Haystack
← Back to Jobs
Engineering
DS

Customer Success Engineer (CSE)

Daylight SecurityUnited States🇺🇸United StatesPosted Sep 28, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States, United States
Posted
6 hours ago
LinearCustomer SuccessOnboarding

Job Description

Daylight delivers Managed Agentic Security Services (MASS), MDR, threat hunting, and a security data lake, through a fundamentally different architecture than traditional security providers.

Our agentic platform runs the full cycle from detection to response, informed by security experts from IR and threat hunting backgrounds. The platform learns your environment and investigates alerts; experts validate decisions, optimize detections, and take over during incidents.

The result: security teams move from firefighting to strategic work.

We're looking for a Customer Success Engineer to own the technical relationship with a portfolio of customer security teams, from onboarding through steady-state operation. You'll be the go-to technical partner for our customers' security engineers, answering most questions on the spot and serving as first-line response across shared channels. This is not a ticket-routing role: every Daylight account is a live integration project. You'll work alongside a Customer Success Manager who owns the commercial relationship, while you own the technical one.

Responsibilities

  • Execute onboarding: run the integration checklist against contracted scope, set up escalation paths and on-demand paging, and drive accounts to silent-mode exit with status visible to the customer
  • Run stale and non-stale activation tracks separately, keeping onboarding moving without CSM follow-up
  • Serve as live first-line technical response in shared Slack or Teams channels and the Pylon queue
  • Confirm integrations are live, sending data, and that the response policy is active; catch expiring tokens, lapsed permissions, and unannounced new tooling
  • Run working sessions with customer security engineers on escalation and response policies, test notification rules end to end, and wire case data into their ticketing until analysts adopt it
  • Tune detections, false escalations, and the end-to-end case experience
  • Explain case dispositions clearly enough to expand response scope from investigations to quarantine and isolation
  • Maintain Pylon knowledge base articles, service differentiator docs, escalation policies, and troubleshooting playbooks
  • File field observations in Linear so Product and the SOC see what you see
  • Deliver QBR technical content to the CSM ahead of the deck
  • Escalate cleanly to the Solutions Architect pool when needed, with the investigation already done
  • Travel roughly quarterly for customer visits, company events, or conferences

Requirements

  • 4+ years in a customer-facing technical role such as CSE, TAM, Solutions Engineer or Architect, or Implementation Engineer
  • Background in cybersecurity, ideally with experience in security operations, detection and response, MDR, or SIEM/EDR tooling
  • Startup or high-growth experience where process is still being built
  • Ability to hold a technical conversation with a customer's security engineer independently
  • Hands-on scripting experience
  • Working knowledge of APIs, SaaS integrations, log pipelines, and modern cloud architecture
  • Ability to read logs, trace a workflow, isolate root causes, and communicate findings clearly
  • Strong prioritization and written communication skills across multiple accounts
  • Experience with structured onboarding and building a customer-facing knowledge base, an advantage

Similar jobs