SPECIFIC JOB RESPONSIBILITIES Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP). Multi-Tenancy & MSSP Architecture: Architect a scalable, multi-tenant environment that ensures strict data isolation between clients while allowing for unified " ClickOps " and Terraform-driven automation. AI & Innovation: Explore and implement Now Assist (GenAI) and AI-heavy workflows to automate security reporting and incident summarization. Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP)
Jobiba hiring network
Security Incident Response Engineer Jobs
3,397 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current security incident response engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world. What you’ll do In this role, you will play a critical part in safeguarding our financial ecosystem through two main pillars: actively responding to live fraud and abuse incidents as a hands-on security engineer, and serving as a key bridge between incidents and merchants to help them remediate threats, improve security posture, and protect their accounts. Leveraging your technical depth in fraud, abuse, and security engineering, you will investigate high-risk accounts, perform post-incident analyses, gather operational requirements, and drive agentic response capabilities ensuring we neutralize threats with speed and precision while elevating Stripe's product integrity function. Responsibilities Respond to live fraud and abuse incidents as a Forward Deployed Security Engineer, investigating high-risk activity, neu
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi
Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way. The Community You Will Join: The Threat Detection and Response team (TDR) at Airbnb is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity. This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response. The Difference You Will Make: You will be a key member of our growing Threat Detection & Response (TDR) team. You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents. You will partner with cross-functional partners across the company to improve the overall security of Airbnb driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems. A Typical Day: Perform investigations of security incidents using your knowledge of digital forensics and data analytics. Use your coding, data analytics and investigation skills to hunt, detect and respond to threats. Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale. Hunt for threats in our corporate and prod
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Senior
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. About the Team The Security Operations (SecOps) team at Robinhood proactively safeguards our platform and millions of customers. We monitor, detect, and respond to security threats in real time while staying ahead of risks through threat intelligence, Red Team operations, and research partnerships. We are building the next generation of security operations—leveraging AI-driven automation, Autonomic Security Operations (ASO), and innovative detection frameworks to set the standard across the cybersecurity industry! About the Role As a Staff Security Engineer (IC6) on the Detection & Response team, you will drive our incident response strategy, build robust detection engineering frameworks, and mentor engineers across the organization. In this high-impact role, you will command high-stress incident responses, eliminate operational noise by developing an AI-native detection platform, and help shape the broader AI-agentic ecosystem for SecOps. You will work closely with cross-functional partners in Proactive Security, Security Engineering, Insider Trust, Infrastructure, Legal, and Communications to protect Robinhood’s ecosystem. This role is based in our Bellevue, WA a
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a founding member of the Security Operations team in EMEA, you will join us at an exciting time in Roblox’s SIRT & SOC program. You will design and build the detections, automation and tooling that let a lean team monitor and protect players, developers, employees and the platform at global scale and serve as security incident commander in the region. This is a highly autonomous role where you will be a primary decision-maker, core to our mission to maintain a highly capable 24/7/365 monitoring and response capability. While you will work in close collaboration with peers at our US West Coast Headquarters, the time difference requires an engineer who can operate independently, making critical decisions without immediate oversight. We favor engineering our way out of toil through automation, orchestration, detections-as-code, and risk-based prioritization, while retaining the deep technical skills required to conduct detailed, hands-on analysis and lead response end-to-end when the situation warrants. Work Environment: This role is based in London, UK. You will be working from a dedicated, private space located within a shared office environment, designed to enable collaboration
About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate. We take a pragmatic approach to preventing and responding to security risks. In this role not only will you build and contribute to systems which detect malicious activity, you will have the unique opportunity to implement new controls to prevent future incidents. You will work across detection and response and corporate security domains. You'll contribute to practices that keep Sentry secure as we grow: alert triage for corporate and production, detection engineering, deploying preventative controls, identity and access management, investigations and incident response, and more. You'll partner with teams across the company to prevent and respond to security incidents. You will work as a technical collaborator who prioritizes preventative controls, defense in depth, and high signal alerting practices. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security approaches and challenges. In this role, you will Maintain, improve, and own detection engineering systems. We own and operate our own detection stack and are building agentic triage with thoughtful security response and orc
About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate. We take a pragmatic approach to preventing and responding to security risks. In this role not only will you build and contribute to systems which detect malicious activity, you will have the unique opportunity to implement new controls to prevent future incidents. You will work across detection and response and corporate security domains. You'll contribute to practices that keep Sentry secure as we grow: alert triage for corporate and production, detection engineering, deploying preventative controls, identity and access management, investigations and incident response, and more. You'll partner with teams across the company to prevent and respond to security incidents. You will work as a technical collaborator who prioritizes preventative controls, defense in depth, and high signal alerting practices. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security approaches and challenges. In this role, you will Maintain, improve, and own detection engineering systems. We own and operate our own detection stack and are building agentic triage with thoughtful security response and orc
