JOBSEARCHER

Security Detection Engineer

WhoopSomerville, MAL6 LeadSeptember 15th, 2026
Overview As a Security Detection Engineer at WHOOP you will design and scale high-signal detections to protect millions of members’ biometric data. You’ll shape the detection program across cloud, identity, endpoint, and applications, ensuring accurate signals and resilience to modern attacker tradecraft. You work with cross-functional teams to translate threat intel into actionable detections and continuously improve detection health. This role offers impact through threat-focused analytics, automation, and incident-informed improvements within a fast-growing security organization. Compensation / Benefitscompetitive base salarymeaningful equitybenefits packageopportunity to influence security at scale ResponsibilitiesDesign, build, and scale detections across cloud, identity, endpoint, network, and applications using Detection-as-CodeDevelop detection logic aligned with attacker frameworks (MITRE ATT&CK)Translate threat intelligence into actionable detections and validate via adversary emulationCreate behavioral detections targeting account takeover, credential abuse, API misuse, automation attacks, privilege escalation, and data exfiltrationTune alerts to reduce false positives and automate enrichment/triageDefine and monitor detection KPIs (precision, recall, FPR, MTTD) and improve detection healthSupport and lead incident investigations including containment and post-incident improvementsContribute to on-call rotation and reduce operational overhead through automationCollaborate with Engineering, IT, Infrastructure, Product, and GRC to ensure monitoring coverageMap detections to threat models and close visibility gaps as environments scaleExplore advanced analytics and machine learning to boost fidelity and triage workflowsStay ahead of threats by researching new techniques and applying learnings to strategy Key requirements4+ years in information security with a focus on detection engineering, threat detection, or security operationsExperience writing and tuning detections across cloud, identity, endpoint, or application environmentsFamiliarity with YARA, SIGMA, Suricata or similar rule-based detection toolingStrong understanding of attacker techniques across identity compromise, cloud abuse, lateral movement, and data exfiltrationExperience analyzing cloud and SaaS telemetry (auth events, API activity, system logs)Strong scripting skills (Python, Go, or PowerShell) for automation and toolingExperience supporting incident response and on-call rotationsDesirable: detecting authentication and API abuse at scale; ML/data analysis for detection/triageBachelor’s degree in Computer Science, Information Security, or related field (or equivalent)Excellent communication and collaboration skillsFast-paced, high-growth environment experiencestrong communicatorcollaborative mindsetanalytical with systems-thinkingdetection engineering across cloud/identity/endpoint/applicationsMITRE ATT&CK mappingadversary emulation/testing