Jobiba hiring network

Security Incident Response Engineer Jobs

3,397 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current security incident response engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.

D
Datadog
📍 New York• Full-time• From $156K/yr
1mo ago

The Team: As a Security Engineer 2 on the Cyber Threat Intelligence team, you will help Datadog stay ahead of evolving threats by identifying, analyzing, and operationalizing intelligence on threat actors, campaigns, and emerging threats. Working within Security Engineering, you will partner closely with security teams to translate intelligence into actionable security improvements across the company. You will serve as a subject matter expert on how the cyber threat landscape intersects with Datadog and contribute to intelligence-led decision making during both steady-state operations and active security incidents. This role provides opportunities to influence detection, response, and security strategy through technical analysis, collaboration, and intelligence-driven initiatives. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Develop and maintain tooling that automates the collection, processing, analysis, and dissemination of threat intelligence. Assess emerging vulnerabilities, threat activity, and security events to help stakeholders understand potential impact to Datadog. Conduct threat hunting and infrastructure analysis to identify adversary activity relevant to Datadog and improve defensive controls. Partner with security teams to operationalize intelligence into detections, investigations, and response workflows. Coordinate with information-sharing communities to gather, evaluate, and disseminate actionable intelligence. Produce technical briefings, threat reports, and intelligence products for security and engineering stakeholders. Who You Are: Experienced in writing and presenting operational and technical intelligence for threat detection, response, and security stakeholders. Skilled in partnering with detection and response te

linuxaigo
View job →
R
Ramp
📍 New York City• Full-time• From $10K/yr
1mo ago

About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our federal and public sector environments. Please note that this role will require you to be comfortable with working in-person at our NYC HQ (located near Madison Square Park) at least 2 days/week What You’ll Do Respond and assist with security requests and incidents submitted by Ramp team members Review logging, alerting, and audit sources to identify potential security incidents and perform initial triage on identified incidents Contribute to the creation, upkeep, and tuning of runbooks and security alerts to effectively handle, triage, and improve security alerts Work closely with the Ramp Security Engineers to improve security alerting and automated remediation Utilize log ingestion platform for security analytics and identification of tactics, techniques and patterns of attackers Design and implement automation to detect and respond t

restaigo
View job →
P
9 days ago

ABOUT THE ROLE Peloton is seeking an experienced, collaborative leader to join the Legal team as Legal Director, Privacy. This role will be responsible for implementing, managing, and evolving Peloton's global privacy program, playing a pivotal role in our mission to be the most trusted brand in connected fitness. As a senior leader on our Legal team, you will act as a primary privacy advisor to the business. You will partner closely with leaders across Information Security, Data Analytics, Product, Engineering, Marketing, and other business units to ensure that our commitment to Member trust is embedded in every product we build and every interaction we have. This role requires a strategic thinker with deep subject matter expertise who can translate complex global regulations into a practical, scalable, and business-enabling privacy framework. YOUR DAILY IMPACT AT PELOTON Lead and refine Peloton's global privacy program, including our policies, procedures, and data governance standards, to ensure compliance with international law Partner closely with cross-functional teams to embed privacy by design in our core processes for collecting, maintaining, using and sharing personal data Develop and manage our privacy risk management framework, including conducting Data Protection Impact Assessments (DPIAs), managing data subject rights requests, and overseeing privacy incident responses Serve as the subject matter expert on global privacy, cybersecurity, and data protection laws. Advise the business on the impact of evolving regulations and continually refine Peloton’s privacy program to reflect best practices Develop and deliver engaging privacy training and awareness programs to educate Peloton employees and key stakeholders on their data protection responsibilities Serve as the primary legal point of contact for data protection authorities. Prepare and present regular reports on the privacy program's status and risk posture to leadership YOU BRING TO PELOT

airecruitment
View job →
P
Pinterest
📍 United States• Full-time• Remote• From $123.7K/yr
1mo ago

About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest is seeking an experienced Security Engineer to build and implement detection and response improvements and adapt to emerging threats to protect employees and infrastructure. In this role you will have the opportunity to solve challenging problems and provide a meaningful impact on our overall security posture. We are looking for a candidate with a passion for both security and innovation. What you'll do: Build alerts and automation workflows to improve capabilities to detect and response to external and internal security threats Manage our logging pipelines and infrastructure and onboard new logging sources to improve our detection coverage Develop and maintain internal tooling to expand and automate team detection and response capabilities Respond to alerts generated from our tooling and run incidents as part of an on-call rotation Co

REMOTEpythonawslinux
View job →
F
Flexport
📍 United States• Full-time• From $165.4K/yr
1mo ago

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi

pythonrestagile
View job →
F
Flexport
📍 San Francisco• Full-time• From $165.4K/yr
1mo ago