The Incident Insights & Readiness SRE team at Datadog fosters a resilient culture by using incidents as learning opportunities and catalysts for growth. Our users are Datadog engineers, and we build the software, tooling, and operational frameworks that help them prepare for, respond to, and learn from incidents. We work closely with engineering teams across Datadog to analyze incidents and turn those insights into better tools, stronger incident response, and organizational learning. Our efforts empower Datadog to navigate unexpected failures confidently, efficiently, and with a commitment to continuous learning and systems improvement. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. The Incident Insights & Readiness SRE team at Datadog fosters a resilient culture by using incidents as learning opportunities and catalysts for growth. Our users are Datadog engineers, and we build the software, tooling, and operational frameworks that help them prepare for, respond to, and learn from incidents. We work closely with engineering teams across Datadog to analyze incidents and turn those insights into better tools, stronger incident response, and organizational learning. Our efforts empower Datadog to navigate unexpected failures confidently, efficiently, and with a commitment to continuous learning and systems improvement. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Own and improve the on-call experience for the company by establishing best practices and building platforms to support on-call rotations and compensation
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Operations (SecOps) team protects Robinhood and its customers by detecting, investigating, and responding to security threats across our production systems, endpoints, and cloud environments. We combine detection engineering, incident response, and threat intelligence to identify emerging risks, strengthen our defenses, and reduce the impact of attacks before they reach our customers. As we continue to evolve our security platform, we're embracing AI and automation to help our teams move faster, uncover threats more effectively, and scale our defenses against increasingly sophisticated adversaries. As the Manager of Response, Automation, Intelligence and Detection Engineering (RAID) within SecOps, you will lead teams across North America, shaping the strategy, execution, and long term evolution of our defensive security capabilities. You'll be responsible for building high performing teams, maturing our detection and incident response programs, and ensuring we stay ahead of an increasingly sophisticated threat landscape. Working closely with Security, Engineering, Infrastructure, and Trust & Safety, you'll translate emerging threats into scalable defenses wh
About Us: AI needs a new infrastructure layer. We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now. Our customers include category-defining companies like Lovable , Ramp , Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale. We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September. Our team includes creators of popular open-source projects (e.g., Seaborn , Luig i ), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience. The Role: We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform. This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness. You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient. What You'll Work On: Detection Engineering Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents Improve visibility across cloud infrastruc
XO Health believes healthcare is fixable. Become part of the community changing the face of the industry. XO Health is the first health plan designed by and for self-insured employers that delivers a more unified health experience for everyone – from those who receive care, to those who deliver it, to those who pay for it. We are growing a multi-disciplinary team of diverse and digitally empowered employees ready to rebuild trust in healthcare through comprehensive and unified transformation. CyberSecurity & Infrastructure Engineer - India (Remote) About the Role : The Cybersecurity & Infrastructure Engineer is responsible for designing, implementing, monitoring, and securing the organization's hybrid cloud and infrastructure environments. This role serves as a technical leader for cybersecurity operations, cloud security, compliance initiatives, infrastructure engineering, and incident response. The position combines hands-on infrastructure administration with cybersecurity engineering responsibilities across Microsoft Azure, Microsoft Sentinel, Microsoft 365, Entra ID, AWS, networking, endpoints, and security platforms. Engineering plays a key role in maintaining compliance with SOC 2 Type II controls, improving cyber resilience, supporting audits, and advancing the organization's security maturity. Responsibilities: SOC2 Audit Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring. Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period. Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance. Develop and maintain policies, pr
About Forma.ai: Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We’re welcoming equally driven individuals who are excited about creating something big! The Opportunity As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure security Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries. Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services. Application, data, and AI security Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations
Datadog Incident Response is an end-to-end incident operations solution native to Datadog’s unified observability and security platform. It brings the entire incident lifecycle — from alert to resolution — together in one place so engineers can respond fast with confidence instead of losing time switching between disconnected monitoring, paging, and incident tools. As a Product Marketing Manager (PMM) - Incident Response, you will develop go-to-market strategy for new products and features, create the content that enables our sales and partner teams, and touch on all areas of the business while helping move Datadog forward. We give our Product Marketing Managers the opportunity to collaborate, investigate, and idealize how we can gear our product strategy to yield the highest results. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Drive the go-to-market strategy for Datadog Incident Response products, such as Incident Management, On-Call, and Incident AI as an expert of your product area. Launch new features with compelling messaging and positioning, developing assets such as slide decks, blogs, product demos, webinars, and solution briefs. Develop high-impact sales enablement assets (battlecards, pitch decks, demos) grounded in deep market and competitive insights. Partner with cross-functional teams to execute campaigns across webinars, paid media, organic channels, and sponsored events. Drive customer marketing initiatives including case studies, testimonials, and
Get new security incident response engineer jobs by email
Daily job updates · Unsubscribe anytime