As the first dedicated Detection & Response Engineer, you will build a greenfield security function from the ground up for a HIPAA-regulated telehealth leader. Moving beyond traditional SIEM management, you will implement a detection-as-code philosophy, automating threat visibility and response across a high-scale AWS environment to protect millions of patients worldwide.
Security Engineer, Detection & Response at Doxy.me
Are you a security engineer who prefers writing code over clicking through a SIEM UI? Join a global telehealth leader trusted by over one million providers as their first-ever Detection & Response Engineer. In this greenfield role, you’ll build a modern security operations function from scratch, implementing detection-as-code and automated response workflows across a massive AWS environment. If you’re ready to own the detection roadmap for a HIPAA-regulated platform serving 180+ countries, this is your chance to make a massive impact on global healthcare security.
About this role
Role overview
About the company
Doxy
Global telehealth platform trusted by over one million healthcare providers across 180 countries
What you'll do
What you will do
- Own the end-to-end detection lifecycle, from threat research to writing and deploying rules via CI/CD using a detection-as-code approach.
- Build and maintain robust telemetry pipelines to correlate signals across AWS infrastructure, identity systems, and application logs.
- Lead incident response efforts, including forensic investigations and the development of automated containment workflows to mitigate emerging threats.
Who you are
Who this is a fit for
- Proven experience in detection engineering with a strong software engineering background in Python, TypeScript, or SQL.
- Deep technical proficiency in AWS security, cloud-native infrastructure, and modern observability platforms like Datadog.
- Expert understanding of attacker techniques (MITRE ATT&CK) and the ability to translate threat models into high-precision detection signals.
Why this role
Why this role is remarkable
- Greenfield Opportunity: As the first dedicated D&R hire, you have total autonomy to shape the function, select the tooling, and define the roadmap without legacy technical debt.
- High-Stakes Impact: Your work directly secures a platform used by 1M+ healthcare providers globally, ensuring the privacy of sensitive patient data in a highly regulated landscape.
- Senior-Led Culture: Work in a flat, high-impact team alongside a CISO and Staff Product Security Engineer who value engineering-first security and automation over manual toil.
Jack & Jill
How Jack & Jill work together
Meet Jack
Jack gets to know what you're great at and what you want next, then searches 15 million jobs daily and helps you discover roles at companies like this.
How does this work?
Jack’s an AI agent for job searching and career coaching. He works for you.
Jill is the AI recruiter working for the company. She recruits from Jack’s network.
If it’s a match and the company wants to meet you, they’ll make the intro. In the meantime, if you’d like, Jack will send you excellent alternatives.