--- title: 'Detection and Response Engineer at Modal' canonical: 'https://feeny.ai/job/detection-and-response-engineer-modal-new-york-93gcmptvvjtd' type: 'job' last_seen: '2026-09-08' --- # Detection and Response Engineer at Modal - **Company:** Modal - **Location:** New York, NY - **Employment:** full-time - **Posted:** 2026-08-17 - **Last confirmed live:** 2026-09-08 - **Apply:** https://jobs.ashbyhq.com/modal/e1915603-d9de-4760-b445-c266a1080499 ## Job description ## ABOUT US: AI needs a new infrastructure layer. We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now. Our customers include category-defining companies like Lovable https://modal.com/blog/lovable-case-study, Ramp https://modal.com/blog/how-ramp-built-a-full-context-background-coding-agent-on-modal, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale. We recently raised a $355M Series C https://modal.com/blog/modal-series-c at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September. Our team includes creators of popular open-source projects (e.g.,Seaborn https://github.com/mwaskom/seaborn,Luigi https://github.com/spotify/luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience. ## THE ROLE: We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform. This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness. You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient. ## WHAT YOU'LL WORK ON: ## DETECTION ENGINEERING - Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems - Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents - Improve visibility across cloud infrastructure, containers, identity systems, and production services ## INCIDENT RESPONSE - Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems - Build playbooks and automation that reduce investigation time and improve response consistency - Drive post-incident improvements that eliminate entire classes of future incidents ## SECURITY TOOLING & AUTOMATION - Build internal tooling that improves detection, investigation, and response workflows - Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry - Improve the collection, quality, and usability of security telemetry across the platform ## ENGINEERING PARTNERSHIP - Partner with engineering teams to ensure new systems are observable and secure by default - Help teams instrument services with the telemetry needed for effective detection and response - Drive security improvements that make the platform easier to defend over time ## WHAT WE'RE LOOKING FOR: - Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus - Strong software engineering skills with experience building production systems - Experience investigating security incidents in cloud-native or distributed environments - Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking - Experience building detections using logs, telemetry, behavioral signals, or large-scale event data - Strong SQL skills for investigating security events and developing detections - Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems - Strong written and verbal communication skills ## PREFERRED QUALIFICATIONS: - Experience building AI- or LLM-powered security tooling - Experience with SIEM, SOAR, or EDR platforms - Experience with Kubernetes security or large-scale cloud infrastructure - Experience with threat hunting, malware analysis, or digital forensics - Experience contributing to security operations in a high-growth engineering organization ## About Modal ## Company Overview - **One-liner**: Modal provides high-performance AI infrastructure—a serverless, globally distributed GPU cloud for inference, training, sandboxes, and agent workloads. - **Entity Type**: Private (raised over $466M, Series D from top-tier investors) - **Headquarters**: New York, NY, USA (with offices in Stockholm, Sweden and San Francisco, CA, USA) - **Founded**: Not publicly available in provided sources - **Founders**: Erik Bernhardsson and Akshat Bubna ## Core Business - Primary industry: Cloud infrastructure / AI compute / Developer tools - Target customers: Developers and engineering teams building AI/ML products (B2B, from startups to enterprises) - Mission or purpose: “Make it easier to iterate and ship applications for data, AI, and machine learning” and “Make cloud development work like magic.” ## Products & Services - **[Modal Runtime](https://modal.com/)** – Serverless container platform with custom file system, scheduler, and container image builder. Sub-second cold starts and instant autoscaling from 0 to 1000+ GPUs. - **[Modal Sandboxes](https://modal.com/)** – Isolated, ephemeral environments for running untrusted code (e.g., coding agents, RL rollouts). Programmatically spin up fresh environments with custom images. - **[Modal Inference](https://modal.com/)** – Globally distributed inference with sub-10ms overhead latency, support