Doppel
Applied Cyber, Detections
- Location
- US Remote, US
- Arrangement
- Remote
- Employment type
- Full-time
- Posted
- 15 July 2026 (about 2 months ago)
Checked 8 days agoApplications go to the employer, never to RoleSprint
About this role
ABOUT DOPPEL
Doppel is building the future of social engineering defense. Our AI-native platform uses agentic AI to protect executives, employees, customers, and brands from phishing, impersonation, fraud, and other AI-powered threats across digital channels. We help some of the world’s most recognized brands detect and dismantle attacker infrastructure while strengthening employee resilience through threat-informed training and simulation. By unifying Digital Risk Protection, Human Risk Management and Email Security, Doppel connects threats into a real-time intelligence graph to power faster disruption, smarter defense, and modern security awareness at scale.
Backed by leading investors including Andreessen Horowitz and Bessemer Venture Partners, and trusted by leading enterprises, Doppel is a rapidly growing Series C startup building the future of social engineering defense. Our team combines deep cybersecurity expertise, operational rigor, and startup velocity to solve some of the internet’s most urgent trust and safety challenges.
THE ROLE
At Doppel, we focus on building a culture where people feel respected, supported, and trusted to do meaningful work. We value clarity, collaboration, and solving real problems for our customers and teammates.
We are looking for an Architect, Applied Cyber, Detections to improve detection workflows, conduct ad hoc OSINT investigations, and support key customer implementations. You will optimize intelligence sourcing and brand abuse detection capabilities, partner with Product and Engineering teams, and help drive scalable platform improvements.
WHAT YOU WILL DO
- Support post sales detection operations for customers by translating risk, brand abuse, and phishing use cases into effective and scalable detection coverage across website domains, SOCMINT, and other related surface areas.
- Conduct onboarding, detection logic implementation, and sourcing workflows for select customers.
- Build, refine, and validate platform automation logic using proprietary frameworks to support alert triaging and movements.
- Investigate and conduct root cause analyses (RCAs) for missed detections, false positives, false negatives, improper alert movements, and low volume customers.
- Work alongside Customer Success Managers (CSMs), Account Executives (AEs), and Technical Account Managers (TAMs) to support ad hoc detection requests and platform configurations.
- Collaborate cross functionally with Engineering, Product, and other Solutions Architecture teams to surface platform limitations, share detection findings, and contribute ideas for process improvements.
- Stay up to date with trends, patterns, and evolving TTPs related to agentic phishing, credential theft, recruitment scams, social media impersonation, disinformation, and paid ads abuse.
WHAT WE ARE LOOKING FOR
- 3+ years of experience in OSINT investigations, threat intelligence, or detections engineering.
- 1+ years of experience conducting SOCMINT investigations.
- Experience using URL intelligence platforms and constructing complex queries (for example, URLScan, VirusTotal, or Spamhaus).
- Demonstrated knowledge of common phishing and credential theft TTPs.
- Demonstrated knowledge of common social media, paid ad, and SERP abuse patterns.
- Strong ability to support ad hoc customer requests and collaborate in cross functional discussions with Product and Engineering teams.
- Excellent written and verbal communication skills in English.
NICE TO HAVE
- A degree in cybersecurity, information assurance, intelligence studies, or data analytics.
- Experience creating advanced SERP queries (Google dorks).
- Experience using, building, or supporting agentic workflows beyond answer and response interactions (for example, Claude Code, Codex, OpenClaw, or self hosted LLM agents).
- Experience using Python for automation.
- Experience using Google Workspace.
- Experience using Jira or Linear.
WHY JOIN DOPPEL
- Compensation: $75,000 to $90,000 OTE based on location and relevant experience.
- Meaningful equity so you share in Doppel’s success.
- Remote first culture.
- Flexible PTO, comprehensive health benefits, parental leave, and more.
- A high growth environment where your work has immediate impact and visibility.
JOIN DOPPEL
Doppel is the first platform built to dismantle digital deception at scale. We scan over 150 billion entities daily and deploy continuously adaptive AI SOC agents, paired with expert human analysts, to uncover and disrupt the infrastructure behind phishing, impersonation, and online fraud before attacks can spread. Our Threat Grid turns every customer signal into shared intelligence, making each disruption smarter, faster, and more effective.
We’re not just another cybersecurity company. We’re defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and trusted by some of the world’s most recognized brands, Doppel is growing fast. If you’re driven to solve real-world problems with bold technology, we’d love to meet you.
Eligible remote locations
- US
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Ashby under the board identifier Doppel, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 15 July 2026, last checked 8 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.