freehire launches on Product Hunt on 26 August.

Follow →

Senior Security Engineer, Incident Response

Open 3d

Summary

Build and optimize threat detection and incident response systems at Airbnb, hunting for anomalies, automating investigations, and leading cross-team responses to security incidents using Python, AWS, and data analytics.

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way.

The Community You Will Join:

The Threat Detection and Response team (TDR) at Airbnb is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity.

This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response.

The Difference You Will Make:

  • You will be a key member of our growing Threat Detection & Response (TDR) team.
  • You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents.
  • You will partner with cross-functional partners across the company to improve the overall security of Airbnb driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems.

A Typical Day:

  • Perform investigations of security incidents using your knowledge of digital forensics and data analytics.
  • Use your coding, data analytics and investigation skills to hunt, detect and respond to threats.
  • Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale.
  • Hunt for threats in our corporate and production environments to proactively identify anomalous activity.
  • Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with partner teams to carry out complex investigations.
  • Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
  • Collaborate well with cross-functional partner teams, such as Legal, Privacy, and Engineering for efficient, large-scale response.

Your Expertise:

  • 5+ years of hands-on in-depth knowledge and technical experience in security operations including investigations, incident response, incident management, digital forensics, threat intelligence, threat hunting, and/or detection engineering.
  • Proficiency in Python or other scripting language. We also use SQL and Pandas frequently.
  • Familiarity with Elasticsearch is preferred.
  • Self-motivated and creative problem-solver able to work independently with minimal guidance.
  • Ability to lead people in complex, ambiguous situations through influence and not authority.
  • Ability to work calmly and collaboratively in critical high-stress situations with expediency.
  • Outstanding organizational, prioritization, and multitasking skills.
  • Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the threat landscape.
  • Experience automating security detection and response.
  • Experience in AWS services (EC2, S3, Lambda, RDS) preferred
  • We are not focused on specific tools but we often use Python, AWS, SQL, and more.

Your Location:

This position is US - Remote Eligible. The role may include occasional work at an Airbnb office or attendance at offsites, as agreed to with your manager. While the position is Remote Eligible, you must live in a state where Airbnb, Inc. has a registered entity. Click here for the up-to-date list of excluded states. This list is continuously evolving, so please check back with us if the state you live in is on the exclusion list. If your position is employed by another Airbnb entity, your recruiter will inform you what states you are eligible to work from.

Our Commitment To Inclusion & Belonging:

Airbnb is committed to working with the broadest talent pool possible. We believe diverse ideas foster innovation and engagement, and allow us to attract creatively-led people, and to develop the best products, services and solutions. All qualified individuals are encouraged to apply.

We strive to also provide a disability inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation in order to submit an application, please contact us at: reasonableaccommodations@airbnb.com. Please include your full name, the role you’re applying for and the accommodation necessary to assist you with the recruiting process.

We ask that you only reach out to us if you are a candidate whose disability prevents you from being able to complete our online application.

How We'll Take Care of You:

Our job titles may span more than one career level. The actual base pay is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role may also be eligible for bonus, equity, benefits, and Employee Travel Credits.

Pay Range
$196,000$227,000 USD

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • LinkedIn Profile optional
  • How did you hear about this job? choose one
  • U.S. Equal Opportunity Employment Information (Completion is voluntary) choose any · optional
  • Gender: choose one · optional
  • Race: choose one · optional
  • Veteran Status: choose one · optional
  • Are you legally authorized to work in the country where the job is located? choose one
  • Will you now or in the future require company sponsorship to retain or extend your work authorization in the country where the job is located? choose one
  • Airbnb Candidate Privacy Policy choose one
  • Are you currently subject to any non-compete or non-solicitation agreement that would impact your ability to work at Airbnb or prevent you from accepting a job offer from Airbnb? choose one
  • Are you currently or have you ever worked for Airbnb in any capacity? This could include, but is not limited to, a full-time employee, intern, apprentice, or contingent worker. choose one
  • Candidate AI Usage Attestation: choose one
  • Do you have experience developing or maintaining detection logic in cloud-native environments (e.g., AWS)? If so, please provide a 1–2 sentence summary outlining the types of threats or behaviors you targeted and how you validated efficacy. written answer
  • Have you built or automated security response workflows (e.g., alert enrichment, triage, remediation) using Python or similar languages? If so, please provide a 1–2 sentence summary outlining your approach and tools used. written answer
  • Have you led or significantly contributed to an incident response investigation involving complex infrastructure (Cloud, Kubernetes, Production Environments)? If so, please provide a 1–2 sentence summary highlighting your role and the outcome without providing private incident details. written answer

See also