Obsidian security

Security Research Engineer

Palo Alto, CA Full Time
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more. 
 
Backed by top investors including Greylock, Norwest Venture Partners, and IVP, we’ve built a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Our team includes leaders who helped define the categories of endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. 
 
Now, we’re transforming how SaaS is secured—in the era of agentic AI. 
 
Today, Obsidian is trusted by global enterprises like Snowflake, T-Mobile, and Pure Storage. We protect more than 200 organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand—including many of the world’s largest Fortune 1000 and Global 2000 companies.
 
With strong global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise on the horizon, we’re scaling quickly toward long-term growth and IPO readiness. Join us as we define the future of SaaS security!

About the Role

We’re seeking a Security Research Engineer to help build the next generation of identity-focused security detections. You will research emerging attack techniques, analyze identity-driven threats across cloud and SaaS environments, and turn insights into high-fidelity detections and product improvements. As a subject matter expert, you’ll guide the evolution of our detection pipeline and core detection logic, driving meaningful impact on customer security and product direction.

What You’ll Do

Threat & Detection Research

  • Research emerging attack techniques across IdPs, SaaS, and cloud environments.
  • Analyze adversary behaviors such as credential abuse, session hijacking, privilege escalation, and persistence.
  • Share your insights with the community through blogs, whitepapers, talks, and contributions that elevate industry understanding.

Data Analysis & Signal Development

  • Analyze large volumes of identity and SaaS telemetry to identify indicators and behavioral patterns.
  • Form hypotheses and run experiments to improve detection accuracy.

Detection Engineering

  • Translate research into rules, heuristics, anomalies, and behavioral models.
  • Partner with engineering to improve detection pipeline capability and performance
  • Test detections against simulated attacks and real data.

Cross-Functional Collaboration

  • Work with product on detection priorities.
  • Partner with engineering on pipelines and telemetry quality.
  • Share findings with customer-facing teams and support investigations when needed.

What We’re Looking For

  • 2–3 years in security research, detection engineering, threat intel, or similar.
  • Experience building detections and analyzing large datasets.
  • Strong understanding of identity systems (Okta, Azure AD/Entra, Google Workspace, etc.) and authentication flows.
  • Familiarity with cloud/SaaS attack surfaces and attacker TTPs (MITRE ATT&CK, OAuth abuse, identity threats).
  • Ability to analyze logs and signals from IdPs, cloud, or SaaS apps.
  • Experience creating or validating rule-, anomaly-, or behavior-based detections.
  • Experience with scalable data pipelines (Spark or similar).
  • Familiar with Python and SQL
  • Bonus: threat simulation, red/blue teaming

Why Join Us

  • Shape core detection capabilities at an early, high-growth company.
  • Work with experienced security engineers who value creativity and practicality.
  • Directly influence product direction and customer outcomes.
  • A culture of learning, autonomy, and speed.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.  If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.

Base Salary Range
$175,000$221,000 USD