Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
23andMe is seeking a Security Operations Engineer to lead incident response, threat detection, and automation architecture within the security team. You will act as Incident Commander, triage alerts across endpoints, identity, cloud, and applications, and design scalable threat detections and response automation.
The role requires 4+ years in security operations, hands-on threat hunting and incident investigation, proficiency with Python scripting, EDR, SIEM platforms, and cloud tools like AWS,
Role: Security Operations Engineer leading incident response, threat detection, and automation architecture within 23andMe's security team.
serve as Incident Commander, triage and investigate alerts across endpoint, identity, cloud, and application telemetry; design and tune threat detections; build automation and integrations to improve response efficiency; maintain and enhance incident response runbooks; partner with cross-functional teams to reduce detection and response times; participate in an on-call rotation.
4+ years in security operations, detection engineering, or incident response; hands‑on experience with threat detection, threat hunting, and incident investigation; proficiency with scripting (Python preferred), EDR, SIEM platforms, and cloud/enterprise tools such as AWS, Okta, CrowdStrike, Splunk, or Datadog; strong communication skills; Bachelor’s degree or equivalent.
HighValue: incident command, detection engineering, threat hunting, threat detection automation, incident response, cloud security, enterprise security stack.
WorkSetup: not specified; likely hybrid or remote based on location.