Back to Jobs
Chainalysis

Staff Threat Detection Engineer

ChainalysisRemote - USAPosted 1 hour ago
Security / ITRemoteFull-timeStaffUSAUSD 175k / yearly – USD 240k / yearly

Job Description

The Detection and Response Engineering (DaRE) team protects Chainalysis corporate assets and manages internal incident response. We reduce risk by building systems that detect and contain malicious activity while performing high-stakes digital forensics. Our mission is to ensure that as blockchain adoption grows, our own infrastructure remains resilient against evolving threats.

As a Staff Threat Detection Engineer, you are the technical lead for our corporate threat detection strategy. You design high-fidelity detections, lead proactive threat hunting, and perform critical risk assessments for both corporate and product engineering functions. This is a high-profile role where you will act as a subject matter expert (SME) for threat modeling, guiding security best practices across all corporate functions.

In this role, you’ll:

  • Lead Detection Strategy: Own the end-to-end roadmap for corporate threat detection, mapping coverage against frameworks like MITRE ATT&CK.

  • Engineeer High-Fidelity Detections: Design and maintain scalable detection logic across SIEM, EDR, and cloud logging platforms (AWS/GCP).

  • Conduct Threat Hunting: Plan and execute hypothesis-driven hunting campaigns to uncover novel TTPs and turn findings into durable controls.

  • Perform Risk Modeling: Lead threat assessments and design reviews for new technology on-boarding and product design changes.

  • Optimize Response: Partner with Incident Response to refine alert quality, automate triage playbooks, and reduce time-to-containment.

  • Mentor & Influence: Provide technical leadership and mentorship to the DaRE team while influencing product teams to improve visibility and remediate gaps.

We’re looking for candidates who have:

  • 8+ years of experience in detection engineering, SOC, or incident response at scale.

  • Deep expertise in building and tuning detections within SIEM, EDR, and log analytics platforms.

  • Advanced proficiency in writing complex detection queries (e.g., KQL, SPL, SQL).

  • Demonstrated experience detecting modern attacker TTPs across endpoint, identity, and cloud environments.

  • Strong scripting skills (Python, Bash) for automation and enrichment.

  • Proven ability to lead cross-functional security initiatives with IT and Engineering stakeholders.

Nice to have experience:

  • Experience leading threat hunting in cloud-first or SaaS-heavy environments.

  • Familiarity with securing AI integrations and managing associated security risks.

  • Knowledge of blockchain ecosystems and threats specific to the Web3/Crypto space.

  • Prior experience in a Staff-level technical leadership or mentorship role.

  • Red teaming experience against web technologies

  • OSINT and investigations

Technologies we use:

  • SIEM, EDR, and Log Analytics platforms

  • AWS, GCP

  • Python, Bash

  • KQL, SPL, SQL

  • MITRE ATT&CK Framework

About Chainalysis

Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

You belong here. 

At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture.

We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can’t wait to meet you. 

Job descriptions are sourced from publicly available company career pages via their official APIs. All trademarks and content belong to their respective owners. If you are a company representative and would like to modify or remove this listing, please contact us.

Job Details

DepartmentSecurity / IT
Work ModeRemote
LocationRemote - USA
Employment TypeFull-time
LevelStaff
SalaryUSD 175k / yearly – USD 240k / yearly
CountryUSA
Apply Now

About Chainalysis

Chainalysis

Chainalysis

45 open positions