Senior Security Engineer Security Incident Response Team EMEA
You will lead high-severity security incidents from detection and triage through containment, eradication, and recovery. You will investigate cloud security events using DFIR methods, improve detections and telemetry, build automated and AI-assisted response workflows, communicate with stakeholders, conduct post-incident reviews, and maintain operational documentation.
Responsibilities
- Lead and coordinate end-to-end incident response for high-severity security events during EMEA business hours within a 24/7 global on-call model
- Prepare executive communications during incidents
- Investigate complex cloud security incidents using DFIR methodologies
- Partner with Signals Engineering to design and implement SIEM use cases, alerting strategies, and telemetry pipelines
- Build and enhance automation and AI-assisted workflows for triage, investigations, and response
- Partner with Threat Intelligence to improve threat context and detection coverage
- Conduct root cause analysis and lead post-incident reviews
- Develop and maintain runbooks, playbooks, and operational documentation
- Collaborate cross-functionally during incidents and lead proactive initiatives such as tabletops
- Mentor engineers and improve incident response maturity
Requirements
- Security incident response and investigation experience in cloud-first environments
- Git or GitLab experience in a security or engineering context
- SIEM, EDR, or detection engineering experience
- AWS and GCP experience
- Threat intelligence and adversary tactics knowledge, including MITRE ATT&CK
- Automation experience with Python, scripting, or SOAR platforms
- AI, machine learning, or data-driven detection, triage, or response experience or interest
- Analytical problem-solving
- Written communication
- Documentation
Benefits
- Health, financial, and well-being benefits
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity compensation
- Employee Stock Purchase Plan
- Parental Leave