Staff Security Engineer, Detection & Response
Maven Clinic
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
129 open detection roles across 57 companies are on ApplySarthi right now, most of them in Bengaluru (11), Pune (1), Hyderabad (1).
- Security Engineer, Detection and ResponseNotion
- Software Development Engineer, Items and Offers Platform, Identity Performance and Defect DetectionAmazon
- Staff Security Engineer, Detection & ResponseAnthropic
- Staff Security Researcher- Detection AI ResearchSentinelOne
- Senior Security Engineer - Threat DetectionSamsara
What detection roles keep asking for: Python (48%), SIEM (47%), AWS (30%), LLMs (23%), SQL (22%), SaaS (22%), Machine learning (19%), Kubernetes (18%) — counted across their open postings here.
Security Engineer jobs in the United States · Security Engineer jobs in New York · Remote Security Engineer jobs · LLMs jobs · SIEM jobs
Maven Clinic has 36 open roles listed here.
- Billing Specialist Associate
- Senior Associate, Member Growth Marketing
- Customer Success Director
- Senior Recruiter (Contract)
- Client Success Manager
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for detection roles keep coming back to Python, SIEM, AWS, LLMs. Practise those questions before you sit with Maven Clinic.
Questions you are likely to be asked
- Why do you want to join Maven Clinic?
- What is your experience with LLMs? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Staff Security Engineer, Detection & Response at Maven Clinic interview free →Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife — improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com
An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including:
- TIME 100 Most Influential Companies (2023, 2026)
- Fortune Change the World (2024)
- CNBC Disruptor 50 List (2022, 2023, 2024)
- Fortune Best Workplaces for Millennials (2024)
- Fortune Best Workplaces in Health Care (2024)
- Fast Company Most Innovative Companies (2020, 2023)
- Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024)
About the Role
You'll own our Incident Detection and Response program, including threat modeling our systems and codebase and directing the investigation when something does happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide technical direction and judgment calls. You'll spend most of your time finding bugs in our code and gaps in our SDLC before they become incidents, then building and implementing or project managing the fixes yourself. AI is a growing part of that surface, and as our reliance on LLMs, AI-generated code, and agents expands, you'll be responsible for understanding and managing the risk that comes with it.
What You'll Own
Investigation & Technical Direction
- Lead investigations hands-on. When an incident or suspicious finding comes up, you pull the logs, build the narrative of what happened, and advise business and engineering leaders on next steps.
- Read production code when needed to understand what's actually happening.
Proactive Hunting & SDLC Hardening
- When you're not investigating, hunt for bugs in our codebase and weaknesses in our SDLC where problems can slip past existing controls.
- Propose and implement fixes yourself, or manage the resolution with the right teams, whether that's a specific code fix, a broader process or control change.
- Partner with our Product Security Engineer on golden paths when a weakness points to a systemic gap.
Detection Engineering
- Own and tune the detection logic running through 7AI, validating its investigations and escalations and setting the criteria for what triggers an alert.
- Close gaps in logging and visibility so the tooling has the right data to work with.
Managing AI Risk
- Help us understand and manage the security risks that come with our growing use of LLMs and AI tooling, both in what we build and what we adopt internally.
What We're Looking For
Required:
- 6+ years of security experience combining hands-on software or AppSec depth with detection and SIEM engineering ownership.
- Comfortable reading production code across multiple languages and stacks well enough to judge whether a finding is actually exploitable.
- Experience building threat models of codebases, reasoning about attack surface, trust boundaries, and data flow well enough to anticipate where problems will emerge.
- A track record of finding and fixing systemic weaknesses, whether they surfaced through an incident or through your own proactive review.
- Strong communication skills, with enough credibility to direct an investigation and influence peers informally.
Strongly preferred:
- Hands-on experience with AI-assisted security operations tooling, such as AI SOC platforms, LLM-based triage, or agentic escalation systems.
- Interest or experience in securing AI and LLM-powered systems, including risks like prompt injection, model misuse, or agentic tool abuse.
- Prior exposure to golden-path or secure-by-default infrastructure initiatives, even in a supporting role.
- Experience with container or image security and the patching lifecycle.
- A relevant certification such as GCIH, GCFA, GCDA, OSCP, or CISSP.
The base salary range for this role is $221,000 - $299,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.
Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.
At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.
Benefits That Work For You
Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally. We remain focused on providing a competitive benefits package for our employees. On top of standards such as employer-covered health, dental, and insurance plan options, we offer an inclusive approach to benefits:
- Maven for Mavens: access to the full platform and specialists, including care for mental health, reproductive health, family planning and pediatrics.
- Whole-self care through wellness partnerships
- Hybrid work, in office meals, and work together days
- 16 weeks 100% paid parental leave and new parent stipend (for Mavens who've been with us for 1 year+)
- Annual professional development stipend and access to a personal career coach through Maven for Mavens
- 401K matching for US-based employees, with immediate vesting
These benefits are applicable to Maven Clinic Co., US-based, full-time employees only. 1099/Contract Providers are ineligible for these benefits.
Maven is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Maven is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Maven Clinic interview requests and job offers only originate from an @mavenclinic.com email address (e.g jsmith@mavenclinic.com). Maven Clinic will never ask for sensitive information to be delivered over email or phone. If you receive a scam issue or a security issue involving Maven Clinic please notify us at: security@mavenclinic.com. For general and additional inquiries, please contact us at careers@mavenclinic.com.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Care CoachMaven Clinic
- Design Lead, ConsumerMaven Clinic
- Director, Marketing OperationsMaven Clinic
- International Care Advocate (UK)Maven Clinic
- Payment Operations AssociateMaven Clinic
- Product Marketing Manager (Contractor)Maven Clinic
- Sales Development RepresentativeMaven Clinic
- Senior Associate, RFP & Implementation Projects Maven Clinic
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-09-25. ApplySarthi collects openings and links to application pages; the role is advertised by Maven Clinic, not by us.