About the Role
Serve as the technical lead for the incident response lifecycle, driving the containment and remediation of security threats across multi-cloud infrastructure, products, and operational environments. Balance hands-on technical investigations with leadership to coordinate response efforts, leveraging a modern security stack to protect a global travel and expense platform.
Responsibilities
- Act as the primary Incident Lead during high-severity events.
- Own the end-to-end response lifecycle: driving triage, containment, evidence capture, and post-incident root-cause analysis.
- Use Tines to build and design workflows that automate triage, enrichment, and containment actions.
- Manage and fine-tune detection rule lifecycles utilizing CrowdStrike EDR and SIEM/SOAR capabilities.
- Monitor and respond to data risks across endpoints, identity, and SaaS applications using Cyberhaven DLP.
- Identify gaps in IAM and vulnerability management and advocate for direct fixes.
- Partner with infrastructure owners to ensure new systems ship with the right telemetry, encryption, authentication, and response playbooks.
- Evaluate and design response strategies for frontier security concerns.
- Actively participate in the scheduled Incident Response on-call rotation.
Requirements
- 5+ years of experience in a dedicated Incident Response, SOC, or Security Engineering role.
- Proven track record of leading high-severity incident containment in fast-paced environments.
- Strong familiarity with the MITRE ATT&CK framework, modern adversary tactics, techniques, and procedures (TTPs), and common attack vectors targeting SaaS platforms.
- Proven experience managing and tuning detection logic within CrowdStrike Falcon (or equivalent enterprise EDR/XDR) and enterprise SIEM platforms.
- Excellent leadership skills with the ability to remain calm under pressure.
- Ability to coordinate cross-functional teams (Engineering, Legal, PR).
- Ability to clearly communicate complex technical risks to stakeholders.
Skills
- Incident Response
- Security Engineering
- Triage
- Containment
- Evidence Capture
- Root-Cause Analysis
- Automation
- SOAR
- Tines
- CrowdStrike EDR
- SIEM
- Cyberhaven DLP
- IAM
- Vulnerability Management
- MITRE ATT&CK framework
- CrowdStrike Falcon
Experience Level
- 5+ years of experience
