Detection and Response Engineer

TLDR

Build and evolve Detection & Response capabilities to ensure the security of global travel and expense platforms by managing detection rules and automating incident responses.

At Navan, you will build and evolve Detection & Response (D&R) capabilities across our infrastructure, products, and research environments. This role focuses on high-signal detection and reliable operational response to ensure the security of our global travel and expense platform.

What You’ll Do:

  • Detection Engineering: Build and manage the lifecycle of detection rules, focusing on measurement/quality loops (coverage, precision, latency) and safe rollout patterns.
  • Automated Response: Build workflows that reduce toil (triage, enrichment, containment) using SIEM tools (e.g., Splunk, Sentinel), EDR/XDR, and automation to improve time-to-contain.
  • Incident Management: Actively participate in the Incident Response lifecycle. You will detect, analyze, and remediate security threats and participate in a scheduled on-call rotation.
  • Secure Architecture: Partner with infrastructure owners to ensure new systems ship with the right telemetry, encryption, authentication, and response playbooks from day one.
  • Visibility & Governance: Drive visibility across endpoints, identity, SaaS, and cloud; identify gaps in IAM and vulnerability management and advocate for direct fixes.
  • Emergent Threats: Evaluate and respond to frontier security concerns, such as detection strategies for automated agents operating across infrastructure at scale. 

What We’re Looking For:

  • Technical Foundation: Deep knowledge of network, cloud, and endpoint security, with hands-on experience in firewalls and vulnerability management.
  • Operational Experience: Direct experience in Incident Response (IR). You are comfortable performing log analysis, threat hunting, and forensics while applying the MITRE ATT&CK framework.
  • Threat Modeling: Ability to evaluate new features, identify "what could go wrong," and turn those risks into concrete telemetry and response requirements.
  • Multi-Cloud Proficiency: Experience across major platforms (Azure, AWS, GCP, OCI) and the ability to design cloud-agnostic detection approaches.
  • Automation Mindset: Passion for replacing repetitive work with automation and scripting; you enjoy using AI/agent tooling to accelerate investigations.

TripActions builds a comprehensive corporate travel and expense management platform that empowers businesses with visibility and control over their spending. Targeted at mid-market companies, it offers seamless integration and innovative solutions designed to enhance the travel experience while optimizing costs. Distinctively, TripActions combines multiple functionalities into one app, making it easier for organizations to manage travel and expenses in a streamlined manner.

View all jobs
Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Engineer Q&A's
Report this job
Apply for this job