Samsara
Samsara

Senior Security Engineer - Threat Detection

engineeringfull-timeRemote - CA
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

About the role

Samsara Security is looking for a Senior Threat Detection Engineer. This is a hands-on engineering role: you will build and operate the signals, pipelines, and tooling that power how we discover threats against Samsara and our customers.

The Threat Detection team owns the detection platform end to end — the data pipelines that feed it, the detection content that runs on it, the CI/CD that ships it, and the AI-assisted tooling that scales what a small team can cover. You will write detections, and you will also build the machinery that makes the next detection faster to develop, safer to deploy, and measurable in production.

You will report to the Director of Threat Detection and Response and work closely with Security Operations, Application Security, and Enterprise Security, as well as engineering teams across the company.

We are looking for someone who takes projects from idea to proof-of-concept to production, who is comfortable being the first person to build something, and who is genuinely interested in what AI can and cannot do for detection engineering — including where it introduces risk rather than removing it.

This role is open to candidates residing in the US except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area.

You should apply if:

  • You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely.
  • You are the architect of your own career: If you put in the work, this role won't be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, countless opportunities to experiment and master your craft in a hyper growth environment.
  • You're energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers.
  • You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best.

In this role, you will:

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry, with clear false-positive thresholds.
  • Own the full detection lifecycle—from hypothesis, data validation, and baselining through deployment, tuning, validation, and retirement.
  • Advance our detection-as-code platform through version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.
  • Identify emerging threat surfaces and build integrations that strengthen data ingestion, enrichment, and coverage across internal and third-party systems.
  • Evaluate AI-powered security capabilities, including secure MCP integrations, threat hunting, anomaly detection, and response automation.
  • Turn threat intelligence into actionable detection and retrospective scanning.
  • Partner closely with Security Operations during investigations, incidents, table top exercises, detection maintenance, and code pairing.
  • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices.

Minimum requirements for the role:

  • 6+ years in security engineering, detection engineering, or a related technology discipline.
  • Strong Python and SQL skills, with experience analyzing large datasets to build and validate detections.
  • Hands-on experience with detection-as-code, Git-based workflows, automated testing, and CI/CD deployment.
  • Deep experience with modern SIEM platforms, including data onboarding, advanced queries, dashboards, and threat intelligence enrichment.
  • Working knowledge of AWS, Linux, containers, and EDR.
  • Proven ability to build systems from scratch, lead projects independently, learn new technologies quickly, and communicate technical concepts clearly through documentation, RFCs, and presentations.

An ideal candidate also has:

  • Experience with data orchestration platforms such as Airflow or Databricks.
  • Applied experience with LLMs, agentic frameworks, and MCP integrations, including their security risks and failure modes.
  • Experience with behavioral analytics, anomaly detection, feature engineering, and model evaluation.
  • Familiarity with risk-based alerting, ChatOps, distributed alerting, and attack simulation.
  • Additional experience with Go, Terraform, malware analysis, digital forensics, or FedRAMP environments.

#LI-Remote

The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance, subject to plan terms and conditions. Learn more about our total rewards and benefits below.

Annual Base Salary

$202,725

$238,500 USD

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now