JobTarget Logo

Senior Software Engineer, Investigations & Cases in Denver, Colorado at Todyl, Inc.

NewJob Function: Information Technology
Todyl, Inc.
Denver, Colorado, 80202, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Senior Software Engineer, Investigations & Cases

Security Platform Engineering · Atlanta, Denver, Remote · Open

About Us

At Todyl, we are on a mission to protect small and medium-sized businesses from ever-changing cyber threats. The Todyl platform fully integrates threat, risk, and compliance management to provide exceptional and affordable unified cybersecurity solutions to MSPs (Managed Service Providers) and their end customers.

At the end of the day, we're here to keep our partners and customers safe and help them manage the risks and comply with regulations. Protecting others requires a team that works together with trust and cares deeply about carrying out our mission.


About the Role

We are looking for a Senior Software Engineer to build the systems our analysts and partners live in — the investigation surface where our SOC works alerts, the case that carries a finding to the partner, and the automation that moves work between them. A detection firing is the start of the job. Everything after it happens in your systems.

This is a hands-on build role. Most of your week is building — designing services, shipping them, and carrying the operational half, on-call included. You will not be writing detection content, which Detection Engineering owns, or setting analyst practice, which our Detection & Response Operations lead owns. They decide how alerts get worked. You own the system they get worked in.

This role reports to the Senior Manager, Security Platform Engineering, and can be based in our Atlanta or Denver offices or remotely within the US. You will own services across Investigations, Cases, and the automation between them, and you will work directly with our SOC — they are the people using what you build, on every shift, and the fastest way to know whether a change landed is to ask them.

Key Responsibilities
  • Investigation Surface: Build and evolve the tooling our analysts use to triage and investigate — pivoting across telemetry, gathering evidence, and recording what they found. Spend enough time with analysts to know where the workflow actually hurts.
  • Alert-to-Case Lifecycle: Build and own services along the path from signal to case to resolution — state, ownership, handoff across shifts and sites, and the audit trail. Make the case surface something a partner reads and immediately understands.
  • Response Automation: Build response actions and playbook capabilities on our SOAR and workflow layer, including the approval gates that keep a person in the loop where one belongs, and the checks that catch AI-assisted output before a partner sees it.
  • Integrations: Build partner-tool integrations and sharpen the framework underneath them as you go, so the next integration is cheaper than the last rather than another entry on a pile.
  • Operability: Instrument what you build so failures surface before partners feel them. Own latency, throughput, and the failure modes that only appear at multi-tenant scale, and join the on-call rotation for your services.
  • Craft & Review: Write the design docs for your own work and bring them to review early. Raise the bar around you through code review and pairing, and mentor engineers earlier in their careers.
QualificationsValues Fit
  • Extreme ownership, particularly when things go wrong or aren't completed on time.
  • Intrinsic drive for growth; self-motivated, always learning, and focused on raising the bar for self and team.
  • Strong bias for action with impact; make tough decisions quickly, measure results, and iterate with clarity to move the mission forward.
Who You Are
  • Experience: 8+ years building and operating production software, including 4+ years writing backend services in Go. You have carried production on-call for systems you designed.
  • Distributed Services: Demonstrated experience designing, building, and operating services in a distributed, event-driven architecture — data model, API, asynchronous processing, and behavior under load. You have drawn service boundaries and lived with the consequences.
  • State & Correctness: Hands-on with systems where the hard problem is state rather than throughput — entity lifecycles, ownership transfer, concurrency between users, idempotency under at-least-once delivery, and audit trails that stay defensible months later.
  • Streaming & Analytical Production experience with an event streaming platform (Redpanda, Kafka, or equivalent) and a columnar analytical store (ClickHouse or equivalent). You can explain the access patterns each is suited to and design accordingly.
  • Operator-Facing Systems: You have built and owned an application that professional operators use as their primary working surface. You can tell a feature request from a workflow problem, and you have shipped changes that measurably cut the time a task takes.
  • Integrations & Automation: Experience building and maintaining integrations against third-party APIs you do not control — retry strategy, rate limiting, partial failure, and schema drift. Familiarity with SOAR or workflow-automation platforms (Torq, Tines, XSOAR, Swimlane, or a homegrown equivalent) and with PSA and RMM tooling in the MSP channel is a strong plus.
  • Security Operations Domain: Working knowledge of detection and response — how a detection becomes an alert, how an analyst triages and investigates it, and why false positives are expensive. Prior work at a security vendor, MDR, MSSP, or on an in-house SOC tooling team.
  • Partner Awareness: Familiarity with MSP/MSSP or multi-tenant environments, where one customer's volume can affect another.
  • Education & Certifications: Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience. Contributions to open security or detection tooling are a plus.

The anticipated base salary range for this position is $160,000-190,000 annually, with final compensation determined based on experience, skills, qualifications, and other job-related factors.

Job Location

Denver, Colorado, 80202, United States

Frequently asked questions about this position

Similar Jobs In Denver, Colorado

NewHot Job

Web Order Processor

Productivity Inc
Littleton, Colorado
Hot Job

Outside Sales Rep - Document Solutions

ARC Document Solutions
Denver, Colorado

Senior Software Engineer

GRVTY
Aurora, Colorado

Software Engineer

Stored Energy Systems
Longmont, Colorado

Software-focused Systems Engineer - 1018

Quantinuum
Broomfield, Colorado
Apply For This Position

Apply Now