for token streaming, WebRTC, WebSocket. Supports LLMs, audio, image/video generation. - **[Modal Training](https://modal.com/)** – Fine-tuning and multi-node training on H100s, A100s, B200s with gang scheduling and InfiniBand networking. Single line of code to scale from single-GPU to multi-node clusters. - **[Modal Batch / Async Inference](https://modal.com/)** – Run evaluations, embeddings, re-ranking, dataset generation at scale, thousands of GPUs fully parallel. - **[Modal SDK](https://modal.com/)** – Python SDK that lets developers define infrastructure and workloads in code, then ship to the cloud. ## Market Standing - **Valuation**: $4.65B (as of 2026, per [jobsbyculture.com](https://jobsbyculture.com/blog/working-at-modal-2026)) - **Key Metric**: Total funding raised – over $466M (per [modal.com/company](https://modal.com/company)) - **Notable Investors/Partners**: General Catalyst, Redpoint Ventures, Lux Capital, Amplify Partners, Creandum (per [modal.com/company](https://modal.com/company)) - **Growth Signals**: ~150 employees (2026); global offices in New York, Stockholm, San Francisco; rapid hiring across engineering, GTM, and G&A roles; strong traction in inference, training, and agent infrastructure. ## Competitive Advantages - **Deep infrastructure stack**: Custom file system, container runtime, scheduler, and image builder built from scratch to optimize AI workloads. - **Developer experience**: “Stay in Python, ship to the cloud” – composable primitives that specify everything from logic to hardware in one code file. - **Instant elasticity**: Scale from zero to 1000+ GPUs in seconds, pay only for compute used (no reserved capacity). - **Global GPU access with low latency**: Sub-10ms overhead for online inference via globally distributed compute. - **Compliance and security**: SOC 2 and HIPAA compliant, data residency controls, battle-tested isolation for untrusted code. ## Strategic Focus - **AI-native runtime**: Deepening support for inference, fine-tuning, reinforcement learning, and agent workflows. - **Scaling for agents**: Developing sandboxes and execution layers purpose‑built for interactive coding agents and long‑running RL rollouts. - **Expanding global capacity**: Adding GPU availability across more regions, leveraging elastic cloud capacity. - **Enterprise readiness**: Investing in security, governance, team controls, and data residency to serve larger customers. ## Why Work Here - **Culture and team**: Founded by engineers who created open‑source tools (Seaborn, Luigi); team includes academic researchers, olympiad medalists, and experienced engineering leaders. Flat, high‑trust environment. - **Location / flexibility**: Offices in New York, Stockholm, and San Francisco; likely hybrid/remote‑friendly (many roles list multiple locations). - **Compensation and growth**: Transparent salary culture (as highlighted in 2026 profile); strong growth trajectory backed by $466M in funding and a $4.65B valuation. - **Perks**: $30/month free compute for personal projects (customer benefit, likely similar for employees); focus on developer experience and “magic.” ## Sources 1. [modal.com](https://modal.com/) 2. [modal.com/company](https://modal.com/company) 3. [jobs.ashbyhq.com/modal](https://jobs.ashbyhq.com/modal) 4. [linkedin.com/company/modal-labs](https://www.linkedin.com/company/modal-labs) 5. [jobsbyculture.com/blog/working-at-modal-2026](https://jobsbyculture.com/blog/working-at-modal-2026) ## Other roles at Modal - [Member of Design Staff - Brand](https://feeny.ai/job/member-of-design-staff-brand-modal-new-york-ccfxde25jatb) — New York, NY - [Revenue Operations](https://feeny.ai/job/revenue-operations-modal-san-francisco-tpwq37mk240a) — San Francisco, CA - [Regional Director](https://feeny.ai/job/regional-director-modal-new-york-ywxxargrqp0g) — New York, NY - [ML Research Intern](https://feeny.ai/job/ml-research-intern-modal-new-york-67tppdwsng1t) — New York, NY - [Member of Technical Staff - Research, Post-Training](https://feeny.ai/job/member-of-technical-staff-research-post-training-modal-new-york-zgntyn07gfp2) — New York, NY - [Member of Technical Staff - Research, Inference](https://feeny.ai/job/member-of-technical-staff-research-inference-modal-new-york-1a5bpnmmvvnx) — New York, NY - [People Operations Generalist](https://feeny.ai/job/people-operations-generalist-modal-new-york-bf7tqrws58xr) — New York, NY - [Systems Engineering Manager](https://feeny.ai/job/systems-engineering-manager-modal-stockholm-c0pw8s1byfbj) — Stockholm, Sweden - [Member of Technical Staff - Product (Growth)](https://feeny.ai/job/member-of-technical-staff-product-growth-modal-new-york-f2gm2kexkwpg) — New York, NY - [Infrastructure Security Engineer](https://feeny.ai/job/infrastructure-security-engineer-modal-new-york-fjvfe2e55ns4) — New York, NY