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do Identity & access Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate. Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents. Endpoint & device lifecycle Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one. Maintain and improve our EDR stack's detection and response coverage across the fleet. SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. Automation & enablement Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor securi

pythonrestagile
View job →
S
Snowflake
📍 United States Minor Outlying Islands, United States• Full-time
1mo ago

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Staff Security Engineer for our Enterprise Security team. The threats facing modern organizations are evolving at an unprecedented pace — driven by AI, cloud complexity, and an ever-expanding attack surface. Our Enterprise Security team is responsible for protecting Snowflake, our employees, and our customers by designing, implementing, and maintaining robust endpoint security solutions at enterprise scale, defending not just endpoints and identities, but the AI-assisted workflows and intelligent systems that define how the modern enterprise operates. AS A STAFF SECURITY ENGINEER AT SNOWFLAKE, YOU WILL: Develop, maintain, and scale Snowflake's endpoint security solutions while actively contributing to architecture and strategy. This includes EDR, DLP, secure browser, MDM, and AI security solutions across a complex multi-cloud, multi-SaaS enterprise environment. Own the technical roadmap for endpoint security tooling as Snowflake rapidly grows. Build intelligent security platforms and automate security operations using AI and robust software engineering. Identify opportunities to reduce toil, increase detection fidelity, and accelerate response through thoughtful, scalable automation. Monitor security events, investigate incidents, and build real-time detecti

javascriptpythonjava
View job →
C-
CLEAR - Corporate
📍 New York• Full-time• $145K – $170K/yr
16 days ago

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. CLEAR is seeking a Senior Security Operations Analyst III to join our SOC team to help strengthen our ability to detect, investigate, and respond to evolving security threats. In this role, you’ll lead complex investigations, improve CLEAR’s threat detection and response capabilities, and serve as a trusted security partner while helping develop the analysts and program around you. What you'll do: Lead complex investigations of security events across corporate networks, endpoints, data centers, cloud environments, and other critical systems, driving incidents from initial analysis through escalation and remediation Develop, tune, and optimize threat detection logic across SIEM, EDR, and other security platforms, proactively identifying coverage gaps, reducing false positives, and improving the fidelity of security alerts Partner with Engineering, Infrastructure, and other teams to investigate threats, identify root causes, communicate risk, and drive timely remediation and improvements to CLEAR’s security posture Apply threat intelligence, data, automation, and AI-enabled tools to identify emerging attack patterns, accelerate investigations, improve detection workflows, and strengthen decision-making while applying sound security judgment Serve as a subject matter expert and escalation point for other analysts, mentoring junior team members, sharing knowledge, and helping establish scalable processes, playbooks, and standards for threat detection and analysis Continuously evaluate CLEAR’s detection coverage against the evolving t

gitrestai
View job →
W
9 days ago

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: Detection Engineering is responsible for designing, developing, and maintaining high-fidelity detection logic across enterprise security platforms. This role focuses on proactive threat detection, automation-first practices, and continuous improvement of detection coverage and accuracy, supporting the WPP SOC transformation into an Autonomic Security Operations model. What you'll be doing: Develop, test, and maintain detection rules and logic across SIEM, EDR, NDR, and cloud-native platforms. Regularly review and enhance detection logic to improve accuracy, reduce noise, and align with evolving threats. Work with wider WPP engineering teams to ensure high-quality, normalized telemetry for effective detection. Automate detection rule deployment, QA, and version control using scripting and CI/CD pipelines. Root Cause Analysis (RCA) Conduct RCA on missed detections, delayed responses, and high-severity incidents. Identify technical and process-level causes of detection failures or inefficiencies. Drive corrective actions based on RCA outcomes (e.g., rule improvements,

pythonairecruitment
View job →
T
Toradex
📍 Bengaluru• Full-time
16 days ago

Toradex is a global company strongly focused on engineering & technology. We’re powered by a diverse & uniquely gifted workforce. We pursue the best people to propel our innovative vision of embedded computing and IoT. If you’re interested in being a driving force at an agile technology company, engineering clever computing solutions & helping other companies bring their products to life, we should talk. Description We are looking for a DevOps Engineer to strengthen our cloud operations and engineering practices, with a focus on reliable website delivery, secure AWS foundations, and fast but controlled delivery of new services. The position combines AWS operations, infrastructure as code, CI/CD, automation, and pragmatic software engineering. The person should be confident working with services for edge delivery, compute, storage, databases, DNS, security, and observability without relying on manual console changes as the default operating model. The role also supports on-premises to cloud migration, global service optimization, and practical responses to increasing AI-driven traffic. We value candidates who can use modern AI-assisted development effectively to spin up proof-of-concept projects quickly, while still applying disciplined Git, review, security, and deployment practices. About you You enjoy building stable, secure, and maintainable infrastructure that supports business-critical services. You can work independently and take ownership of cloud environments, deployments, and operational improvements. You are comfortable balancing speed, reliability, cost, and security when making technical decisions. You communicate clearly with technical and non-technical stakeholders and explain trade-offs in a practical way. You document your work well and create clear runbooks and support material for future maintenance. You are methodical when troubleshooting incidents and stay calm when systems are under pressure. You are curious about modern traffic patt

