Skip to content
TwilioTwilio

Security Engineer, Incident Response

Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.

About the job

Responsibilities

  • Lead and support responses to security events and incidents across global infrastructure, services, and applications.
  • Document incidents and projects; create runbooks and standard operating procedures.
  • Collaborate across teams to address threats and security challenges.
  • Drive improvements identified from security events and incidents.
  • Own the security incident lifecycle, participate in on-call rotations, and conduct root-cause analyses.
  • Build relationships with internal customers to facilitate solutions and increase team impact.
  • Provide mentorship and support that enable team development and success.

Requirements

  • 3+ years of security incident response experience in a production cloud environment.
  • Subject-matter expertise in security issues and technologies.
  • Ability to use AI for complex security incident response and high-fidelity detections.
  • Advanced knowledge of service-oriented architectures and cloud security tools and technologies.
  • Experience addressing difficult security challenges across a technology stack.
  • Experience with SIEM platforms and extending their functionality.
  • Experience with SOAR tools and automating manual security processes.
  • Experience with AWS, Google Cloud, or another large cloud platform.
  • Excellent written and verbal communication skills.
  • Ability to influence and build effective relationships across organizational levels.

Nice to haves

  • AI model security and posture management, including safeguards against prompt injection, model evasion, and data poisoning.
  • AI-driven threat response using generative AI and large language models.
  • Artifact and evidence triage, including malware, trojan, and source-code analysis.
  • Threat intelligence integration and analysis.

Compensation and benefits

  • Competitive pay.
  • Generous time off.
  • Parental and wellness leave.
  • Healthcare.
  • Retirement savings program.
  • Benefits vary by location.

Occasional travel may be required for project or team meetings.

Skills

Incident Response, Cloud Security, AWS, GCP, SIEM, Soar, Security Automation, Service-Oriented Architecture, Generative AI, LLMs, Threat Intelligence, Malware Analysis

Writer

Writer

London, United Kingdom

Security Engineer, Application Security
No salary listedHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.

Stripe

Stripe

Dublin, Ireland

Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.

Stripe

Stripe

Seattle, WA
Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Kodex

Kodex

Sydney, Australia

Threat Intelligence Specialist – EMEA
No salary listedRemote3+ YOESecurity Engineering

The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.