Staff Security Engineer - Detection and Response

Staff Security Engineer - Detection and Response

18 Mar 2024
Colorado, Denver, 80221 Denver USA

Staff Security Engineer - Detection and Response

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including Vimeo, Pinterest, The New York Times, and GitHub.We're building a more trustworthy Internet. Come join us.As a Staff Security Engineer on our Detection and Response team, you will help detect and respond to threats for one of the biggest online platforms in the world that handles massive amounts of traffic at very low latency.We are looking for a teammate with expertise in both security engineering and operations and that values the complement between the two. You will have the opportunity to build and integrate tooling and detections, as well as investigate threats and lead incidents. As part of the larger Security organization, we make risk-informed decisions and prioritize automations to help us scale. As the lead engineer on our team, you will design, build, and mature our detection and response program, enabling rapid detection and effective response to threats against Fastly. You will lead large, complex, cross-team projects and mentor other security engineers on our growing team.What You'll Do:

Lead the design and implementation of a robust Detection Engineering program

Develop detections and other analytics to identify threats across cloud, corporate, and edge environments

Partner closely with Engineering, Security Architecture, Risk Management, Compliance, and other teams to prioritize detections and delivery of other security initiatives

Triage and investigate security threats and lead security incidents

Research, evaluate, implement, and maintain a variety of custom and commercial security tools, such as Endpoint Detection and Response (EDR), anti-phishing, and Security Information and Event Monitoring (SIEM)

Develop strategies, frameworks, designs, automations, metrics, and processes to support the maturity of the Detection and Response program

Develop and maintain incident response playbooks and other detection and response documentation

Conduct threat hunts to discover unknown malicious activity across our environment

Participate in our on-call rotations

Mentor other team members and contribute to larger Security initiatives

What We're Looking For:At Fastly we value a diversity of voices. The following is not a laundry list, but to be effective in this role you should possess most of the following and an interest in learning more about the rest:

Expertise in utilizing Splunk to include investigating threats, developing metrics and dashboards, normalizing data feeds, and integrating with other tools

Strong understanding of attacker tactics, techniques, and procedures (TTPs) and investigating advanced threats

Experience in implementing “Detection as Code”

Experience in securing, developing detections, and responding to incidents in one major public cloud infrastructure, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP)

Experience in effectively leading large and complex security incidents from detection to remediation

Familiarity with modern security frameworks and best practices, such as the MITRE ATT&CK framework and NIST CSF

Proficiency in one or more general purpose programming languages such as Python, Ruby, Go, or Rust

Experience with Linux administration at scale, associated intrusion/manipulation techniques, and standard methodologies for system hardening and process isolation

We’ll be super impressed if you have experience in any of these:

Built a Detection Engineering pipeline

Built and led threat hunts

Published research on detection engineering or threat intelligence

Developed automations to improve security operations

Familiarity with content delivery networks (CDN), edge cloud platforms, or other Fastly products and services

Work Hours:

This position will require you to be available during core business hours.

Work Locations & Travel Requirements:This position is open to the following preferred office locations:

San Francisco, CA

Los Angeles, CA

Denver, CO

New York City, NY

Fastly currently embraces a largely hybrid model for most roles which allows employees flexibility to split their time between the office and home.Salary:The estimated salary range for this position is $167,790 to $209,740.Starting salary may vary based on permissible, non-discriminatory factors such as experience, skills, qualifications, and location.This role may be eligible to participate in Fastly’s equity and discretionary bonus programs.Benefits:We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too. We support our teams with great benefits that start on the first day of your employment with Fastly. Curious about our offerings?We offer a comprehensive benefits package including medical, dental, and vision insurance. Family planning, mental health support along with Employee Assistance Program, Insurance (Life, Disability, and Accident), a non-accrual vacation policy and up to 18 days of accrued paid sick leave are there to help support our employees. We also offer 401(k) (including company match) and an Employee Stock Purchase Program. For 2024, we offer 10 paid local holidays, 11 paid company wellness days.Why Fastly?

We have a huge impact. Fastly is a small company with a big reach. Not only do our customers (https://www.fastly.com/customers) have a tremendous user base, but we also support a growing number of open source projects and initiatives (https://www.fastly.com/open-source/) . Outside of code, employees are encouraged to share causes close to their heart with others so we can help lend a supportive hand.

We love distributed teams. Fastly’s home-base is in San Francisco, but we have multiple offices and employees sprinkled around the globe. As a new hire, you will be able to attend our IN-PERSON new hire orientation in our San Francisco office! It is an exciting week-long experience that we offer to new employees to build connections with colleagues across Fastly, participate in hands-on learning opportunities, and immerse yourself in our culture firsthand.

We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful every day.

We are passionate. Fastly is chock full of passionate people and we’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team. If you think you might be a fit please apply! A fully completed application and resume or CV are required when applying.Fastly is committed to ensuring equal employment opportunity and to providing employees with a safe and welcoming work environment free of discrimination and harassment. Our employment decisions are based on business needs, job requirements and individual qualifications. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, family or parental status, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.Consistent with the Americans with Disabilities Act (ADA) and federal or state disability laws, Fastly will provide reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact your Recruiter, or the Fastly Employee Relations team at candidateaccommodations@fastly.com or 501-287-4901.Fastly collects and processes personal data submitted by job applicants in accordance with our Privacy Policy (https://www.fastly.com/privacy) . Please see our privacy notice for job applicants (https://www.fastly.com/privacy-job-applicants) .

Related jobs

  • Staff Product Security Engineer - 2406174566W

  • Business Title: GSOC (Global Security Operations Center) Incident Response Manager

  • Job Number 24062158

  • Job Number 24062106

  • As a Software Engineer for the Application Security team, you will integrate and engineer scalable security solutions throughout each phase of the software development lifecycle (SDLC) to protect our customers from potential security threats and attacks. We work closely with product and platform engineers across various domains of the Datadog stack, driving a culture of empowering engineers to have strong security ownership of their products and services through the development of security resources and tools that help promote a secure by default model. Not only do we partner with engineering teams to identify security risks that can impact our overall security posture, we work alongside them and collaborate to develop security solutions and standards to mitigate these risks to our customers and their data. You will be involved in every step of the team\'s work: discussing with other teams, designing projects, building and operating them (in a full DevSecOps manner). You\'ll join at an ideal time for making a big impact. Our product is seeing very high growth, with the platform becoming more interactive and new products and features being developed regularly including products for the Security space. At Datadog, we value people from all walks of life. We understand not everyone will meet all the above qualifications on day one. That\'s okay. If you\'re passionate about technology and want to grow your skills, we encourage you to apply. What You\'ll Do: Get a deep understanding of Datadog\'s software development life cycle, software supply chain, build pipelines, delivery mechanisms and configuration management Design, implement, operate and maintain systems improving the security of Datadog against supply-chain attacks Work with engineering teams to align new features to achieve world-class security. Build security into Datadog\'s SDLC from design to development, testing, deployment, and even in the use of our products by customers. Empathize with the full spectrum of our customers and our engineers by advocating for effective solutions that scale with the needs of our business and our customers. Serve as a subject matter expert to other teams when it comes to building, and delivering/deploying code at Datadog Who You Are: Passionate about advocating for and implementing solutions to complex problems, at-scale, in a large multi-cloud environment. You don\'t want to just provide security recommendations, you want to help implement them. You have prior experience in Development Operations, Software Engineering, Site-Reliability Engineering, Compute engineering, Systems Engineering. Fluent in one or more modern coding languages (Python, Go, JavaScript, etc.). Have experience with one of the major cloud providers (AWS, Azure, GCP) and infrastructure workloads (Kubernetes or containerization). Able to work both independently and collaboratively, willing to work in a fast paced, high growth environment. You stay updated with modern security best practices, technologies and emerging threats Benefits and Growth: New hire stock equity (RSUs) and employee stock purchase plan (ESPP) Continuous professional development, product training, and career pathing Intradepartmental mentor and buddy program for in-house networking An inclusive company culture, ability to join our Community Guilds (Datadog employee resource groups) Access to Inclusion Talks, our internal panel discussions Free, global mental health benefits for employees and dependents age 6+ Competitive global benefits Benefits and Growth listed above may vary based on the country of your employment and the nature of your employment with Datadog. About Datadog We\'re on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at a high scale - trillions of data points per day - providing always-on alerting, metrics visualization, logs, and app ication tracing for tens of thousands of companies. Our engineering culture values pragmatism, honesty, and simplicity to solve hard problems the right way. The reasonably estimated salary for this role at Datadog ranges from $187,000 to $240,000, plus a competitive equity package, and may include variable compensation. Actual compensation is based on factors such as the candidate\'s skills, qualifications, and experience. In addition, Datadog offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan #LI-EK1

  • Job Description

  • Job Number 24036883

Job Details

Jocancy Online Job Portal by jobSearchi.