Overview
You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineering work behind these capabilities—designing scalable systems to detect threats and trigger automated responses. You will integrate AI into detection and response workflows to accelerate rule development, streamline enrichment, and reduce investigation time, with human validation ensuring precision and alignment.
As a cloud-first SaaS company relying on a broad portfolio of SaaS tools, we generate large volumes of event data across identity, endpoint, infrastructure, and collaboration systems. The scale and complexity of this telemetry demand improved detection engineering and automation. This is a platform engineering role focused on building and operating a modern detection pipeline integrated with security automation workflows. You will use Python, structured data, and widely adopted frameworks for mapping adversary behaviors and response logic to drive faster, more effective security outcomes. This role is not a support or triage position but a strategic contributor to our security infrastructure.
About Nerdy At Nerdy (NYSE : NRDY) - the company behind Varsity Tutors - we are redrawing the blueprint of learning. Our Live + AI platform fuses real-time human expertise with proprietary generative-AI systems, setting a new bar for measurable academic impact at global scale. We recruit technologists and operators who turn ambiguous problems into shipping code, iterate quickly, and compound their advantage with every data point. Join us if you are driven to ship meaningful work and push the boundaries of what generative AI can do.
How we compete
- AI-Native at every level From the CEO to day-one hires, everyone builds and ships with generative AI. If you're not wielding AI, you're not done.
- Entrepreneurial velocity Move at founder speed, prototype in hours, and measure in real user outcomes.
- Free-market rigor Ideas rise or fall on merit and results - no committees, no politics, no cap on upside.
- Full-stack ownership You design, build, and run what you ship; accountability is a feature, not a bug.
- Reward for contribution Pay rises with impact; outstanding results earn outsized rewards. Leadership principles and effective AI use are measured and rewarded.
- Relentless exploration Push the frontier of generative AI in live learning and question legacy assumptions.
- Is Apolitical You stay focused on mission-aligned outcomes.
If you are a technically minded builder who thrives on open competition and ownership, join us to do impactful work and redefine what generative AI can do.
Qualifications
Required
5+ years in security engineering, detection engineering, or threat-focused automation rolesStrong knowledge of MITRE ATT&CK framework, detection logic, and IOC / IOA patternsFamiliarity with MITRE D3FEND for defense-in-depth and response playbook designHands-on experience designing, deploying, or managing SIEM platforms (vendor-neutral mindset preferred)Strong Python scripting skills for integrations, enrichment logic, and playbook developmentExperience with structured data formats such as JSON, YAML, logs, and metricsFamiliarity with SaaS logging constraints and cloud-native telemetry, preferably AWSUnderstanding of event-driven architecture and API-driven integrationsDemonstrated ability to use AI tools to accelerate scripting, generate or translate detection rules, or assist with enrichment workflows, always with human validation for accuracyComfortable working autonomously and cross-functionally to deliver reliable detection outcomesPreferred
Experience building or maintaining detection pipelines using Elastic, Panther, or similar platformsExperience with detection-as-code practices, managing detection logic as version-controlled code with testing and CI / CDExperience writing detection rules in formats such as Sigma, including contributing to open-source or internal detection librariesExperience with MITRE frameworks : ATT&CK, D3FEND, and ATLASExperience with OWASP guidance on application telemetry and detection (e.g., AppSensor, Logging Cheat Sheet)Responsibilities
Implement and operate detection systems, including a scalable cloud-native SIEM platform supporting ingestion from identity, endpoint, SaaS, and infrastructure sourcesDevelop and maintain detection coverage maps aligned to MITRE ATT&CK techniques, threat modeling, and incident historyLeverage AI to accelerate detection rule creation, enrichment, and triage insights; conduct AI-assisted threat hunting to surface novel behaviors and codify them as deterministic detectionsBuild detection observability tools and dashboards to monitor rule effectiveness, alert volumes, and system performanceDesign and implement SOAR workflows and automated response playbooks with built-in observability, rollback, and reliability controlsLeverage AI within SOAR for adaptive enrichment, workflow generation, and documentation, while continuously tuning automation based on incident outcomesLead incident response activities as part of the incident commander rotation; drive continuous improvement of runbooks and playbooks using lessons learned and AI support for timelines and summariesCollaborate cross-functionally with engineering and business stakeholders to embed detection and response into system design, operational processes, and organizational prioritiesBenefits and additional notes
Join our worldwide team—work from home, competitive pay, and the chance to shape the future of learning100% remote (home country only), flexible time off, local holiday payContinuous learning membership for you and your householdAccess to exclusive AI tools to boost productivityFeedback-rich, collaborative culture with regular training and peer reviewsMake a global impact with an innovative platform used by learners around the worldThe Bottom Line : This is not a traditional corporate environment—it's a place to do meaningful work and deliver impact at scale.
Job details
Seniority level : Mid-Senior levelEmployment type : ContractJob function : Information TechnologyIndustries : Technology, Information and Internet#J-18808-Ljbffr