--- title: 'Detection Engineer at Artemis' canonical: 'https://feeny.ai/job/detection-engineer-artemis-remote-8ba3238mmbjq' type: 'job' last_seen: '2026-09-05' --- # Detection Engineer at Artemis - **Company:** Artemis - **Location:** Remote - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-08-11 - **Last confirmed live:** 2026-09-05 - **Apply:** https://jobs.ashbyhq.com/artemis/d6f6a87c-d596-4437-8b60-15d16628436c ## Job description ## About the Role We're looking for a Detection Engineer to own the detection content that powers the Artemis platform. You'll design, build, test, and continuously tune high-fidelity detections across cloud, identity, endpoint, and SaaS environments — treating detection as code, and using AI as a force multiplier at every step: authoring rules with AI assistance, and building anomaly detections that learn what's normal in each environment and flag what isn't. Detections at Artemis don't just fire alerts; they feed an AI-native investigation pipeline, so precision, rich context, and machine-readable output matter as much as coverage. This is a hands-on engineering role where every rule you ship directly determines what threats we catch for customers and how fast we catch them. ## Responsibilities - Build and maintain the detection library - Design, implement, and own high-fidelity detections across cloud (AWS, Azure, GCP), identity (Okta, Entra ID), endpoint (EDR), and SaaS log sources, from hypothesis to production. - Practice detection-as-code - Manage detection content like software: version-controlled rules, peer review, automated validation and testing, and CI/CD deployment across customer environments. - Map and close coverage gaps - Measure detection coverage against MITRE ATT&CK, prioritize gaps based on real-world threat activity, and systematically close them. - Validate against real attacks - Build and run attack simulations and test harnesses to prove detections fire on true positives and stay quiet on benign activity, before and after they ship. - Tune relentlessly - Own false-positive and false-negative rates across the fleet: analyze detection performance data, tune noisy logic at the source, and sunset detections that no longer earn their keep. - Use AI to write detections at scale - Leverage AI throughout the detection lifecycle: use AI-assisted workflows to author, convert, test, and document rules faster than any traditional team could, and build the tooling that makes AI-generated detection content trustworthy enough to ship. - Build behavioral and anomaly-based detections - Go beyond static signatures: establish behavioral baselines of normal activity per environment (identity, cloud, SaaS usage patterns) and engineer anomaly detections that surface deviations — impossible travel, unusual privilege use, novel API activity — with high signal and low noise. - Engineer detections for AI-powered investigation - Design detections that produce rich, structured context so the Artemis platform can investigate and resolve cases autonomously. - Turn intelligence into detections - Translate threat intelligence, incident findings, and threat hunt results from our research and SOC teams into durable, behavioral detection logic. - Partner with the SOC and research teams - Close the loop with Apollo analysts and security researchers: use case outcomes and analyst feedback to drive detection improvements, and give them documentation that makes every alert investigable. - Support customer-specific tuning - Adapt and tune detection content to each customer's environment and business context, reducing noise without sacrificing coverage. ## Qualifications - 5+ years of hands-on cybersecurity experience, with significant time in detection engineering - Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms - Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA-L, and comfort writing code (Python preferred) for automation and testing - Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry - Experience with detection-as-code workflows: Git, peer review, automated testing, and CI/CD for detection content - Experience using AI tools to accelerate detection authoring, tuning, or validation — and judgment about when AI-generated logic is ready to ship - Experience building behavioral or anomaly-based detections: establishing baselines of normal activity and engineering detections that flag meaningful deviations - Strong log-analysis skills and demonstrated ability to distinguish malicious activity from benign noise across diverse data sources - Clear written and verbal communication — able to document detection logic and explain coverage and trade-offs to engineers, analysts, and customers Bonus - Experience in an MDR, MSSP, or high-volume SOC environment - Experience with attack simulation and validation frameworks (Atomic Red Team, purple teaming) - Background in threat hunting or incident response across cloud environments - Experience with UEBA platforms or statistical/ML-based detection methods (peer grouping, time-series baselining, outlier scoring) - Experience building AI-assisted detection or investigation tooling from scratch - Contributions to open-source detection content or the broader detection engineering community Why Work at Artemis? - Make a real world impact. You'll lead the human layer of defense that protects real companies. Every standard you set and process you sharpen raises the quality of protection customers depend on. - Be challenged to be better than ever before. Our team includes some of the smartest and most driven people in the world. We guarantee you will learn more in 1 year here than 10 years in another place. - Push the boundaries of technology. Lead a SOC built on the most advanced AI capabilities in cybersecurity, where the platform automates detection, investigation, and tuning, and your team owns the expertise, response, and relationship. You'll define what a modern, AI-native MDR looks like. - Innovative culture. We obsess about customers, move fast with high quality, and value open communication, mentorship and learning. You'll have the autonomy to shape the direction of the operation and own outcomes, not just run a runbook. If you are passionate about cyber security and want to build and lead the team at the cutting edge of AI-powered defense, we'd love to hear from you. ## Compensation We offer a competitive compensation of $100,000-160,000 per year, and a top-of-market equity component. A variety of factors