javascripttypescriptpython
View job →
S
1mo ago

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Security Incident Response team is responsible for triaging and assessing the severity of incoming security alerts, responding with initial containment measures and escalating as needed to incident responders for further investigation and resolution. They analyze a variety of data sources to identify potential threats, collect requirements for operational enhancements to detection and response systems, and generally scale security processes. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed globally and regularly coordinates with stakeholders in North America, Europe, and Asia. What you’ll do You will leverage your security management experience to improve incident response capabilities at Stripe. You will manage a team of security analysts, investigators, and responders on the front lines of the incident response process, hiring, training, and evaluating their performance, providing technical guidance where needed, developing clear and consistent response procedures, and ensuring timely and effect

pythonsqlgit
View job →

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Senior Security Incident Responder is a lead technical authority for incident response execution, responsible for handling the most complex, high-impact, and business-critical security incidents across WPP. The role does not have line management responsibility; people management remains with the Security Incident Management Lead. What you'll be doing: KEY RESPONSIBILITIES Advanced Incident Detection, Analysis & Response - Lead investigations for high-severity and complex security incidents. - Perform deep technical analysis using SIEM, SOAR, EDR/XDR, identity, email, and cloud telemetry. - Execute and oversee containment, eradication, and recovery actions. - Act as technical incident commander when delegated. Escalation Handling & Stakeholder Coordination - Serve as the primary escalation point for complex incidents. - Coordinate with Legal, Privacy, Risk, Technology Operations, and agency teams. - Provide clear technical updates to senior stakeholders. Forensics, Evidence Handling & Assurance - Lead forensic evidence collection, preservation, and analysis. - Ensure d

recruitment
View job →

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Head of Security Incident Management is responsible for leading and maturing WPP's global Security Incident Management capability, providing strategic, operational, and technical leadership across the entire incident response lifecycle. Reporting directly to the Director of Operational Security, this role owns the Security Incident Management function, including Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders. The position ensures that security incidents are managed consistently, effectively, and in accordance with WPP policies, regulatory obligations, and operational standards. The role evolves and scales incident response capabilities in alignment with WPP's Autonomic Security Operations (ASO) strategy and automation-first operating model. This includes oversight of people, process, technology, governance, service performance, and continuous improvement. What you'll be doing: Own the end-to-end Security Incident Management capability across WPP. Lead and develop Security Incident Management Leads, Senior Security

recruitment
View job →
PE
1mo ago

Role Summary We are seeking an experienced SOC / Security Operations Lead to oversee and strengthen the organization's Security Operations Center (SOC), threat detection, incident response, vulnerability management, data protection, and security monitoring capabilities. The ideal candidate will possess extensive experience in managing enterprise security operations, SIEM/SOAR platforms, threat hunting, incident response, DLP, endpoint security, and vulnerability management programs. The role requires leadership of a multi-functional security operations team responsible for protecting critical business systems, customer data, and digital assets while ensuring compliance with RBI regulations and industry security standards. Key Responsibilities Security Operations Center (SOC) Management -Lead and manage 24x7 Security Operations Center (SOC) functions. -Establish and enhance SOC processes, playbooks, escalation procedures, and operational metrics. -Ensure timely detection, triage, investigation, containment, and remediation of security incidents. -Develop SOC maturity roadmaps aligned with industry best practices and regulatory expectations. -Monitor security KPIs, SLAs, MTTR, MTTD, and incident response effectiveness. SIEM, XSIAM & Threat Detection -Lead implementation, administration, and optimization of: -Palo Alto Cortex XSIAM -SIEM Platforms -SOAR Platforms -UEBA Solutions -Threat Intelligence Platforms -Develop and tune correlation rules, detection logic, and analytics use cases. -Enhance detection coverage across cloud, endpoints, applications, networks, and third-party environments. -Drive threat hunting and proactive security monitoring initiatives. Incident Response & Threat Management -Lead enterprise cyber incident response activities. -Develop and maintain incident response plans, runbooks, and communication procedures. -Coordinate investigations involving malware, ransomware, phishing, insider threats, account compromise, fraud, and adv

🔔

Get new security incident response engineer jobs by email

Daily job updates · Unsubscribe anytime