Senior Security Engineer, Incident Response
The Senior Security Engineer will investigate, contain, and perform forensics on security incidents while supporting distributed on-call operations. The role also builds AI-enabled response automation and requires cloud security expertise, broad incident response skills, and experience with SIEM, SOAR, and security tooling.
About the job
Responsibilities
- Respond to incidents as part of a distributed 24x7 operations and on-call schedule.
- Triage and respond to security events and alerts, ensuring quick and effective containment.
- Contribute to security investigations, conducting analysis and forensics across a range of data sources to determine the timeline and impact of security events.
- Build automations, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite work, and scale the impact of the team.
- Communicate technical decisions through design documents and technical talks.
- Mentor junior security responders through security guidance, design reviews, and code reviews.
Requirements
- Bachelor's degree and 4+ years of incident response experience, or master's degree and 2+ years of experience.
- Strong cloud security background in at least one of AWS, Google Cloud, or Microsoft Azure, with working knowledge of the others.
- Knowledge of AI/LLM and agentic capabilities, including effective prompting and use of MCP, agents, and agent skills.
- Broad security subject matter expertise.
- Expertise in several core incident response skills, such as DFIR, reverse engineering, traditional network security, storage and access security, sandboxing, and compute security.
- Experience with enterprise security and SaaS applications.
- Working knowledge of SIEM and SOAR.
- Experience building incident response tooling and scripting skills.
Skills
AWS, GCP, Microsoft Azure, Ai/Llm, Mcp, Dfir, Reverse Engineering, Network Security, SIEM, Soar, Incident Response Tooling, Scripting, Saas Applications
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.