Security Engineer

five9

United States

Hybrid

USD 66,000 - 175,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity
Performance bonus
Remote work
Hybrid work schedule

Job summary

Five9 seeks an experienced security engineer to build and operate the AI-enriched triage system. You’ll own incidents end-to-end, design automated detections, and push the envelope on threat intelligence and hunting. This role emphasizes practical solutions, clear incident timelines, and robust documentation.

You’ll work with Python-based tooling, telemetries from multiple sources, and modern automation to reduce repetitive work and improve system effectiveness.

Qualifications

  • Hands-on security operations experience with incident explanations.
  • Proficiency in Python or scripting to automate recurring problems.
  • Knowledge of detection logic and telemetry from endpoints, cloud, identity, and SaaS.
  • Ability to define success, build practical solutions, and document postmortems.

Responsibilities

  • Own security incidents through scoping, containment, investigation, and remediation.
  • Create, tune, test, version, measure, and retire detections by outcomes.
  • Build playbooks, integrations, and automated workflows to reduce manual work.
  • Track threat activity and turn intelligence into detections and hardening actions.
  • Contribute to threat hunting and improve AI-assisted triage tooling.
  • Handle escalations and feed results back into the system for improvement.

Skills

Security operations
Python
Detection logic
Incident response
Clear communication

Job description

Role overview

Build and operate the engineering systems behind an AI-enriched security triage process. The role is centered on incident response, detection engineering, response automation, threat intelligence, hunting, and the development of reliable AI tooling not routine alert handling. You will be given security problems to solve end to end and will need to define the outcome, implement the solution, and communicate the reasoning clearly.

Responsibilities
  • Own security incidents through scoping, containment, forensic investigation, documentation, remediation, and follow-through.
  • Create, tune, test, version, measure, and retire detections based on operational outcomes rather than alert volume.
  • Build playbooks, integrations, and automated workflows that reduce repetitive response work.
  • Track relevant threat activity and turn intelligence into detections, hunting hypotheses, and hardening actions.
  • Contribute to hypothesis-driven threat hunting and improve the agents, prompts, and enrichment logic used by the triage pipeline.
  • Handle escalations surfaced by the pipeline and feed investigation results back into the system to improve it.
Requirements
  • Hands-on security operations experience, including the ability to explain incidents in detail.
  • Proficiency in Python or another scripting language, with a preference for solving recurring operational problems through code.
  • Working knowledge of detection logic, log pipelines, and telemetry from endpoint, identity, cloud, and SaaS sources.
  • Ability to take an ambiguous security problem, define what success means, and build a practical solution.
  • Clear written communication for incident timelines, design documentation, and postmortems.
  • Self-direction, sound judgment, and comfort working with limited day-to-day supervision.
Nice to have
  • GCP or AWS experience, including cloud logging, IAM, and cloud-specific failure modes.
  • Experience with Tines, n8n, or similar automation tools, including judgment about when to productionize a workflow in code.
  • Agent development, prompt engineering, or experience operating AI-assisted detection and triage systems.
Benefits and work setup
  • Requires working Pacific Time hours, from 9:00 a.m. to 5:00 p.m.
  • Fully remote outside a 30-mile radius of an office; within that radius, the role is hybrid with three office days per week.
  • The source lists a United States base salary range of $66,300-$174,700, plus potential bonus, equity, and benefits subject to applicable plans.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Analyst
Staff Security Analyst

turing • United States

Remote
USD 198,000 - 242,000
Salary $220,000
Senior IC track
Staff Security Engineer
Staff Security Engineer

robotsandpencils • United States

Remote
USD 77,000 - 106,000
Senior Security Engineer
Senior Security Engineer

Stanton House • United States

On-site
USD 130,000 - 160,000
Equity in a revolutionary startup
Remote work with optional team events
Opportunity to develop detection/automation skills
Staff Security Engineer
Staff Security Engineer

Primerai • United States

Remote
USD 175,000 - 235,000
Remote work
Comprehensive benefits
401(k) with match
+4
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Security Engineer, Detection and Response
Security Engineer, Detection and Response

OpenAI • United States

On-site
USD 293,000 - 385,000
Senior Security Engineer
Senior Security Engineer

muonspace • United States

On-site
USD 193,000 - 218,000
Competitive equity grant
Comprehensive benefits
Hybrid/remote work options
+3
Director of Security Operations
Director of Security Operations

backblaze • United States

Remote
USD 205,000 - 230,000
RSU grants for full-time employees
ESP P program
401K plan
+5
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
401(k) matching
Paid time off
+2