux, cloud, identity, and SaaS environments.
  • Excellent communication skills with the ability to engage practitioners, executives, and customers.
  • Early-stage startup mindset. You thrive on ambiguity and move with lightspeed execution
  • Being data-driven is part of your DNA.

Preferred

  • Experience leading detection engineering programs at large complex environments.
  • Expertise with EDR platforms such as CrowdStrike, Microsoft Defender, SentinelOne, or Palo Alto Cortex XDR.
  • Experience with cloud security platforms including AWS, Azure, and GCP.
  • Familiarity with AI, machine learning, LLMs, or autonomous security workflows.
  • Experience contributing to open-source detection content (Sigma, YARA, Suricata, Zeek, etc.).
  • Public speaking, research publication, or conference presentation experience.

Work Environment/Travel

We are a 100% remote company where you will work from your home with company-provided equipment to set you up for success. Semi-frequent travel to professional office settings and other events locally and nationally; some overnight travel expected.

Compensation

In the spirit of pay transparency, we are excited to share the base salary range below, exclusive of fringe benefits or potential bonuses. If you are hired at Dropzone your final base salary compensation will be determined based on factors such as geographic location, skills, education, and/or experience. In addition to those factors, we believe in the importance of pay equity and consider internal equity of our current team members as a part of any final offer. Please keep in mind that hiring at the maximum of the range would not be typical to allow for future and continued salary growth. We also offer a generous benefits package, including company paid health insurance, 401K Plan with employer match, Self-Managed PTO, parental leave, and more.

The pay range for this role is:
$200,000$250,000 USD