About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe’s business or users. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed, working across multiple AMER time zones, and will regularly coordinate with stakeholders in EMEA and APAC. What you’ll do You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity. Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms. Responsibilities Analyze and inv
Jobiba hiring network
Security Incident Response Engineer Jobs
3,397 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current security incident response engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Squarespace is looking for a Security Engineer with a focus on Investigations and Incident Response to join a dedicated team responsible for monitoring and responding to attacks on our platform. You'll partner with teams across the organization as you investigate security events specific to our platform and corporate environment. This is a hybrid role working from our Dublin office 3 days per week and you will report to the Detection and Response Manager. You’ll Get To… You will investigate security events through our SIEM and SOAR technology Design alerts to monitor both our customer and corporate environments for anomalous behavior Share insights gleaned from SOAR case work with relevant security team members in order to drive more security feature implementation to the product or corporate environment You will respond to ongoing incidents, investigate historical compromises, and provide adept analysis and findings Establish strategies for threat detection, alerting, and response You will initiate reactive threat hunting engagements by performing endpoint, network, application, and log analysis Establish processes and build 'playbooks' of operational response to security events and/or incidents Familiarity with Threat Intelligence and keeping up-to-date on modern threats and InfoSec news Build and support security-focused tools and services Provide Mentorship and technical expertise to junior team members to assist their technical development Who We’re Looking For 5+ years experience in the security industry Certifications (preferred not required): OSCP, OSCE, OSWP Experience working with SIEM and SOAR technologies Knowledgeable of cloud & container security, and infrastructure as code Working understanding of malware analysis, reverse engineering, and host-based and memory forensics Proficiency in programming or scripting languages (preference to Python, Go, JavaScript, or Bash) is a plus Knowledge of network and web related protocols (e.g., TCP/I
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will be on the frontline of protecting both GitLab.com and GitLab the company from security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-function
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As an Intermediate Security Engineer on GitLab's Security Incident Response Team (SIRT), you will be on the frontline of protecting both GitLab.com and GitLab the company from security threats. This role operates on a compressed 4-day work schedule, with a full-time week's hours condensed into four longer working days. Shifts run either Sunday through Wednesday or Wednesday through Saturday to provide 24/7/365 security coverage. Your primary focus will be detecting and responding to security incidents during your scheduled shifts. You'll work extensively with our incident response automation tools to inve
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detecti
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions. You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions. You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow
ABOUT THE ROLE Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts. YOUR DAILY IMPACT AT PELOTON Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams Recommend and build countermeasures based on threat analysis, intelligence, and forecasting Develop, implement, and maintain security incident playbooks/runbooks Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world. What you’ll do In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi
Get new security incident response engineer jobs by email
Daily job updates · Unsubscribe anytime