Senior Security Engineer
The Senior Security Engineer will build and operate detection and response capabilities across Mixpanel’s product, cloud, corporate, and identity environments. The role requires deep detection-as-code expertise, Google Cloud and Python proficiency, and the ability to lead EMEA incident response.
About the job
Responsibilities
- Own Detection & Response, integrating telemetry from Product, Cloud, Corporate Infrastructure, and Identity into a unified detection and response engine.
- Translate project requirements and technical scoping documents into milestones, manage task delivery, and drive cross-functional results.
- Design and implement precise, actionable alerting in Google Security Operations (SIEM/SOAR), treating detections as code and scaling them for high-volume data ingestion.
- Develop detection logic and playbooks for application-layer abuse, account takeover (ATO), and sophisticated social engineering.
- Lead security incident response during EMEA hours, including investigation, containment, and cross-functional communication.
- Develop threat intelligence capabilities by identifying relevant adversaries and translating intelligence into proactive SIEM/SOAR logic.
- Maintain the operational health and telemetry flow of SentinelOne, GCP Security Command Center, and Mimecast Incydr.
Requirements
- Experience across modern security program pillars, including Product, Cloud, and Corporate Security.
- Experience with Identity and Access Management (IAM), threat modeling, and secure code reviews.
- Deep understanding of the detection-as-code lifecycle and experience converting telemetry into actionable alerting.
- Experience building security infrastructure for high-scale SaaS environments.
- Ability to manage diverse security operations, including vulnerability and policy-violation triage and suspicious-activity investigations.
- Proficiency with Google Cloud Platform, specifically Cloud Logging, BigQuery, and Pub/Sub, for security data pipelines and visibility.
- Proficiency in Python for automated workflows and security-tool API integrations.
- Comfort using AI and large language models (LLMs) for alert enrichment, incident summarization, and code analysis.
Nice-to-haves
- Threat intelligence experience, including dark web monitoring, brand protection, and adversary tactics.
- Experience leading Security Champions initiatives or mentoring non-security teams.
- Familiarity with deception techniques such as honeytokens, canary credentials, and fake internal endpoints.
- Experience with enterprise security tools, including Endpoint Detection and Response (EDR), email security gateways, and cloud-native security command centers.
- Experience defending high-volume data ingestion and complex user-access patterns.
- Experience with vulnerability coordination platforms, automated external scanning, or bug bounty programs.
Compensation and Benefits
- Total target cash compensation: £103,000–£139,500 GBP, including base and variable compensation.
- Eligible for equity consideration.
- Medical, vision, and dental insurance coverage.
- Mental wellness benefit.
- Generous vacation policy and additional company holidays.
- Enhanced parental leave.
- Volunteer time off.
Skills
Google Security Operations, SIEM, Soar, Detection As Code, Python, GCP, Cloud Logging, BigQuery, Pub/Sub, IAM, Threat Modeling, Secure Code Review, Sentinelone, Mimecast Incydr, Threat Intelligence
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.