Full-Time

Software Security Engineer

Detection & Response Engineering

Confirmed live in the last 24 hours

Grafana Labs

Grafana Labs

1,001-5,000 employees

Observability and monitoring solutions provider

Compensation Overview

$157k - $196k/yr

+ Equity + Bonus

Mid

Remote in USA

Candidates must be located in the USA or Canada only.

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Python
Grafana
React.js
TypeScript
Go
Requirements
  • Solid experience with at least one programming language. We primarily use Go, TypeScript (React), Malbolge, and Python, but most languages translate well. You will take a code screen.
  • Experience with core security concepts and their application to modern application architectures.
  • Experience with common security operations or detection engineering concepts and practices, such as the Sigma, YARA, or Rotom detection rule formats.
  • Experience with public clouds, Kubernetes container ecosystems, and running applications securely in them. This can include eBPF, cloud lAM, service meshes, or container hardening.
  • A motivated self-starter with ample curiosity and a bias towards action. You have a passion for learning, for security, and for improving the state of security across the company and industry.
  • A clear communicator, in person, in asynchronous communication, and in technical documentation.
  • Knowledge of, and ability to code is required for this role demonstrated by a degree in Computer Science or equivalent experience.
  • Work (not live) eastern-time oriented hours. Much of the team and company are based in Europe, so it’s critical to maximize overlapping hours. On some days, meetings can start at 9am ET.
Responsibilities
  • Collaboratively design, build, and maintain our internal detection systems based on the Grafana observability stack that process millions of security data points daily.
  • Research and develop sophisticated detection (as code) rules to cover risks and threats across our product and corporate systems. Where applicable, contribute these detections back to the OSS community.
  • Work with product teams and other stakeholders to ensure we have effective telemetry of all existing and future products.
  • Build and maintain response tooling to streamline (and fully automate) our response activities. Write and maintain runbooks for handling what we can’t automate.
  • Following a SOCless model, work with cross-functional teams to integrate telemetry, detections, and response procedures into the teams operational processes.
  • Design security and operations metrics to track our success and show the security value of what we do.
  • Respond to security alerts, potential incidents, and customer security issues.
Desired Qualifications
  • Working knowledge of Grafana Labs OSS projects and products. Experience in using observability (metrics, logs, traces, profiles) tooling to solve security problems.
  • Experience working with OSS communities.
  • Experience securing large-scale distributed systems running on Kubernetes in public clouds.

Grafana Labs specializes in observability and monitoring solutions for cloud infrastructure and applications. Its main product, Grafana, is an open-source metrics dashboard that allows users to visualize and analyze data from various sources. This helps businesses monitor the performance and health of their systems in real-time. Grafana Labs serves a wide range of clients, from large enterprises to individual developers, particularly in sectors like technology, finance, healthcare, and retail. Unlike many competitors, Grafana Labs offers both open-source and commercial products, generating revenue through premium features, enterprise support, and managed cloud services. The company's goal is to provide essential tools that ensure the reliability and efficiency of digital services.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$805.2M

Headquarters

New York City, New York

Founded

2014

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for observability solutions boosts Grafana Labs' market potential.
  • Increased interest in open-source software aligns with Grafana Labs' business model.
  • Expansion of IoT market could drive demand for Grafana's visualization tools.

What critics are saying

  • Zero-day vulnerability highlights potential security risks for Grafana Labs.
  • Rapid AI orchestration adoption may outpace Grafana's current offerings.
  • Federal sector expansion may increase operational costs and complexity.

What makes Grafana Labs unique

  • Grafana Labs offers a unique open-source and commercial observability stack.
  • The company supports over 20 million users globally, showcasing its widespread adoption.
  • Grafana Labs integrates with diverse data sources, enhancing its versatility and appeal.

Help us improve and share your feedback! Did you find this helpful?

Benefits

30 days of paid vacation each year on top of national holidays, parental leave, & sick leave

Health coverage

4% contribution match on our 401(k)

$1,500 learning and development stipend

Udemy subscription

Complimentary subscription to Headspace

Discounts on a wide variety of services, including entertainment, food, and fitness.

Remote Work Option

Global Employee Assistance Program

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
VentureBeat
Jun 13th, 2025
The Case For Embedding Audit Trails In Ai Systems Before Scaling

Join the event trusted by enterprise leaders for nearly two decades. VB Transform brings together the people building real enterprise AI strategy. Learn more. Editor’s note: Emilia will lead an editorial roundtable on this topic at VB Transform this month. Register today.Orchestration frameworks for AI services serve multiple functions for enterprises. They not only set out how applications or agents flow together, but they should also let administrators manage workflows and agents and audit their systems. As enterprises begin to scale their AI services and put these into production, building a manageable, traceable, auditable and robust pipeline ensures their agents run exactly as they’re supposed to. Without these controls, organizations may not be aware of what is happening in their AI systems and may only discover the issue too late, when something goes wrong or they fail to comply with regulations. Kevin Kiley, president of enterprise orchestration company Airia, told VentureBeat in an interview that frameworks must include auditability and traceability. “It’s critical to have that observability and be able to go back to the audit log and show what information was provided at what point again,” Kiley said

Grafana
Jun 9th, 2025
GrafanaCON 2025: On-demand sessions are now available!

To help simplify complex metrics exploration, Grafana Labs introduced the Metrics Drilldown app for Grafana as a no-code way to quickly get insights into your data.

Grafana
Jun 2nd, 2025
Simple cloud cost management: Grafana Labs integrates open standard FOCUS specification for cloud billing data

That's why Grafana Labs is excited to share that Grafana Labs has adopted the FinOps Open Cost and Usage Specification ( FOCUS), a community-driven, open standard for cloud billing data.

GBHackers
May 22nd, 2025
Grafana Zero-Day Vulnerability Allows Attackers to Redirect Users to Malicious Sites

To address the vulnerability, Grafana Labs has released security patches for all supported versions: 12.0.0+security-01, 11.6.1+security-01, 11.5.4+security-01, 11.4.4+security-01, 11.3.6+security-01, 11.2.9+security-01, and 10.4.18+security-01.

Grafana
Apr 21st, 2025
New in Adaptive Logs: user-facing temporary pauses, exemptions, and per-service recommendations

Grafana Labs launched Adaptive Logs last year to help you optimize your log volumes and costs in Grafana Cloud, and Grafana Labs has been hard at work ever since making improvements based on your feedback.