Instacart
Detection Engineer II
About this role
Instacart seeks a Detection Engineer II to develop and maintain security detection logic across endpoint, cloud, container, and SaaS environments. You'll own the full detection lifecycle—from telemetry design to automated response—while collaborating with engineering, incident response, and red teams to translate adversary techniques into durable, high-fidelity detections operating at scale.
What you'll do
- Develop, tune, and maintain detection logic across endpoint, cloud, container, and SaaS log sources
- Assist with cyber forensic investigations across multiple log sources and platforms
- Optimize log ingestion pipelines and telemetry collection to balance quality, volume, and cost
- Design and build SOAR playbooks and automation workflows for detection triage and response
- Mentor other detection engineers on threat hunting methodologies and investigation techniques
- Implement detection-as-code workflows with version control, testing, and CI/CD pipelines
What they're looking for
- Detection engineering and threat modeling
- Incident response and cyber forensics
- Cloud platforms (AWS, Azure, or GCP)
- macOS internals and endpoint telemetry
- Python, Golang, or similar scripting languages
- SOAR platform automation and orchestration
- Detection-as-code and CI/CD workflows
- Knowledge of attacker TTPs and zero trust security
Opens the official application on the employer’s site. No login required.
Instacart
Instacart builds a grocery delivery marketplace and enterprise AI solutions that optimize shopping experiences through machine learning, pricing, recommendations, and generative AI. The company is hiring PhD-level machine learning researchers, systems engineers, and forward-deployed engineers to develop scalable AI systems and deploy agentic solutions for retail and CPG partners.
- Website
- instacart.com
Likely interview questions
- Can you walk us through a detection you've built from scratch—from identifying an adversary TTP to validating it in production?
- How do you balance detection fidelity with alert volume and analyst burnout in high-signal environments?