Response Engineer - CMDC
The Response Engineer monitors and investigates security alerts, analyzes traffic, and applies attack mitigations while improving monitoring tools and supporting high-value customers. The role requires at least two years of technical and customer support experience plus strong networking, systems, scripting, and security expertise.
About the job
Responsibilities
- Monitor and investigate alerts to identify attacks.
- Review alerts for relevancy and urgency; create tracking tickets for incidents requiring review or escalation.
- Work with Engineering, Operations, and Product teams to mitigate attacks, improve products and tools, and implement appropriate mitigations.
- Communicate extensively with high-value customers via chat, email, and phone.
- Configure and manage security monitoring rules and contribute to tool improvements.
- Compare traffic signatures and attributes—including IP addresses, cookie variations, HTTP headers, and JavaScript footprints—to distinguish legitimate from malicious traffic.
- Participate in a weekend and holiday rotation; main working hours are 9:00 a.m. to 5:00 p.m. Pacific time.
Requirements
- At least 2 years of technical support and customer support experience.
- Strong understanding of the OSI model, TCP, UDP, BGP, and QUIC.
- Advanced knowledge of iptables.
- Experience analyzing traffic for attack anomaly detection and creating mitigation rules.
- Experience handling attack mitigation and thorough knowledge of Layer 3/4 and Layer 7 attacks.
- Strong communication skills with high-value customers.
- Command-line and Bash shell proficiency.
- Systems administration skills across Linux, macOS, and Windows.
- Programming experience with Python, Ruby, PHP, C, C#, Java, Perl, and Git.
Nice-to-haves
- Security certifications such as CISSP, GCIA, GCIH, GCFA, or GCFE.
- Previous DDoS mitigation experience across OSI Layers 3, 4, and 7.
- Experience using Cloudflare Magic Transit, Network Firewall, WAF, IP reputation lists, packet inspection, blacklisting, whitelisting, or rate limiting.
Skills
Osi Model, Tcp, Udp, BGP, Quic, Iptables, Bash, Linux, Python, Ddos Mitigation, Web Application Firewall, Git
Similar jobs
Security Engineering jobsBuild foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.
Build Greptile’s security product, including code scanning, vulnerability detection and reproduction, security-focused pull-request workflows, and agent infrastructure. The role requires a computer science degree, software or DevOps experience, JavaScript/TypeScript expertise, and hands-on security experience.
Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.
Build security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.
Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.