Incident Response Security Engineer — IR Automation

Replit

Foster City (CA)

On-site

USD 170,000 - 250,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Salary & equity
401(k) match
Health insurance
Dental & Vision
Paid leave
Flexible time off
Commuter benefits
Wellness stipend
Office setup reimbursement

Job summary

Replit is seeking a Security Engineer with deep incident response experience to defend a fast-moving, cloud-native platform. You will lead investigations from signal to root cause, coordinate containment with Security, SRE and Engineering, and inform stakeholders during high-velocity incidents.

You will write scripts and tooling to automate triage, evidence collection, and containment, and translate lessons into better detections and platform hardening for faster responses in the future.

Qualifications

  • Proven experience leading or managing security incidents in cloud/SaaS
  • Strong hands-on investigation with SIEM and cloud logs
  • Proficiency scripting in Python/Go/Bash for automation
  • Solid knowledge of Google Cloud Platform and GKE
  • Working knowledge of Kubernetes and containers
  • Understanding of identity systems, SaaS architectures, and cloud attack paths
  • Familiarity with IR frameworks (e.g., NIST 800-61) and vulnerability analysis

Responsibilities

  • Serve as incident commander for security incidents from detection through containment and post-incident review
  • Coordinate response across Security, SRE, Engineering, Legal and leadership
  • Communicate incident status, impact and risk to technical and executive audiences
  • Develop scripts and tooling to speed up triage, evidence collection, and containment
  • Turn incident findings into new detections and improved logging/visibility
  • Lead blameless post-incident reviews and drive remediation to completion
  • Run tabletop exercises to test readiness and identify gaps

Skills

Incident response
SIEM
Cloud logs
Python
Go
Bash
GCP
Kubernetes
Containers
Identity systems
CI/CD
NIST 800-61

Tools

SOAR

Job description

Replit is seeking a Security Engineer with deep incident response experience to defend a fast-moving, cloud-native platform. You will lead investigations from signal to root cause, coordinate containment with Security, SRE and Engineering, and inform stakeholders during high-velocity incidents.

You will write scripts and tooling to automate triage, evidence collection, and containment, and translate lessons into better detections and platform hardening for faster responses in the future.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident-Response Security Engineer: Lead & Automate IR
Incident-Response Security Engineer: Lead & Automate IR

Replit • United States

Remote
USD 130,000 - 180,000
Security Engineer - Incident Response
Security Engineer - Incident Response

Replit • United States

Remote
USD 130,000 - 180,000
Remote Security Engineer - Incident Response & Automation
Remote Security Engineer - Incident Response & Automation

Jobgether SRL • United States

Remote
USD 60,000 - 100,000
Remote-first working model
Diversity and inclusion networks
Wellbeing days
+3
Senior AI-Driven Incident Response Engineer
Senior AI-Driven Incident Response Engineer

Intuit Inc. • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Security Incident Response Engineer - Automation & IR Lead
Security Incident Response Engineer - Automation & IR Lead

Twitch • San Francisco (CA)

On-site
USD 167,000 - 213,000
Medical, Dental, Vision & Disability
401(k)
Parental Leave
+2
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Senior Incident Response Engineer: AI-Driven SOC Leader
Senior Incident Response Engineer: AI-Driven SOC Leader

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Security Incident Response Engineer — Cloud & Automation
Security Incident Response Engineer — Cloud & Automation

Amazon • Seattle (WA)

Hybrid
USD 159,000 - 202,000
Medical, Dental, Vision & Disability
401(k)
Maternity & Parental Leave
+2
Senior Cyber Incident Response Engineer
Senior Cyber Incident Response Engineer

Acrisure • Atlanta (GA)

On-site
USD 120,000 - 180,000