The opportunity
At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community.
What you'll do
Develop, tune, document, and maintain detection logic across multiple log: sources including endpoint, cloud, container, and SaaS products.
Assist in cyber forensic investigations across a variety of log sources
Optimize log ingestion pipelines and telemetry collection to ensure: high-quality, actionable security data while managing volume and cost
Design and build SOAR playbooks and automation workflows to streamline: detection triage, enrichment, and response actions
Mentor/knowledge share with other detection engineers on threat hunting: methodologies, detection logic development, and investigation techniques
+ years of experience in a detection engineering, incident response, or offensive security role.
What they're looking for
- Experience with 1 or more public cloud platforms (AWS, Azure, GCP)
- Deep understanding of attacker TTPs across modern zero trust environments,: including identity compromise, token theft, and abuse of trust boundaries
- Proficient understanding of macOS internals and telemetry available to identify macOS specific threats
- Experience implementing detection-as-code workflows including version: control, peer review processes, automated testing, and CI/CD deployment pipelines