Were looking for a hands-on incident response expert thats passionate about investigating real threats, building scalable detections, and improving automation across modern cloud-native environments. This is a high-impact role within our security group, ideal for someone who thrives on both investigation and building long-term solutions. In your day-to-day, youll:
Investigate complex security incidents in cloud (AWS/GCP), containerized (Kubernetes), and endpoint environments
Design and maintain detection rules and anomaly-based logic to identify emerging threats in production systems
Automate forensic evidence collection and response actions across diverse platforms and services
Collaborate with SOC analysts, Security Architects, and Engineering teams to improve detection coverage and data visibility
Lead incident retrospectives and document technical findings, response steps, and process improvements
Develop and maintain investigation playbooks, chain-of-custody protocols, and sprint-based IR deliverables
Participate in on-call rotations and contribute to incident readiness exercises and escalation protocols.
Investigate complex security incidents in cloud (AWS/GCP), containerized (Kubernetes), and endpoint environments
Design and maintain detection rules and anomaly-based logic to identify emerging threats in production systems
Automate forensic evidence collection and response actions across diverse platforms and services
Collaborate with SOC analysts, Security Architects, and Engineering teams to improve detection coverage and data visibility
Lead incident retrospectives and document technical findings, response steps, and process improvements
Develop and maintain investigation playbooks, chain-of-custody protocols, and sprint-based IR deliverables
Participate in on-call rotations and contribute to incident readiness exercises and escalation protocols.
Requirements:
4+ years of hands-on experience in incident response or security operations
Proficiency in Python for scripting, automation, and tool development
Strong knowledge of cloud platforms (AWS and/or GCP) and container technologies (Kubernetes)
Experience with detection engineering, threat hunting, and automated response tooling
Familiarity with scripting or automation tools for investigation and remediation
Excellent written and verbal communication skills in English
Ability to work effectively with global teams across time zones.
4+ years of hands-on experience in incident response or security operations
Proficiency in Python for scripting, automation, and tool development
Strong knowledge of cloud platforms (AWS and/or GCP) and container technologies (Kubernetes)
Experience with detection engineering, threat hunting, and automated response tooling
Familiarity with scripting or automation tools for investigation and remediation
Excellent written and verbal communication skills in English
Ability to work effectively with global teams across time zones.
This position is open to all candidates.