are considered when determining the compensation, including a candidate's professional experience. Final offer amounts may vary from the amounts listed. ## Equal Opportunity At Artemis, we believe the best ideas come from diverse teams. We're committed to creating an inclusive environment where people of all backgrounds, experiences, and perspectives can do their best work. We welcome everyone, regardless of race, gender, age, religion, identity, or anything else that makes you, you. ## About Artemis ## Company Overview - **One-liner**: Artemis is building an AI-native protection platform that helps security teams detect, investigate, and respond to modern cyber threats by replacing traditional SIEMs with agentic, environment-aware detection. - **Entity Type**: Private (Series A) - **Headquarters**: New York, New York, United States - **Founded**: 2025 - **Founders**: Shachar Hirshberg (CEO) and Dan Shiebler (CTO) ## Core Business - Primary industry: Cybersecurity (AI-Native Security Operations) - Target customers: Enterprise security teams (SOC, detection engineering, threat hunting) - Mission or purpose: Reinventing how companies defend themselves in the AI era by delivering precise, adaptive, and cost-effective threat detection and response. ## Products & Services - **[Artemis AI-Native Protection Platform]**: A SaaS platform that continuously analyzes a customer’s technical and business environment to autonomously create, tune, and maintain detections. It correlates identity, cloud, endpoint, network, and SaaS telemetry into complete attack narratives. Features include AI agents for autonomous investigation, natural-language querying, federated telemetry (reducing ingest costs), automated threat intelligence mapping (MITRE ATT&CK), and incident response playbooks. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total Funding of $70M (Series A of $50M and Seed of $20M, both closed in April 2026) - **Notable Investors/Partners**: Felicis, First Round Capital, Brightmind, Theory VC, Lockstep, Two Sigma Ventures, plus a group of prominent cybersecurity operators - **Growth Signals**: The company has grown to 22 employees in under two years (founded 2025), with a monthly headcount growth of +11.8%. It reports a 96% reduction in mean time to resolution for customers and a “2 weeks to coverage” deployment timeline. The company is actively hiring across engineering, GTM, and security roles (12 open positions as of mid-2026). ## Competitive Advantages - **AI-Native Architecture**: Built from the ground up with AI agents that reason, adapt, and act—not a chatbot bolted onto a legacy SIEM. This allows for autonomous detection writing, investigation, and response. - **Federated Telemetry**: Streams only detection-critical logs and retrieves the rest on demand, dramatically reducing data ingestion costs while maintaining full visibility. - **Environment Intelligence**: Continuously builds a living model of assets, users, configurations, and business context, enabling detections that adapt to the specific environment rather than relying on generic rules. - **Founding Team Depth**: CEO Shachar Hirshberg led product for Amazon GuardDuty and was an early employee at Demisto; CTO Dan Shiebler led AI/ML at Abnormal Security and built ML systems at Twitter. ## Strategic Focus - Current priorities include expanding the enterprise customer base, deepening AI agent capabilities across the full security lifecycle (detection, investigation, response, containment), and scaling the go-to-market team (hiring for enterprise sales, partnerships, and product marketing). - The company is also focused on closing the gap between traditional SIEMs and the speed of AI-driven threats, with a clear emphasis on replacing legacy detection workflows. ## Why Work Here - **Culture & Mission**: Mission-driven work at the intersection of AI and cybersecurity, with a focus on building “AI that defends modern systems.” The team includes alumni from Amazon, Abnormal Security, Two Sigma, and Lockheed Martin. - **Work Policy**: Most roles are based in New York City (HQ), with some remote positions (e.g., Senior Software Engineer, Infrastructure). - **Benefits**: Top-of-market salary and equity in an early-stage company; comprehensive health, dental, and vision insurance; 401k plan; daily team meals (breakfast, lunch, dinner); $200/month commute reimbursement; $300/month wellness stipend. - **Engineering Culture**: AI-first development approach—teams design systems where AI agents reason and act autonomously, rather than relying on handcrafted rules. Tech stack includes TypeScript, Python, React, ClickHouse, Snowflake, Terraform, and more. - **Growth**: Early-stage company with significant growth potential and a fast-paced, high-impact environment. ## Sources 1. [artemissecurity.com](https://artemissecurity.com/) – Product and company overview 2. [artemissecurity.com/about](https://artemissecurity.com/about/) – Founders and mission 3. [artemissecurity.com/careers](https://artemissecurity.com/careers/) – Open roles and benefits 4. [linkedin.com/company/goartemis](https://www.linkedin.com/company/goartemis) – LinkedIn profile, funding, employee data 5. [getclera.com](https://www.getclera.com/companies/artemis-ai) – Company intelligence and tech stack ## Other roles at Artemis - [Senior Recruiter](https://feeny.ai/job/senior-recruiter-artemis-new-york-5v4j4n4x8hdt) — New York, NY - [Senior Sales Engineer](https://feeny.ai/job/senior-sales-engineer-artemis-remote-mn6a5gb7k2qc) - [Technical Customer Success Engineer](https://feeny.ai/job/technical-customer-success-engineer-artemis-remote-jy1n11khfkm8) - [Lead Security Engineer, Internal and IT](https://feeny.ai/job/lead-security-engineer-internal-and-it-artemis-new-york-q4a3a392y7yf) — New York, NY - [Senior Product Designer](https://feeny.ai/job/senior-product-designer-artemis-new-york-0gr8n14wm303) — New York, NY - [Technology Alliances Manager](https://feeny.ai/job/technology-alliances-manager-artemis-remote-vb4bkcq9nvwe) - [SOC Manager](https://feeny.ai/job/soc-manager-artemis-new-york-pchrty2c6kke) — New York, NY - [Senior Account Executive (Enterprise)](https://feeny.ai/job/senior-account-executive-enterprise-artemis-remote-e634bg6hzzt1) - [Channels and Partnerships Lead](https://feeny.ai/job/channels-and-partnerships-lead-artemis-new-york-4s35wh24q1jt) — New York, NY - [Security Analyst](https://feeny.ai/job/security-analyst-artemis-new-york-415jc8m0a2fe) — New York, NY