← Back to jobs

Applied Cyber, Email Security (Detection Engineering)

Company
Doppel
Location
United States
Work type
Full Time · Remote
Posted
2026-09-15

Job description

The Role
You’ll investigate the hardest email threats and detection failures, then turn what you learn into detections, evals, AI behavior, and product capabilities that scale across every Doppel customer. As our technology learns to handle today’s problems, you’ll move up the complexity curve to solve the next ones.

What You Will Do
Own detection problems end-to-end — from emerging TTP or FN → investigation → detection hypothesis → validation → production coverage → measurement.

Use AI as a force multiplier — build evals, supervise model behavior, use coding agents aggressively, and automate repetitive investigative work.

Partner with Product and Engineering on signals, detection logic, edge cases, and validation.

Work with customers and GTM on detection gaps, real-world TTPs, and platform behavior.

Turn tooling, threat-intelligence partnerships, and provider relationships into new signals and detection capabilities.

Required Qualifications
Bring deep practitioner judgment from one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email/messaging security; range across multiple areas is a major plus.

Take messy detection failures from “something’s off” to root cause — prove what matters in the data and turn FP/FN cases into durable fixes.

Think like both attacker and defender across phishing, BEC, impersonation, credential theft, ATO, and evolving social-engineering TTPs.

Turn expert judgment into detection logic, evals, tests, requirements, and systems that scale beyond a single investigation or customer.

Thrive at the intersection of security, AI, product, and customers — challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity.

Nice to Have
SEG/email-security depth: SPF, DKIM, DMARC, headers, mail flow, and sender identity.

Experience with M365/Exchange Online, Google Workspace, or email-security APIs.

Detection-as-code, eval datasets/labeling, model benchmarks, or LLM/ML security systems.

Built agentic security workflows, autonomous triage, or LLM evaluation systems.

Experience with Agentic SOC, SIEM/TI tooling, and threat-intelligence provider/vendor partnerships.

Why This Role
Shape the product, not just operate it. You work on real emerging attacks and turn practitioner judgment into detections, AI behavior, and product capabilities alongside Product, Engineering, AI/ML, customers, and ecosystem partners.

Original source