Posted on: 17/09/2026
Role : Staff Security Engineer - Detection & Response
Your goal is to improve the education process and better the lives of students by keeping their data secure.
What you will do :
- Triage and investigate alerts from our SIEM/UEBA, endpoint detection and response, cloud, and email security platforms to determine whether indicators of compromise represent a real intrusion
- Declare, lead, and manage security incidents end to end - endpoint compromise, cloud and infrastructure compromise, credential theft, phishing, and insider risk - through containment, eradication, and recovery
- Own written incident documentation, including timelines, root cause analysis, and post-incident reviews that drive durable fixes rather than one-off cleanup
- Build, tune, and maintain detection content to expand coverage of real attacker behavior while reducing false positives and alert fatigue
- Develop and maintain incident response playbooks and runbooks
- Between incidents, contribute to security engineering work : deploying and operating security tooling in our cloud environment, closing logging and telemetry gaps, and automating response actions
- Partner with IT, engineering, and cloud platform teams to drive remediation of identified weaknesses to closure
What you'll bring :
- 7+ years of relevant work experience, with significant time spent in security operations, detection and response, or incident response
- Hands-on experience investigating alerts across SIEM/UEBA and endpoint detection and response tooling, and separating true positives from noise at volume
- Demonstrated experience leading incident response from detection through recovery, including coordinating responders and stakeholders across teams
- Strong understanding of attacker tradecraft and common attack paths across endpoint, identity, network, and cloud, and familiarity with a framework such as MITRE ATT&CK
- Working knowledge of security in cloud environments, ideally AWS, including identity, logging, and the misconfigurations attackers most often abuse
- Experience writing and tuning detection logic, correlation rules, or queries against large log data sets
- Scripting and automation ability, such as Python, and comfort working with open-source tools and APIs to connect systems and remove manual effort
- Practical familiarity with Windows, macOS, and Linux internals, and the forensic artifacts each produces during an investigation
- Sound judgment and composure under pressure, including the ability to make decisions with incomplete information
- Excellent written and oral communication skills, including the ability to explain an incident clearly to both engineers and executives
- Ability to work independently and with various other teams across the organization
- Creative, resourceful, and adaptive problem solving
Stand Out Qualifications :
- Experience with a SIEM or UEBA platform such as Exabeam, and an endpoint detection and response platform such as SentinelOne
- Experience working in AWS with features such as GuardDuty, CloudTrail, Security Hub, Inspector, IAM, WAF and Shield
- Experience managing detection content as code, under version control and peer review
- Familiarity with SOAR platforms and automated response workflows
- Digital forensics, malware analysis, or reverse engineering experience
- Experience working with container technologies including Docker and Kubernetes
- Relevant certifications such as GCIH, GCIA, GCFA, OSCP, or AWS Certified Security - Specialty
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1672063