Intermediate Security Engineer, Security Incident Response Team
This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.
About the job
Responsibilities
- Lead security incident response in a 24/7 global rotation, managing incidents from detection through containment and recovery.
- Create and maintain incident response documentation, including runbooks and standard procedures.
- Conduct post-incident analysis, root-cause analysis, and lessons-learned reviews.
- Design and implement automated security processes to improve operational efficiency and reduce manual intervention.
- Identify security gaps and implement improved detection and response capabilities.
- Collaborate across teams on security capabilities and technical infrastructure projects.
Requirements
- Ability to learn and independently lead incident response processes.
- Experience with SIEM and security logging tools.
- Experience with cloud platforms such as Google Cloud and/or AWS.
- Python programming skills or strong willingness to learn.
- Strong technical documentation skills or interest in developing them.
- Proactive approach to identifying and investigating security threats.
- Interest in forensic analysis of infected hosts.
- Experience or strong interest in cloud-based security investigations.
Compensation and Benefits
- Full-time, compressed four-day work schedule with shifts running Sunday through Wednesday or Wednesday through Saturday.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
Skills
Incident Response, SIEM, Security Logging, GCP, AWS, Python, Forensic Analysis, Security Automation, Threat Detection, Technical Documentation
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Investigates and responds to security alerts, intrusions, malware, and suspicious cloud activity while providing remediation guidance. The role requires at least two years of SOC or DFIR experience and knowledge of endpoint telemetry, threat actor techniques, administration, networking, and web security.