Security Engineer, Incident Response responsible for leading and executing cybersecurity incident responses at Instructure. Collaborating with teams to enhance security initiatives and procedures.
Responsibilities
Lead and direct all phases of the incident response lifecycle, from initial detection and triage to containment, eradication, and post-incident analysis and review.
Conduct in-depth forensic analysis of security incidents to determine the root cause, assess the impact, and define the scope of the incident.
Collaborate with engineering and product teams to develop and implement effective containment and eradication strategies for SaaS environments.
Coordinate recovery activities to ensure the timely and secure restoration of impacted systems and services.
Support design, develop, and implement robust detection rules and signatures across our security toolset (e.g., SIEM, EDR, WAF, CSPM) to proactively identify malicious activity.
Continuously refine and optimize detection rules to minimize false positives and enhance the accuracy of our security alerts.
Evaluate and recommend new security technologies and methodologies to enhance our security posture.
Create and maintain detailed documentation for all incident response procedures, playbooks, and runbooks.
Develop and document security best practices and guidelines for engineering and product teams.
Contribute to the creation and maintenance of our overall security knowledge base.
Schedule and manage tabletop exercises to test and refine our incident response capabilities.
Document the results of tabletop exercises and track the remediation of any identified gaps.
Provide training and guidance to junior analysts and other team members on incident response and security best practices.
Requirements
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Proven experience in a security role with a strong focus on incident response and security engineering.
Demonstrated experience leading incident response for a SaaS product company.
Strong understanding of common attack techniques, tactics, and procedures (TTPs).
Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Elastic SIEM, Microsoft Sentinel) and developing detection rules.
Familiarity with Endpoint Detection and Response (EDR) solutions.
Proficiency in at least one scripting language (e.g., Python, Go, etc).
Excellent analytical, problem-solving, and communication skills.
Proven ability to write clear and concise documentation.
This position includes participation in an on-call rotation
Benefits
Competitive compensation, plus all full-time employees participate in our ownership program - because everyone should have a stake in our success.
Flexible schedules and a remote-friendly culture, with hybrid or onsite work options available in some regions for specific roles
Generous time off, including local holidays and our annual company-wide “Dim the Lights” week in late December, when we encourage everyone to step back and recharge
Comprehensive wellness programs and mental health support
Annual learning and development stipends to support your growth
The technology and tools you need to do your best work — typically a Mac, with PC options available in some locations
Motivosity employee recognition program
A culture rooted in inclusivity, support, and meaningful connection
Product Specialist BDE responsible for advising on Networks and Cybersecurity at Datacom. Supporting development of product strategies and sales ideas to drive customer success.
Security Guard at Commissionaires Nova Scotia ensuring safety, security, and protection for clients. Engaging veteran personnel in critical roles across various environment.
Fachkraft für Schutz und Sicherheit supporting public and private safety while protecting individuals and assets. Engage in preventing conflicts and recognizing dangers across various settings.
Senior Software Engineer at eBay developing cloud - native security services and mentoring teams. Focused on high availability and secure coding practices with a scalable infrastructure.
Project manager for IT infrastructure within IT security projects at DATAGROUP. Engaging in project management and communication with technical teams and clients.
Senior SAP Security Consultant designing future SAP security solutions for clients. Engaging with technological challenges and supporting digital transformation efforts.
Cybersecurity Engineer managing identity and access controls for enterprise applications at Truist. Expertise in Microsoft Entra and troubleshooting access issues in complex environments.
Cybersecurity Compliance Consultant performing SOX IT compliance testing at Truist. Assessing corporate cybersecurity compliance and managing risk and compliance functions across various locations.
IT Security Consultant conducting technical audits and consulting on cybersecurity for various sectors. Developing tailored security strategies and ensuring compliance with regulations.
Senior Consultant in IT Security conducting audits and creating security strategies. Advising clients in cybersecurity and ensuring compliance with regulations.