Security Engineer, Incident Response

SendGrid

United Kingdom

On-site

GBP 80,000 - 110,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Twilio is seeking a Security Engineer to lead the technical response to security events and incidents across our global infrastructure, services, and applications. You will triage, contain, remediate, and drive post-incident improvements while coordinating with R&D Engineering and R&D Business teams.

You will join a team of highly technical Security Engineers focused on bespoke and standard response processes, threat mitigation, and automation.

Qualifications

  • Proven experience: 3+ years of security incident response in a production-cloud environment.
  • Subject-matter expert on security issues and technologies.
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections.
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment.
  • Experience working across a technology stack on difficult security challenges and initiatives.
  • Experience with SIEM platforms and the ability to extend their functionality.
  • Experience with SOAR tools and automating manual security processes.
  • Experience in either AWS, GCP, or other large cloud platform.
  • Excellent written and verbal communication skills.
  • Ability to influence and build effective working relationships with every level of the organization.

Responsibilities

  • Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Skills

Security incident response
Cloud security
AI for security
SOAR
SIEM
AWS/GCP
Communication skills

Tools

SIEM platforms
SOAR tools
AWS
GCP

Job description

About the job

The Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities
  • Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.
Qualifications

Required:

  • Proven experience: 3+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks.
Location

This role will be remote, and based in Ireland or U.K.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Security Incident Response Engineer
Remote Security Incident Response Engineer

SendGrid • United Kingdom

On-site
GBP 80,000 - 110,000
Principal Presales Engineer
Principal Presales Engineer

Twilio • United Kingdom

On-site
GBP 85,000 - 110,000
Competitive pay
Generous time off
Healthcare benefits
+3
Strategic Account Executive
Strategic Account Executive

SendGrid • United Kingdom

On-site
GBP 90,000 - 150,000
Digital Sales Representative
Digital Sales Representative

Twilio • United Kingdom

Remote
GBP 50,000 - 80,000
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

AMAZON UK • Manchester

On-site
GBP 65,000 - 100,000
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon Web Services (AWS) • Manchester

On-site
GBP 70,000 - 110,000
Security Engineer - Security Operations
Security Engineer - Security Operations

Perk • Greater London

On-site
GBP 72,000 - 85,000
Equity options
Private medical insurance
Life insurance
+2
Senior SecOps Specialist
Senior SecOps Specialist

Teya Solutions • Greater London

Hybrid
GBP 63,000 - 103,000
Health insurance
25 days annual leave
Friday lunch in the office
+2
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon • Manchester

On-site
GBP 60,000 - 85,000
Financial Manager, EMEA GTM
Financial Manager, EMEA GTM

Twilio • United Kingdom

Remote
GBP 90,000 - 120,000
Healthcare
Retirement savings program
Generous time-off
+2