Talent Apply
Log in
All jobs
H

Principal Software Engineer, Security, Detection & Response

HubSpot
Remote - USA
RemoteUSD 266,200 - 425,900 / year

About this role

Job title: Principal Software Engineer, Security, Detection & Response

About the Role HubSpot is seeking a Principal Software Engineer to shape and deliver advanced detection engineering, threat intelligence, and incident response solutions for the platform. You will influence the technical direction, implement security practices, and lead high-impact efforts that strengthen defenses and resilience.

What You'll Do

  • Lead the development of strong detection foundations and response frameworks to advance HubSpot’s security posture.
  • Drive the development of automated detection systems and prioritize mitigations based on current threats and coverage gaps.
  • Partner with engineering teams to supply data for purple team exercises and implement practical risk mitigations.
  • Guide architectural decisions for corporate security logging infrastructure and SIEM.
  • Contribute code to security automations, review designs for detection reliability, and mentor engineers to champion detection-in-depth.
  • Provide threat intelligence and incident response expertise, ensuring products meet guardrails and customer trust needs.
  • Support incident response by aiding investigations, understanding attacker behaviors, and anticipating future actions.
  • Work with product managers and legal/privacy to embed incident response standards like NIST and SANS into lifecycle.
  • Produce actionable intelligence by filtering and correlating data from indicators of compromise (IOCs) using Splunk and CrowdStrike.
  • Evaluate customer impact on threats and maintain relationships with industry contacts for intelligence sharing.

What We're Looking For

  • 10-15 years of experience in software development and information security, focusing on detection engineering, threat intelligence, and incident response.
  • Proven experience designing automated detection systems and managing large-scale security logging infrastructure (e.g., Splunk, SIEM).
  • Expert knowledge of endpoint and network detection (EDR/SASE); hands-on with CrowdStrike Falcon for investigation and response.
  • Deep understanding of incident response methodologies and frameworks such as NIST 800-61 and SANS; ability to lead high-severity CritSits.
  • Demonstrated experience correlating diverse telemetry (identity, cloud, network) to detect post-entry behavior and contain threats quickly.
  • Experience ingesting Indicators of Compromise (IOCs) and mapping actor techniques to STIX/TAXII.
  • Excellent communication skills, with the ability to articulate complex threat landscapes to technical and non-technical audiences.
  • Relevant industry certifications (e.g., GCIH, GCFA, CISSP, or vendor-specific EDR certifications).

Compensation & Benefits

  • Annual Cash Compensation Range: $266,200—$425,900 USD; base salary plus on-target commission and annual bonus targets; equity plan with RSUs for eligible roles.
  • Some roles may be eligible for overtime pay.
  • HubSpot’s equity plan with RSUs and a comprehensive benefits package; HubSpot values transparency and fair compensation.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →