Principal Security Engineer - Incident Response
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Seattle, United States. Incident response operations are supported from the US, with collaboration across EMEA, LATAM, and Americas time zones.
Annual base pay: $182,200–$273,200, plus potential incentive compensation, bonus, restricted stock units, and benefits.
Company
develops technologies that help organizations create, secure, and operate applications, including BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS protection, bot defense, and AI-enabled services.
What you will do
- Lead ’s incident response program, including its roadmap, governance, standards, playbooks, severity model, metrics, and executive reporting.
- Direct end-to-end response to cyber and product security incidents, from preparation and detection through containment, recovery, customer-impact assessment, and post-incident review.
- Manage cyber crises by defining workstreams, driving decisions, coordinating stakeholders, and maintaining executive visibility.
- Build response capabilities for AI applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths.
- Lead tabletop exercises, cyber simulations, product security drills, and customer-impact response assessments.
- Improve detection, containment, recovery, observability, fleet visibility, automation, and response orchestration across environments.
Requirements
- 10+ years of cybersecurity experience with deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations.
- Experience leading enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments.
- Strong knowledge of modern attack techniques, incident management, executive communications, crisis coordination, and stakeholder orchestration.
- Experience with application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security.
- Familiarity with CrowdStrike, EDR detections, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence, identity and access logs, API gateway logs, cloud telemetry, and network/edge logs.
- Ability to influence large organizations without direct authority; FedRAMP eligibility is required. Familiarity with NIST, ISO, SOC, PCI, and GDPR is preferred.
Culture & Benefits
- Work within the Office of the CISO as a principal individual contributor.
- Collaborate with security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders.
- Contribute to a diverse workplace focused on improving customer and end-user experiences.
- Potential incentive compensation, bonus, restricted stock units, and employee benefits are available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →