Doppel logo

Doppel

Applied Cyber, Email Security (Detection Engineering)

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 8 days ago · Added 4 days ago

First listed 8 days ago and still open.

Salary

$120,000–$180,000

Location

United States only

Timezone

Not stated

Contract

Full-time

Experience

Mid

Category

Operations

Published by the employer

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "US Remote, Remote"

What Nomaders makes of it

  • Residency required in United States
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Doppel

Doppel is building the future of social engineering defense. Our AI-native platform uses agentic AI to protect executives, employees, customers, and brands from phishing, impersonation, fraud, and other AI-powered threats across digital channels. We help some of the world’s most recognized brands detect and dismantle attacker infrastructure while strengthening employee resilience through threat-informed training and simulation. By unifying Digital Risk Protection, Human Risk Management and Email Security, Doppel connects threats into a real-time intelligence graph to power faster disruption, smarter defense, and modern security awareness at scale.

Backed by leading investors including Andreessen Horowitz and Bessemer Venture Partners, and trusted by leading enterprises, Doppel is a rapidly growing Series C startup building the future of social engineering defense. Our team combines deep cybersecurity expertise, operational rigor, and startup velocity to solve some of the internet’s most urgent trust and safety challenges.

At Doppel, we focus on building a culture where people feel respected, supported, and trusted to do meaningful work. We value clarity, collaboration, and solving real problems for our customers and teammates.

The Role

You’ll investigate the hardest email threats and detection failures, then turn what you learn into detections, evals, AI behavior, and product capabilities that scale across every Doppel customer. As our technology learns to handle today’s problems, you’ll move up the complexity curve to solve the next ones.

What You Will Do

Own detection problems end-to-end — from emerging TTP or FN → investigation → detection hypothesis → validation → production coverage → measurement.

Use AI as a force multiplier — build evals, supervise model behavior, use coding agents aggressively, and automate repetitive investigative work.

Partner with Product and Engineering on signals, detection logic, edge cases, and validation.

Work with customers and GTM on detection gaps, real-world TTPs, and platform behavior.

Turn tooling, threat-intelligence partnerships, and provider relationships into new signals and detection capabilities.

Required Qualifications

Bring deep practitioner judgment from one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email/messaging security; range across multiple areas is a major plus.

Take messy detection failures from “something’s off” to root cause — prove what matters in the data and turn FP/FN cases into durable fixes.

Think like both attacker and defender across phishing, BEC, impersonation, credential theft, ATO, and evolving social-engineering TTPs.

Turn expert judgment into detection logic, evals, tests, requirements, and systems that scale beyond a single investigation or customer.

Thrive at the intersection of security, AI, product, and customers — challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity.

Nice to Have

SEG/email-security depth: SPF, DKIM, DMARC, headers, mail flow, and sender identity.

Experience with M365/Exchange Online, Google Workspace, or email-security APIs.

Detection-as-code, eval datasets/labeling, model benchmarks, or LLM/ML security systems.

Built agentic security workflows, autonomous triage, or LLM evaluation systems.

Experience with Agentic SOC, SIEM/TI tooling, and threat-intelligence provider/vendor partnerships.

Requirements

  • ·Bring deep practitioner judgment from one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email/messaging security; range across multiple areas is a major plus.
  • ·Take messy detection failures from “something’s off” to root cause — prove what matters in the data and turn FP/FN cases into durable fixes.
  • ·Think like both attacker and defender across phishing, BEC, impersonation, credential theft, ATO, and evolving social-engineering TTPs.
  • ·Turn expert judgment into detection logic, evals, tests, requirements, and systems that scale beyond a single investigation or customer.
  • ·Thrive at the intersection of security, AI, product, and customers — challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity.

Benefits

  • ·A high-growth environment where your work has immediate technical and customer impact

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Doppel, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open operations roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$120,000–$180,000 · You'll be taken to the employer's careers page.