Senior Security Engineer, Incident Response
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
About the job
Responsibilities
- Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
- Document incidents and projects, and craft best practices as runbooks and standard operating procedures.
- Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
- Improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
- Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
- Own the security incident lifecycle, respond to incidents, participate in on-call rotation and RCAs for security incidents.
- Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions.
- Provide mentorship, support, and care for the team to enable long-term career development.
Qualifications
Required:
- 5+ years of security incident response in a production-cloud environment.
- Subject-matter expert on security issues and technologies.
- Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections.
- Advanced knowledge of service-oriented architectures, and experience with security tools and technologies fit for a cloud environment.
- Experience working across a technology stack on difficult security challenges and initiatives.
- Experience with SIEM platforms and the ability to extend their functionality.
- Experience with SOAR tools and automating manual security processes.
- Experience in either AWS, GCP, or other large cloud platform.
- Excellent written and verbal communication skills.
- Ability to influence and build effective working relationships with every level of the organization.
Desired:
- AI Model Security & Posture Management: Support implementation of controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning.
- AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data.
- Artifact & Evidence Triage: Collect intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
- Threat Intelligence Integration: Monitor external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks.
Skills
Incident Response, SIEM, Soar, AWS, GCP, Cloud Security, Ai For Security, Threat Intelligence, Forensics, Runbooks, Service-Oriented Architectures
Similar jobs
Security Engineering jobsSenior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.
Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.