Skip to content

Engineering Manager, Investigations and Incident Response

Leads engineering team in investigations and incident response for security threats at Airbnb. Owns strategy, operations, and scaling via automation; requires 9+ years in threat detection/response and 3-5 years management, with expertise in EDR, SIEM, MITRE ATT&CK, and cloud environments.

204k – 255kUnited StatesEngineering ManagementRemote9+ YOE

About the role

Responsibilities

  • Define and execute approaches to detecting, containing, and mitigating security threats and incidents.
  • Own incident response and investigation outcomes, leading end-to-end response across identification, containment, eradication, and recovery.
  • Shape team operations, evolving models, guiding execution during incidents, and scaling through automation and engineering.
  • Define and drive strategy for modern incident response function, ensuring high-quality investigations and improvements in detection/response.
  • Assess capabilities and chart path forward across people, process, and technology for global response.
  • Scale function through automation, tooling, and improved workflows.
  • Serve as key voice to senior leadership on incident trends, risks, and strategic direction; partner to turn learnings into security improvements.
  • Lead and mentor team of ~5+ senior engineers.
  • Partner with Security Platform, Detection Engineering, Infrastructure Security, Application Security, Infrastructure, Legal, Privacy, Global Safety and Security, and Engineering teams.
  • Coach and develop team members in careers, technical expertise, and collaboration.
  • Act as senior escalation point during high-severity incidents.
  • Ensure consistent, high-quality investigations with strong root cause analysis.
  • Establish priorities balancing speed, depth, and risk reduction.
  • Improve escalation paths, ownership clarity, and cross-functional coordination.
  • Use incident data to influence security priorities and investments.
  • Share incident learnings with Information Security teams for roadmaps.
  • Drive remediation with infrastructure, product, and engineering teams.
  • Define and track metrics like MTTD, MTTR, incident severity, and recurrence.
  • Communicate clearly during incidents to senior/executive leadership on insights, patterns, trends, and risks.

Requirements

  • 9+ years industry experience in threat detection and incident response, with 3-5 years in engineering management.
  • Experience shaping/evolving incident response programs in complex environments.
  • Exceptional people management, mentorship, recruiting, developing, and retaining top talent.
  • Strong understanding of attacker behavior and frameworks like MITRE ATT&CK.
  • Experience with technologies: EDR, SIEM, cloud environments, investigation workflows.
  • Experience in cloud-native environments (AWS, GCP, Azure).
  • Ability to analyze ambiguous situations and make timely decisions.
  • Comfort partnering with engineering teams for scalable solutions.
  • Operate at strategic and tactical levels, from executive communication to incident leadership.
  • Experience defining team strategy, priorities, and operating models.
  • Strong judgment in risk assessment, escalation, and trade-offs.
  • Excellent communication across technical and executive audiences.

Compensation

Pay Range: $204,000—$255,000 USD (base pay; may include bonus, equity, benefits, Employee Travel Credits).

Skills

Mitre Att&CkEdrSIEMAWSGCPAzureIncident ResponseThreat DetectionCloud SecurityInvestigation Workflows

Senior Staff Software Engineer, Platform

Senior technical leader defining long-term architecture for Rippling's core platform and AI infrastructure. Designs scalable distributed systems and leads cross-org initiatives that power the company's Business Operating System.

201k – 345kSan Francisco, CA +2Engineering ManagementHybrid10+ YOEGoJava

Staff Software Engineer

Lead cross-team strategic engineering initiatives and embed in teams to resolve urgent technical challenges. Requires 10+ years experience, strong architecture and distributed systems expertise, and hands-on coding ability.

200k – 210kNew York, NYEngineering ManagementHybrid10+ YOEGoAWS

Staff Software Engineer

Staff Software Engineer provides technical leadership, owns end-to-end feature delivery, mentors engineers, and drives innovation in building reliable software for healthcare workflows. Requires 7+ years experience, strong programming skills, and cloud architecture expertise.

210k – 225kNew York, NYEngineering ManagementOn-site7+ YOEGoAWS

Application Systems Engineering Manager

Lead a 6-person AI engineering team to design, develop, and deploy AI-powered applications that enhance customer and advocate experiences for Gusto's payroll workflows. Requires 10+ years technical experience and 2+ years engineering management plus 2+ years Generative AI.

197k – 235kSan Francisco, CAEngineering ManagementHybrid10+ YOEC++Java

Manager, Forward Deployed Engineering

Lead and scale a team of Forward Deployed Engineers and AI Engineers delivering large-scale data migrations, AI/ML platforms, and enterprise engagements for strategic Databricks customers.

212k – 291kUnited StatesEngineering ManagementRemote9+ YOESparkMLOps