Skip to main content
frontier

Doppel hires 18 roles at $356k median as AI impersonation attacks surge

By Priya Nair

What Open Roles Reveal About Doppel's Hiring

Doppel lists 17 salaried roles on its job board with a typical salary band of $96k–$356k (median $260k). The board shows six specific engineering openings across detection, infrastructure, and simulation:

Role Location Salary Band
Machine Learning Engineer, Detection Toronto 183,000–429,390 CAD
Machine Learning Engineer, Detection New York 150,000–365,000 USD
Software Engineer, Detection Toronto 157,000–367,000 CAD
Software Engineer, Infrastructure San Francisco 150,000–400,000 USD
Software Engineer, Infrastructure Toronto 169,000–396,360 CAD
Software Engineer, Simulation Toronto 150,000–365,000 CAD

One role, Machine Learning Engineer, Detection in Toronto, was added in the past seven days at the top of the band.

Doppel's architecture runs a three-step loop: agentic AI ingests signals across traditional and emerging channels, correlates them into a unified Threat Graph, then automates takedowns and training actions that feed back into the graph. The company analyzes more than one billion indicators daily and reports a median takedown time under ten hours for domains, social media profiles, and paid ads, Doppel Vision's data shows.

Two detection ML engineers (one in Toronto, one in New York) operate at the ingestion layer. A detection software engineer in Toronto builds pipelines that turn raw signals into structured threat intelligence. The company emphasizes human-readable detection logic: a July 2026 LinkedIn post called black-box models "an operational nightmare for SOCs" and argued that scaling defenses without inflating headcount demands explainable outputs.

Infrastructure roles carry the highest compensation bands. The platform automates takedowns across registrars, social platforms, ad networks, and telcos, each with its own API contracts, rate limits, and workflows. The site promises "effortless integration, infinite scalability" and "no costly upgrades."

Simulation is a distinct pillar. A simulation engineer in Toronto owns the engine that generates multi-channel phishing scenarios — email, Slack, Teams, vishing, deepfake video — tailored to each organization's threat profile. The product page describes simulations "designed to reveal real vulnerabilities, build response readiness, and feed directly into your defense strategy." That feedback loop, from simulation result back into the Threat Graph, differentiates Doppel from the static phishing tests it publicly dismisses.

The AI Managed Service for Human Risk Management, announced generally available July 30, 2026, lets security teams "set goals and guardrails once, while agentic AI designs, runs, and continuously improves their security awareness programs." Building that guardrail layer — defining what the agent may and may not do, then proving it stays within bounds — sits at the intersection of ML, product safety, and security operations.

The Talent Vacuum AI Security Created

Traditional cybersecurity hiring assumes the threat arrives as code: malware, exploit kits, credential stuffing. Defenders build signatures, write rules, tune SIEMs. That model strains when the attack vector is a deepfake vishing call referencing the target's actual project data, cloned from a CEO's voice and timed to a Friday afternoon VAT filing. This is the exact scenario Beck McCauley, a chartered psychologist with a defense background, described on Razorwire Cybersecurity after nearly falling for it herself.

Richard Cassidy, CISO at Rubrik, put the acceleration bluntly on the same panel: deepfake vishing surged over 1,600 percent in the first half of the prior year. Trend Micro research showed AI has turned OSINT from a manual effort into a fully automated pipeline; attackers now move from LinkedIn profiles to fully tailored attack scenarios in 30 minutes. The medium changed; the psychology — authority, urgency, scarcity, liking, reciprocity, social proof — hasn't moved an inch since Cialdini mapped it in 1984.

The asymmetry is structural. Attackers engineer the conditions in which decisions get made. They create time pressure, ambiguity, signals of authority. They control the narrative and introduce information in sequence. The defender receives fragmented inputs, doesn't know what's relevant, often doesn't realize a decision point exists until after the transfer executes. McCauley described it as the difference between a designed environment and a disruptive one. Traditional security awareness training (annual phishing simulations, policy acknowledgments) assumes a static threat. It cannot counter an adversary that generates context-aware, real-time manipulation at machine speed.

Cassidy called social engineering "a human problem that cybersecurity has inherited." Defending against it requires people who can translate behavioral psychology into detection logic, then into real-time countermeasures.

Doppel's open roles reflect that translation layer. The board lists Machine Learning Engineers in Detection alongside Software Engineers in Simulation and Infrastructure, not "security analysts" or "threat hunters." The work sits at the intersection of three domains: building models that detect synthetic media in streaming audio, simulating attack paths that mirror how adversaries weaponize Cialdini's principles, and deploying infrastructure that responds in the same window attackers operate in.

Traditional cybersecurity programs produce neither. Computer science curricula treat human factors as electives. Psychology programs don't teach adversarial robustness. The talent pool exists in fragments: red teamers who studied behavioral economics, ML researchers who worked on deepfake detection, former trust-and-safety engineers from platforms that fought coordinated inauthentic behavior. Doppel's roles represent a bet that the intersection can be hired for directly, not assembled from pieces.

The intersection of adversarial machine learning, behavioral psychology, and real-time security operations has no established talent pipeline. Universities don't graduate "AI social engineering defense engineers." Certifications don't exist for building agentic systems that simulate attacker cognition to preempt manipulation. Doppel's roles, spanning machine learning detection, simulation engineering, and infrastructure across Toronto, San Francisco, and New York, sit in a labor market vacuum where the required hybrid expertise simply doesn't exist at scale.

