Responsibilities
- Proactively identify and respond to emerging security threats.
- Advance deployment of AI to SOC function.
- Develop plans to manage and maintain core tooling, such as SIEM and Orchestration platforms.
- Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
- Respond to incidents and collaborate across teams to investigate and resolve.
- Develop detection techniques to identify anomalous behaviors and attacks across the environment.
- Provide security guidance to various organizations throughout the company.
- Support broader security team projects such as threat modeling, vulnerability scanning, audits, and custom tool building.
- Take on-call shifts (every 3rd week and occasional weekend).
Requirements
- Strong ability to work collaboratively across teams during high-stress situations, which sometimes involves after hours work.
- Ability to manage multiple competing priorities and use good judgment to establish order of priorities on the fly.
- Self-motivated and creative problem-solver able to work independently with minimal guidance.
- Experience/familiarity with Slack, Apple MacOS and GSuite.
- 10+ years of experience in detection, response, or security engineering.
- 3+ years of experience commanding security incidents, especially those involving engineering.
- Experience working in an AWS + EKS environment required and some exposure to GCP or OCI preferred.
- Hands-on experience using AI tooling both to accelerate work and to address threats, coupled with a strong understanding of the organizational risks AI introduces and strategies to defend against them.
- Extensive knowledge of SIEM, Case Management, and SOAR solutions.
- Knowledge of operating systems, file systems, and memory on MacOS.
- Programming experience in Python, Golang, or similar programming languages.
- Experience with building Detections As Code.
Nice to Have
- Professional or hobbyist blockchain exposure is preferred.
Work Arrangement
Hybrid
Additional Information
- This position will require you to perform on-call duties mainly during working hours to support security operations, and you will assist the team with the occasional night time and weekend incident.
