
Quora is a privately held, "remote-first" company. This position can be performed remotely from anywhere in Canada or the United States.
About Quora
Quoraβs mission is to grow the world's collective intelligence. To do so, we have two platforms:
- Quora: A global knowledge sharing platform with millions of monthly unique visitors.
- Poe: A platform providing millions of global users with one place to chat, explore, and build with a wide variety of AI language models.
This role will be supporting both our Quora and Poe products.
About the Role
Quora's Security team is responsible for protecting the company's critical assets from external threats and insider risks. We are looking for a Detection & Corporate Security Engineer to strengthen preventative and detection capabilities across corporate and production environments. You will build and maintain detection systems while owning corporate security controls that protect our employee fleet and internal infrastructure.
Responsibilities
- Build and maintain a SIEM to collect and analyze logs from across corporate and production systems; write and deploy detections and alerts.
- Design and deploy canary tokens and early warning mechanisms to detect threats.
- Investigate security incidents end-to-end (malware analysis, exfiltration assessment, timeline reconstruction) and build runbooks.
- Partner with IT to define and enforce security standards across the employee device fleet (EDR, OS compliance, VPN access controls).
- Drive the PoC and implementation of Zero-Trust VPN and corporate security infrastructure.
- Provide security guidance and advisory support to non-engineering functions.
Minimum Requirements
- Availability for meetings and impromptu communication during Quora's coordination hours (Mon-Fri: 9am-3pm Pacific Time).
- 5+ years of experience in security engineering, detection engineering, or a closely related field.
- Hands-on experience building or maintaining SIEM infrastructure and writing detection rules.
- Experience with endpoint security tools (e.g., CrowdStrike or similar EDR platforms).
- Strong Python engineering skills with a track record of writing production code.
- Experience conducting security incident investigations and threat modeling.
- Experience with corporate security controls, identity management, and access control enforcement.
Preferred Requirements
- Experience with SIEM/SOAR options such as Elastic/Splunk.
- Familiarity with identity platforms such as Okta and authentication technology (OAuth, Yubikey, Passkey).
- Experience with Zero-Trust network architecture or VPN implementation.
- Demonstrated use of AI coding tools to build or automate security workflows.
- Experience in a small security team or fast-paced startup environment.
- Familiarity with AWS and cloud-native security tooling.
Timezone overlap
UTC-8β-4
Benefits
Equity, Health, Dental, Vision, PTO, Home office, Mental health
Open to
NA
Sign in to track applications and earn points.