Applied Cyber, Email Security (Detection Engineering)
Boost your chances before you apply.
Doppel
US
Summary
You will investigate complex email threats and detection failures to develop scalable detection logic and AI-driven security capabilities. You will collaborate with product and engineering teams to validate signals and automate investigative workflows.
Job Description
About Doppel
Doppel is building the future of social engineering defense. Our AI-native platform uses agentic AI to protect executives, employees, customers, and brands from phishing, impersonation, fraud, and other AI-powered threats across digital channels. We help some of the world’s most recognized brands detect and dismantle attacker infrastructure while strengthening employee resilience through threat-informed training and simulation. By unifying Digital Risk Protection, Human Risk Management and Email Security, Doppel connects threats into a real-time intelligence graph to power faster disruption, smarter defense, and modern security awareness at scale.
Backed by leading investors including Andreessen Horowitz and Bessemer Venture Partners, and trusted by leading enterprises, Doppel is a rapidly growing Series C startup building the future of social engineering defense. Our team combines deep cybersecurity expertise, operational rigor, and startup velocity to solve some of the internet’s most urgent trust and safety challenges.
At Doppel, we focus on building a culture where people feel respected, supported, and trusted to do meaningful work. We value clarity, collaboration, and solving real problems for our customers and teammates.
The Role
You’ll investigate the hardest email threats and detection failures, then turn what you learn into detections, evals, AI behavior, and product capabilities that scale across every Doppel customer. As our technology learns to handle today’s problems, you’ll move up the complexity curve to solve the next ones.
What You Will Do
-
Own detection problems end-to-end — from emerging TTP or FN → investigation → detection hypothesis → validation → production coverage → measurement.
-
Use AI as a force multiplier — build evals, supervise model behavior, use coding agents aggressively, and automate repetitive investigative work.
-
Partner with Product and Engineering on signals, detection logic, edge cases, and validation.
-
Work with customers and GTM on detection gaps, real-world TTPs, and platform behavior.
-
Turn tooling, threat-intelligence partnerships, and provider relationships into new signals and detection capabilities.
Required Qualifications
-
Bring deep practitioner judgment from one or more of detection engineering, SOC/IR, threat intelligence/OSINT, or email/messaging security; range across multiple areas is a major plus.
-
Take messy detection failures from “something’s off” to root cause — prove what matters in the data and turn FP/FN cases into durable fixes.
-
Think like both attacker and defender across phishing, BEC, impersonation, credential theft, ATO, and evolving social-engineering TTPs.
-
Turn expert judgment into detection logic, evals, tests, requirements, and systems that scale beyond a single investigation or customer.
-
Thrive at the intersection of security, AI, product, and customers — challenge assumptions, use coding/AI agents aggressively, and move fast through ambiguity.
Nice to Have
-
SEG/email-security depth: SPF, DKIM, DMARC, headers, mail flow, and sender identity.
-
Experience with M365/Exchange Online, Google Workspace, or email-security APIs.
-
Detection-as-code, eval datasets/labeling, model benchmarks, or LLM/ML security systems.
-
Built agentic security workflows, autonomous triage, or LLM evaluation systems.
-
Experience with Agentic SOC, SIEM/TI tooling, and threat-intelligence provider/vendor partnerships.
Why This Role
-
Shape the product, not just operate it. You work on real emerging attacks and turn practitioner judgment into detections, AI behavior, and product capabilities alongside Product, Engineering, AI/ML, customers, and ecosystem partners.
Why Join Doppel
-
Compensation: $120,000-$180,000 OTE, based on location, experience, and demonstrated expertise
-
Meaningful equity so you share in Doppel's success
-
Remote-first culture
-
Flexible PTO, comprehensive health benefits, parental leave, and more
-
A high-growth environment where your work has immediate technical and customer impact
Join Doppel
Doppel is the first platform built to dismantle digital deception at scale. We scan over 150 billion entities daily and deploy continuously adaptive AI SOC agents, paired with expert human analysts, to uncover and disrupt the infrastructure behind phishing, impersonation, and online fraud before attacks can spread. Our Threat Grid turns every customer signal into shared intelligence, making each disruption smarter, faster, and more effective.
We’re not just another cybersecurity company. We’re defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and trusted by some of the world’s most recognized brands, Doppel is growing fast. If you’re driven to solve real-world problems with bold technology, we’d love to meet you.
In the era of AI, knowing what’s real is harder than ever.
Social engineering threats are sophisticated, multi-channel campaigns. They lurk in your inbox, compromise your email channels, and weaponize fake profiles across social networks to deceive and defraud your people and your brands.
Doppel is the agentic social engineering defense platform built to fight AI with AI. Unlike traditional systems that stop at detection and inbox scoring, Doppel delivers real-time disruption. We secure the inbox while executing automated takedowns on malicious sending infrastructures, lookalike domains, and rogue profiles at machine speed.
By unifying Digital Risk Protection, Human Risk Management, and Email Security onto a single centralized platform, Doppel shuts down threats at their source. We safeguard every channel, move faster than attack speed, and turn global threat intelligence into a compounding network effect that keeps you ahead of the curve.
Backed by Bessemer Venture Partners, a16z, George Kurtz - CEO, CrowdStrike, South Park Commons, Strategic Cyber Ventures, Aurum Partners, a group of athlete investors led by WNBA players Nneka Ogwumike, Breanna Stewart, and Kelsey Plum, who joined the round through the a16z Cultural Leadership Fund, Script Capital, 9Yards Capital, Sozo Ventures, NTT DOCOMO Ventures, and SVAngel.
Founded
2022
Company size
201-500 employees
Industry
Technology, Information and Internet
Org type
Privately Held
In the era of AI, knowing what’s real is harder than ever.
Social engineering threats are sophisticated, multi-channel campaigns. They lurk in your inbox, compromise your email channels, and weaponize fake profiles across social networks to deceive and defraud your people and your brands.
Doppel is the agentic social engineering defense platform built to fight AI with AI. Unlike traditional systems that stop at detection and inbox scoring, Doppel delivers real-time disruption. We secure the inbox while executing automated takedowns on malicious sending infrastructures, lookalike domains, and rogue profiles at machine speed.
By unifying Digital Risk Protection, Human Risk Management, and Email Security onto a single centralized platform, Doppel shuts down threats at their source. We safeguard every channel, move faster than attack speed, and turn global threat intelligence into a compounding network effect that keeps you ahead of the curve.
Backed by Bessemer Venture Partners, a16z, George Kurtz - CEO, CrowdStrike, South Park Commons, Strategic Cyber Ventures, Aurum Partners, a group of athlete investors led by WNBA players Nneka Ogwumike, Breanna Stewart, and Kelsey Plum, who joined the round through the a16z Cultural Leadership Fund, Script Capital, 9Yards Capital, Sozo Ventures, NTT DOCOMO Ventures, and SVAngel.
Founded
2022
Company size
201-500 employees
Industry
Technology, Information and Internet
Org type
Privately Held