5 months ago
Base Salary
$172k - $250k/yr
Responsibilities
- Build and maintain a SIEM that collects and analyzes logs from corporate and production systems.
- Write and deploy detections and alerts for malicious behavior.
- Design and deploy canary tokens and early-warning mechanisms.
- Investigate security incidents end to end, including malware analysis, exfiltration assessment, and timeline reconstruction.
- Create incident-response runbooks to scale response capabilities.
- Partner with IT to define and enforce employee-device security standards, including endpoint protection, managed-device requirements, OS compliance, and VPN access controls.
- Drive the proof of concept and implementation of Zero-Trust VPN and other corporate security infrastructure.
- Provide security guidance and advisory support to non-engineering teams.
Requirements
- At least 5 years of experience in security engineering, detection engineering, or a closely related field.
- Hands-on experience building or maintaining SIEM infrastructure and writing detection rules.
- Experience with endpoint security tools such as CrowdStrike or similar EDR platforms.
- Strong Python engineering skills and experience shipping production code reviewed with software engineering teams.
- Experience conducting security incident investigations, including malware analysis, log review, timeline reconstruction, and threat modeling.
- Experience with corporate security controls, identity management, endpoint protection, and access-control enforcement.
- Preferred experience with SIEM/SOAR platforms such as Elastic or Splunk.
- Preferred familiarity with identity platforms such as Okta.
- Preferred understanding of OAuth, Yubikey, and Passkey authentication technologies.
- Preferred experience with Zero-Trust network architecture or VPN implementation.
- Preferred use of AI coding tools to build or automate security workflows.
- Preferred experience working on a small security team or in a fast-paced startup environment.
- Preferred familiarity with AWS and cloud-native security tooling.
Benefits
- Remote work from anywhere in Canada or the United States, subject to country eligibility.
- Remote work reimbursement, medical, dental, and vision coverage, equity refreshers, paid time off, and employee assistance programs.
- Benefits are country-specific and may vary.
- Availability is expected during coordination hours, Monday through Friday from 9 a.m. to 3 p.m. Pacific Time.
- Final candidates undergo identity verification and a comprehensive background check before onboarding.
About Quora
Quora builds a global Q&A platform where people share and discover knowledge, and Poe, a multi-model AI chat app that lets users and creators build and monetize bots. Its business model includes advertising and subscriptions such as Quora+ and Poe. Privately held, founded in 2009 and headquartered in Mountain View, California, it serves a worldwide audience with hundreds of millions of monthly visitors.
