2 days ago
Responsibilities
- Own response playbooks and investigation methodologies for security automation platforms.
- Design and implement autonomous incident-response workflows from initial triage through root-cause analysis and remediation.
- Build automated DFIR capabilities for log correlation, forensic evidence collection, and threat eradication at cloud scale.
- Make security-domain decisions about investigation, action, and remediation while partnering with software development engineers on platform scalability.
- Participate in an on-call rotation focused on automation health and security escalations.
- Mentor engineers on security expertise and incident-response best practices.
- Maintain end-to-end ownership of production systems from design through deployment and operational excellence.
Requirements
- Non-internship experience with scripting, programming, and security code review in a common programming language.
- Non-internship experience troubleshooting systems issues, analyzing logs, or automating complex tasks with command-line tools.
- Experience identifying security issues and risks and developing mitigation plans.
- Non-internship industry experience identifying security vulnerabilities, attack patterns, and remediation techniques.
- Experience as a mentor, technical lead, or engineering team lead.
- Preferred experience generating automated metrics to measure service and program effectiveness and consistency.
- Preferred experience in security operations, risk management, and incident response.
- Preferred experience designing or building automated security-response workflows, playbooks, or orchestration systems such as SOAR or custom pipelines.
Benefits
- Flexible, distributed working culture with core collaboration hours designed to respect personal time.
- Inclusive work environment that values diverse backgrounds and perspectives.
- Participation in an on-call rotation is part of the role.