Competitors for this talent don't look like traditional security vendors. They're frontier AI labs building autonomous agents, red-team contractors simulating nation-state influence operations, and trust-and-safety teams at platforms fighting synthetic media at scale. Each pulls from the same shallow pool: researchers who've published on prompt injection, engineers who've deployed LLM guardrails in production, psychologists who've modeled credential harvesting workflows. Doppel's differentiation ("real-time disruption" rather than "detection and inbox scoring," per its LinkedIn positioning) demands talent that can ship adversarial agents, not just classify threats.

The board data reveals a telling pattern: roles split between Detection (ML and software), Simulation, and Infrastructure. That taxonomy maps directly to the product's operational loop (simulate attacker behavior, detect manipulation in production, disrupt the kill chain), and each pillar requires a different hybrid profile. Simulation engineers need game-theory fluency and human-factors modeling. Detection engineers need streaming inference optimization and adversarial robustness. Infrastructure engineers need multi-region latency budgets for agent-to-agent combat. No single background covers all three.

The one role recently added, a Toronto detection ML engineer role at the band's ceiling, suggests the detection pillar is the current bottleneck. That aligns with the shift from product development to enterprise deployment: detection must generalize across customer environments, attacker variations, and evolving LLM capabilities without false-positive fatigue. The salary ceiling reflects the scarcity of engineers who've shipped production detection systems against adaptive adversaries, not just static benchmarks.

The market won't solve this gap through volume. It will solve it through poaching, upskilling, and, for the few companies that can articulate the mission, attracting researchers who want their work to confront AI-powered manipulation directly rather than optimize ad click-through. Doppel's positioning as the platform that "dismantles attacker infrastructure" rather than "scores inbox risk" is its recruiting pitch. Whether it converts depends on whether the roles represent a coherent team design or a wish list the market can't fill.

How a Product Pivot Rewrote the Hiring Plan

Doppel was founded in 2022 on the premise that detection alone had already failed. The company's own messaging makes the distinction blunt: "Unlike traditional systems that stop at detection and inbox scoring, Doppel delivers real-time disruption" (LinkedIn, August 2026). That sentence summarizes a product architecture built around automated takedowns of malicious sending infrastructure, lookalike domains, and rogue profiles, executed at machine speed across email, social, ads, telco, dark web, and crypto channels.

The platform unifies Digital Risk Protection, Human Risk Management, and Email Security into a single graph-driven intelligence layer that links signals across platforms, brands, and infrastructure to expose campaigns in real time. That unification is the product, and it dictates the hiring profile.

Machine Learning Engineer, Detection appears in both Toronto and New York. Software Engineer, Detection sits beside it in Toronto. These require engineers who can build detection logic that is human-readable, a direct response to the "operational nightmare for SOCs" caused by black-box models, as the company noted in a July 2026 LinkedIn post. The same post argued that scaling defenses against automated threat volume without that.

Infrastructure hiring tells the other half of the story. Software Engineer, Infrastructure roles are open in San Francisco and Toronto with salary bands reaching $400,000 and CAD 396,360 respectively. The scale — billions of URLs scanned daily, takedowns executed across registrars, hosting providers, social platforms, and ad networks in under ten hours — demands engineers who have built distributed systems that survive partial failures without losing the chain of custody for a takedown request.

The Simulation Engineer role in Toronto exists because Doppel's agentic AI engine automates not just correlation and prioritization but also training and simulation, "continuously getting smart" per the company's site. That service makes the hiring implication explicit: building the guardrail layer is a distinct engineering discipline sitting at that intersection.

The product shift also redefines what "detection" means. Traditional email security scores messages. Doppel's graph-driven approach sees the campaign infrastructure behind the message. That requires engineers who understand threat actor tooling (domain generation algorithms, bulletproof hosting, proxy networks, crypto payment rails) and can model the economics of takedown. The company's own phrasing: "Attackers see one attack chain, from the infrastructure they build to the inbox they land in. Most defenses see three separate problems" (LinkedIn, August 2026). Closing that gap is why the detection and infrastructure roles are hired in parallel, not sequence.

The hiring surge across these profiles is not a scaling exercise. It is a capability build for a product category that did not exist three years ago. The engineers who join now will not maintain a detection engine. They will build the countermeasures that make the attack unprofitable.

Inside the Screen: What Doppel Actually Tests

CTO Rahul Madduluri has said publicly that his teams "scan billions of URLs every day, develop advanced AI and machine learning systems, and build infrastructure capable of operating at extraordinary scale" (LinkedIn, August 2026). The same post mentions deep research and reinforcement fine-tuning as critical to staying ahead.

The Japan hire signals geographic depth. Hideki Ushigome, former Recorded Future and Swimlane executive, joined as Country Manager for Japan in August 2026 with 25 years of cybersecurity scaling experience. A LinkedIn post from July 30 notes findings from a honeypot project in Japan: 67% of malicious lures arrived Monday or Friday, 47% at 9 a.m. or noon JST, with financial services and payments making up 67.8% of impersonated brands.

Black-box models are explicitly called out as an operational nightmare for SOCs. Doppel's marketing and technical leads repeat this. The product's investigation view surfaces human-readable logic for every detection and investigation.

Daniel Pyykonen, Head of Platform Security at Notion, said Doppel turned him from "stressed about all of the looming threats" to "just a chill guy" (Doppel customer story). That outcome, reduced cognitive load for defenders, is the north star the company references.

The five-stage Social Engineering Attack Chain (setup, reconnaissance, weaponization, delivery, exploitation) maps to detection, infrastructure, simulation, and threat intelligence (Doppel website). The common thread across every role: Doppel builds for the attack chain, not the alert queue.


Working in frontier tech? Zero G Talent tracks the openings: see every open Doppel role, browse frontier tech jobs, the companies hiring, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs