Position Overview Our Threat Detection and Response (TDR) team is focused on automating security detection, responding to security incidents, and collaborating with partner teams to build capabilities supporting the full security incident response lifecycle. As the front-line defense, TDR detects, investigates, and responds to security threats against our data, systems, and global infrastructure.
To expand our coverage, we are building a mature, world-class Insider Threat Program. We are seeking a Senior Security Engineer to help implement and execute our vision for insider threat detection capabilities. In this role, you will have a direct impact on shaping a foundational security program through key technical contributions and cross-functional leadership. Key Responsibilities
Detection & Automation: Build automation, detection rules, and behavioral models to identify anomalous activity, data abuse, and data exfiltration at scale.
Threat Hunting & Investigation: Use coding, data analytics, and forensic skills to proactively hunt for insider threats across corporate and production environments.
Infrastructure & Visibility: Identify logging gaps across systems and work with internal business partners to increase visibility.
Cross-Functional Collaboration: Partner closely with HR, Legal, and broader engineering teams to conduct complex investigations, design countermeasures, and develop targeted Security Awareness training.
Incident Response & On-Call: Participate in 24/7 on-call rotation coverage to manage threat detection, incident response, and insider threat mitigation.
Minimum Requirements
Experience: 5+ years of hands-on technical experience in security operations—including detection engineering, threat hunting, incident response, digital forensics, or threat intelligence.
Education: Bachelor’s degree in a technical field (Computer Science, Cybersecurity, InfoSec) or equivalent practical experience.
Domain Expertise: Solid understanding of Insider Threat technologies (Data Loss Prevention, UEBA) and B2C operational security challenges.
Frameworks: Familiarity with the Cyber Kill Chain and MITRE ATT&CK frameworks, specifically applied to the insider threat landscape.
Technical Skills:
Experience automating security detection and response workflows.
Proficiency in core tooling languages/platforms such as Python, SQL, and AWS (EC2, S3, Lambda, RDS).
Exposure to data science and analytics solutions relevant to user behavior detection.
Soft Skills: Ability to remain calm and decisive under pressure during critical incidents; strong self-motivation, problem-solving, and multitasking abilities.
Ready to take your career to new heights? Explore job opportunities around the bustling city of San Francisco, California. Known for its vibrant tech scene, picturesque views of the Golden Gate Bridge, diverse culinary offerings like the famous clam chowder in sourdough bread bowls at Fisherman's Wharf, and the artistic vibe of the iconic street art at Clarion Alley. Work-life balance flourishes with easy access to outdoor adventures like hiking in Muir Woods, catching a Giants game at Oracle Park, or browsing through the exhibits at the San Francisco Museum of Modern Art. Join us in San Francisco and discover the endless possibilities this innovative and charming city has to offer.
Are you sure you want to apply for this job?
Please take a moment to verify your personal information and resume are up-to-date before you apply.