Назад
2 часа назад

Security Engineer (Incident Response)

230 000 - 360 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (Incident Response) (Cloud Security/AI): Defending a cloud-native AI software creation platform through incident response, forensic investigation, and automated containment with an accent on cloud infrastructure, identity systems, containers, and application-layer threats. Focus on leading investigations, building Python/Go/Bash response tooling, improving detections and playbooks, and coordinating remediation across Security, SRE, Engineering, Legal, and leadership.

Location: Hybrid in Foster City, California, United States

Salary: $230,000–$360,000 annually

Company

Replit is an agentic software creation platform that enables users to build applications using natural language.

What you will do

  • Lead security incidents from detection and triage through containment, eradication, recovery, and post-incident review.
  • Coordinate incident response across Security, SRE, Engineering, Legal, and leadership while communicating status, impact, and risk.
  • Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, cloud logging, telemetry, and host or container artifacts.
  • Build Python, Go, Bash, or Replit-based automation for enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage.
  • Develop response playbooks, runbooks, and integrations with SIEM, SOAR, ticketing, and chat tools.
  • Convert incident findings into detections, improved logging and visibility, remediation work, tabletop exercises, and readiness improvements.

Requirements

  • Proven experience leading or technically leading security incidents in cloud or SaaS environments.
  • Strong hands-on investigation skills with SIEM, cloud audit logs, and large log datasets.
  • Production-quality scripting or tooling experience in Python, Go, or Bash.
  • Strong knowledge of cloud architecture and security, especially Google Cloud Platform, IAM, audit logging, GKE, and networking.
  • Working knowledge of Kubernetes, containers, identity systems, SaaS architectures, cloud attack paths, CI/CD, and package ecosystems.
  • Understanding of incident response frameworks such as NIST 800-61, vulnerability lifecycles, and exploitability analysis.

Nice to have

  • Experience with SOAR platforms, digital forensics, threat intelligence, threat hunting, or security research.
  • Experience with bug bounty programs, coordinated vulnerability disclosure, detection-as-code, or detection rules.
  • Experience in fast-paced, cloud-native, or AI/ML-driven environments.
  • Relevant certifications such as GCIH, GCFA, or GCFR, or equivalent hands-on experience.

Culture & Benefits

  • Autonomous work environment with a hybrid office setup.
  • Health, dental, vision, life, short-term disability, and long-term disability insurance.
  • 401(k) program with a 4% match for US employees.
  • Flexible time off, holidays, and paid parental, medical, and caregiver leave.
  • Monthly wellness stipend, commuter benefits, office setup reimbursement, office amenities, and quarterly team gatherings.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →