Back to Jobs
Doppel
AI & Machine Learning 1d ago

Detection Engineering Lead (AI & SOC) at Doppel

Doppel
United StatesUnited States
Full-time
$120,000-$180,000 OTE
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Machine Learning41mFree Trial ✨
Start 10-Day Free Trial
AI EngineerDetection-as-codeAgentic SOCCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

About Doppel

Doppel is building the future of social engineering defense. Our AI-native platform uses agentic AI to protect executives, employees, customers, and brands from phishing, impersonation, fraud, and other AI-powered threats across digital channels. We help some of the world’s most recognized brands detect and dismantle attacker infrastructure while strengthening employee resilience through threat-informed training and simulation. By unifying Digital Risk Protection, Human Risk Management, and Email Security, Doppel connects threats into a real-time intelligence graph to power faster disruption, smarter defense, and modern security awareness at scale.

Backed by leading investors including Andreessen Horowitz and Bessemer Venture Partners, and trusted by leading enterprises, Doppel is a rapidly growing Series C startup building the future of social engineering defense. Our team combines deep cybersecurity expertise, operational rigor, and startup velocity to solve some of the internet’s most urgent trust and safety challenges.

At Doppel, we focus on building a culture where people feel respected, supported, and trusted to do meaningful work. We value clarity, collaboration, and solving real problems for our customers and teammates.

The Role

You’ll investigate the hardest email threats and detection failures, then turn what you learn into detections, evals, AI behavior, and product capabilities that scale across every Doppel customer. As our technology learns to handle today’s problems, you’ll move up the complexity curve to solve the next ones.

What You Will Do

  • Own detection problems end-to-end — from emerging TTP (Tactics, Techniques, and Procedures) or FN (False Negatives) → investigation → detection hypothesis → validation → production coverage → measurement.

  • Use AI as a force multiplier — build evals, supervise model behavior, use coding agents aggressively, and automate repetitive investigative work.

  • Partner with Product and Engineering on signals, detection logic, edge cases, and validation.

  • Work with customers and GTM on detection gaps, real-world TTPs, and platform behavior.

  • Turn tooling, threat-intelligence partnerships, and provider relationships into new signals and detection capabilities.

Required Qualifications

  • Bring deep practitioner judgment from one or more of detection engineering, SOC/Incident Response (IR), threat intelligence/OSINT (Open-Source Intelligence), or email/messaging security; range across multiple areas is a major plus.

  • Take messy detection failures from “something’s off” to root cause — prove what matters in the data and turn FP (False Positives)/FN (False Negatives) cases into durable fixes.

  • Think like both attacker and defender across phishing, Business Email Compromise (BEC), impersonation, credential theft, Account Takeover (ATO), and evolving social-engineering TTPs.

  • Turn expert judgment into detection logic, evals, tests, requirements, and systems that scale beyond a single investigation or customer.

  • Thrive at the intersection of security, AI, product, and customers — challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity.

Nice to Have

  • SEG (Sender Email Guidelines)/email-security depth: SPF, DKIM, DMARC, headers, mail flow, and sender identity.

  • Experience with M365/Exchange Online, Google Workspace, or email-security APIs.

  • Detection-as-code, eval datasets/labeling, model benchmarks, or LLM/ML security systems.

  • Built agentic security workflows, autonomous triage, or LLM evaluation systems.

  • Experience with Agentic SOC, SIEM/TI tooling, and threat-intelligence provider/vendor partnerships.

Why This Role

  • Shape the product, not just operate it. You work on real emerging attacks and turn practitioner judgment into detections, AI behavior, and product capabilities alongside Product, Engineering, AI/ML, customers, and ecosystem partners.

How would you rate this job post?

See what other professionals think about this role.

banner

Doppel (operating via doppel.com) is a premier AI-native social engineering defense platform engineered to protect the world’s best brands from sophisticated, multi-channel attacks. Founded in 2022 and headquartered in San Francisco, California, the company fundamentally transforms how security operations centers (SOCs) detect and disrupt impersonation and fraud. Moving far beyond traditional, siloed security tools, Doppel natively unifies Digital Risk Protection, Human Risk Management, and Email Security into a single, cohesive ecosystem. The platform empowers organizations to outpace AI-driven threats by identifying malicious activity across domains, social media, paid ads, and the dark web. Under the hood, their sophisticated agentic AI and proprietary Threat Graph automatically correlate disparate threat signals, execute rapid infrastructure takedowns, and continuously train employees using highly realistic deepfake simulations. Trusted by industry leaders like Notion, Coinbase, and Andreessen Horowitz, Doppel remains a definitive cornerstone of the modern cybersecurity landscape, actively bridging the gap between digital and human risk to stop digital threats before they scale.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More