About the job
WorkOS provides APIs and developer tools that help companies meet enterprise requirements for authentication, identity management, and authorization. The platform supports developers scaling their products securely for large organizations. WorkOS is trusted by leading AI companies, including OpenAI, Cursor, Perplexity, Vercel, and Plaid, and is backed by investors such as Meritech, Sapphire, Greenoaks, Craft, Abstract, and Audacious. Following a $100M Series C, the company now holds a $2B valuation.
Security is central to WorkOS’s mission. The Security team safeguards the data and identities of millions, maintaining customer trust as a core priority. Team members collaborate closely, drawing on practical engineering experience and real-world knowledge of system attacks and defenses. The group covers product security, cloud security, and Governance, Risk, and Compliance (GRC), and works with a Managed Detection and Response (MDR) provider for continuous monitoring and response.
Role overview
The Security Engineer - Detection & Response will help advance detection and response capabilities at WorkOS. The company has already established foundational security telemetry across SIEM, EDR, cloud, and identity platforms. The next phase involves building custom detections, developing alerting pipelines, conducting thorough incident investigations, and expanding coverage across both corporate systems and the core product platform.
What you will do
- Lead detection engineering and incident response activities
- Design and improve threat detections across WorkOS infrastructure and corporate environments, with plans to extend to the product platform
- Collaborate closely with the MDR team to strengthen security operations
- Drive threat hunting initiatives and help mature internal security processes

