Remote job
Staff Security Engineer, Incident Response
Job details
About this role
Role overview
A staff-level individual contributor role on a distributed Incident Response team tasked with safeguarding customers, employees, and enterprise data from security threats. The position blends hands-on incident handling and forensic analysis with engineering work to automate and scale detection, containment, and investigation workflows, including through AI-driven and agentic tooling. Selected candidates will participate in 24x7 follow-the-sun on-call rotations while mentoring junior responders and helping shape the team's technical direction.
Responsibilities
- Triage and respond to security events and alerts within a distributed 24x7 on-call rotation - Conduct forensic analysis across diverse data sources and reconstruct incident timelines and impact - Lead containment and remediation efforts for high-priority security incidents - Build automated solutions, including AI- and agentic-based capabilities, that amplify the team's reach - Communicate technical direction through design documents and internal presentations - Mentor less-experienced responders via guidance, design reviews, and code reviews
Requirements
- Active or current U.S. government Secret clearance eligibility, with Top Secret preferred - Bachelor's degree with at least 7 years of incident response experience, or a Master's degree with 5+ years - Hands-on security experience in at least one major cloud platform (AWS, GCP, or Azure) and working proficiency in the others - Practical knowledge of AI, LLM, or agentic systems, ideally applied inside a security context - Deep expertise in core IR disciplines such as DFIR, reverse engineering, network security, storage and access security, sandboxing, or compute security - Familiarity with SIEM and SOAR platforms, scripting languages, and AI-assisted coding tools
Nice to have
- Experience securing enterprise SaaS applications - Background building custom incident response tooling - Prior technical leadership or mentorship in a security operations environment
Benefits and work setup
- Distributed team with continuous on-call responsibilities across multiple regions - Region-specific benefits package offered to employees