24 days ago
Remote, United StatesSenior
Base Salary
$172k - $240k/yr
Responsibilities
- Own day-to-day operation of the Panther SIEM, including log-source ingestion, detection content, and alert investigation pipelines.
- Lead adoption of AI-augmented SOC tooling such as Prophet Security, Dropzone AI, or an equivalent platform.
- Triage security alerts and drive investigation and remediation with Engineering and IT stakeholders.
- Lead incident response activities including investigation, containment, and post-incident review.
- Build security automation and detection tooling to identify threats, enrich alerts, and reduce manual investigation work.
- Develop self-service log onboarding, detection proposals, runbooks, and repeatable response processes.
- Improve detection coverage using findings from offensive and proactive security work.
- Partner on cloud, infrastructure, and application security initiatives.
- Participate in the Security team’s on-call rotation and incident response.
Requirements
- At least 5 years of experience in security engineering, security operations, detection engineering, or security-focused software engineering.
- Hands-on production SIEM experience, including log-source onboarding, detection-content development and maintenance, and alert triage.
- Ability to write production-quality code for security automation and detection-as-code.
- Experience leading or substantially contributing to security incident response.
- Strong technical writing skills for design documents, runbooks, and post-incident reviews.
- Risk-based judgment for prioritizing security work, ability to navigate large codebases, and ability to reason about complex engineering systems.
- Excellent verbal communication and willingness to participate in an on-call rotation.
- Preferred: experience with Prophet Security, Dropzone AI, or equivalent AI-augmented SOC platforms, or with LLM-augmented investigation and runbook tooling.
- Preferred: experience operating cloud environments at scale, especially AWS cloud incident response.
- Preferred: endpoint forensics on Mac or Linux, detection-as-code workflows in CI/CD pipelines, and mobile adtech or high-volume SaaS experience.
Benefits
- Full-time remote work is available in approved U.S. states, with a remote-first company and hubs in Redwood City, Los Angeles, and New York City.
- Employees are expected to attend in-person project meetings, regional meetups, or company-wide gatherings at least once per quarter.
- Benefits may include medical coverage, wellness stipends, equity, and additional perks based on country of residence.