eBay Logo

eBay

Detection & Response Engineer

Posted 6 Days Ago
Be an Early Applicant
In-Office
Austin, TX, USA
119K-206K Annually
Senior level
In-Office
Austin, TX, USA
119K-206K Annually
Senior level
Lead incident response and detection engineering across endpoints, identity, cloud, Kubernetes, and networks. Investigate complex security events, develop and tune SIEM detections, perform threat hunting and forensics, apply threat modeling, and build automation and playbooks to scale response. Participate in on-call rotation.
The summary above was generated by AI

At eBay, we're more than a global ecommerce leader — we’re changing the way the world shops and sells. Our platform empowers millions of buyers and sellers in more than 190 markets around the world. We’re committed to pushing boundaries and leaving our mark as we reinvent the future of ecommerce for enthusiasts.

Our customers are our compass, authenticity thrives, bold ideas are welcome, and everyone can bring their unique selves to work — every day. We're in this together, sustaining the future of our customers, our company, and our planet.

Join a team of passionate thinkers, innovators, and dreamers — and help us connect people and build communities to create economic opportunity for all.

About the team and the role:

The Detection & Response team helps protect eBay’s global marketplace by identifying, investigating, and responding to cyber threats across a sophisticated technology environment. This role sits at the center of high-impact security work, partnering closely with the SOC, Global Technology engineering, People Team, Legal, and other security teams to reduce risk and strengthen resilience across the company.

As a senior individual contributor, you will work across endpoint, identity, cloud, Kubernetes/container, and network environments to investigate advanced threats, improve detections, and help compose scalable response capabilities. This is an opportunity to influence how eBay detects and responds to modern adversaries, while contributing to automation, threat-informed defense, and continuous improvement across the security program. This role participates in an on-call rotation.

What you will accomplish:

  • Lead high-impact incident response across a wide range of scenarios, including external intrusions, insider threats, and misuse, helping contain risk and restore business operations quickly and optimally. Improve eBay’s ability to detect and respond to threats by building, tuning, and maintaining SIEM detections and alert logic that increase coverage while reducing false positives.

  • Investigate complex security events end-to-end by reconstructing activity from telemetry, identifying root cause, and driving containment, eradication, and recovery with multi-functional partners.

  • Apply threat modeling to new systems, infrastructure, and features, translating security risks into practical telemetry, detection, and response requirements for engineering teams.

  • Proactively hunt for attacker behavior, surface visibility gaps, and turn adversary research into actionable countermeasures, playbooks, and detective controls that strengthen long-term defense.

  • Develop automation and tooling, including AI- or agent-assisted workflows, to streamline enrichment, triage, evidence collection, and response actions in ways that are safe, auditable, and scalable.

What you will bring:

  • 5+ years of experience in incident response, detection engineering, threat hunting, or a closely related security field, with a track record of leading investigations and improving response operations.

  • Strong understanding of modern adversary tactics, techniques, and procedures, capable of translating them into practical detections, mitigations, and response strategies.

  • Hands-on experience across cloud and SaaS environments, with the ability to develop detection approaches that can scale across platforms such as AWS, Azure, and GCP.

  • Experience working in Kubernetes or containerized environments, including using cluster telemetry to investigate activity and identify common attack paths or failure patterns.

  • Proven network and digital forensics fundamentals, including analyzing network traffic and applying forensically sound practices during active investigations.

  • Scripting or automation experience in Python or a similar language, along with strong communication skills and the flexibility to participate in an on-call rotation.

#LI-BB1

    Additional Details

    The base pay range for this position is expected in the range below:

    $118,800 - $205,600

    Base pay offered may vary depending on multiple individualized factors, including location, skills, and experience. The total compensation package for this position may also include other elements, including a target bonus and restricted stock units (as applicable) in addition to a full range of medical, financial, and/or other benefits (including 401(k) eligibility and various paid time off benefits, such as PTO and parental leave). Details of participation in these benefit plans will be provided if an employee receives an offer of employment.

    If hired, employees will be in an “at-will position” and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

    Remote roles are not eligible for U.S. visa sponsorship.

    eBay is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, and disability, or other legally protected status. If you have a need that requires accommodation, please contact us at [email protected]. We will make every effort to respond to your request for accommodation as soon as possible. View our accessibility statement to learn more about eBay's commitment to ensuring digital accessibility for people with disabilities. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

    We use cookies to enhance your experience and may use AI tools for administrative tasks in the hiring process. To learn how we handle your personal data and use AI responsibly, please visit our Talent Privacy Notice, Privacy Center and AI Hiring Guidelines.

    eBay Austin, Texas, USA Office

    7700 W Parmer Ln, Building D, Austin, Texas, United States, 78729

    Similar Jobs

    2 Days Ago
    In-Office
    Senior level
    Senior level
    Artificial Intelligence • Energy • Renewable Energy
    Owns cybersecurity detection and response across Microsoft Sentinel, Defender, Purview, Entra ID, AWS, and SaaS telemetry. Responsibilities include deploying SIEM connectors, writing and tuning KQL detections mapped to MITRE ATT&CK, leading incident response from triage through post-incident review, investigating endpoint, email, application, DLP, and insider-risk alerts, supporting SOC 2, ISO 27001, and NIST audits, and automating triage with PowerShell, Graph API, or Python.
    Top Skills: AWSAws GuarddutyEntra IdGraph ApiIso 27001KqlMicrosoft Defender For Cloud AppsMicrosoft Defender For EndpointMicrosoft Defender For Office 365Microsoft PurviewMicrosoft SentinelMitre Att&CkNist Csf 2.0PowershellPythonSoc 2
    4 Days Ago
    In-Office or Remote
    Austin, TX, USA
    182K-202K Annually
    Senior level
    182K-202K Annually
    Senior level
    Security • Software • Cybersecurity
    Design, build, and maintain detection-as-code and AI-powered detection/response tooling across cloud, endpoints, and identity. Automate investigation and response workflows, lead incident response, improve observability, tune alerts, and partner with engineering to expand logging and embed detections.
    Top Skills: AWSCloudtrailCrowdstrikeDatadogElkGoGuarddutyPythonRubySentineloneSplunkVpc Flow Logs
    9 Days Ago
    In-Office or Remote
    Austin, TX, USA
    123K-165K Annually
    Junior
    123K-165K Annually
    Junior
    Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
    Lead detection and response efforts: build detections, manage SIEM and orchestration tooling, deploy AI in SOC workflows, investigate incidents across AWS/EKS environments, support threat modeling and vulnerability scanning, and take on-call shifts.
    Top Skills: Ai ToolingAWSBlockchainEksGoGoogle SuiteKubernetesmacOSOrchestration PlatformsPythonSIEMSlack

    What you need to know about the Austin Tech Scene

    Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

    Key Facts About Austin Tech

    • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
    • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
    • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
    • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
    • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
    • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account