Security Operations Engineer: Incident Response & Threat Automation

23andMe, Inc.

Palo Alto (CA)

Hybrid

USD 120,000 - 150,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

23andMe is seeking a Security Operations Engineer to lead incident response, threat detection, and automation architecture within the security team. You will act as Incident Commander, triage alerts across endpoints, identity, cloud, and applications, and design scalable threat detections and response automation.

The role requires 4+ years in security operations, hands-on threat hunting and incident investigation, proficiency with Python scripting, EDR, SIEM platforms, and cloud tools like AWS,

Qualifications

  • 4+ years in security operations, detection engineering, or incident response.
  • Hands-on experience with threat detection, threat hunting, and incident investigation.
  • Scripting (Python preferred), EDR, SIEM platforms, and cloud/enterprise tools such as AWS, Okta, CrowdStrike, Splunk, or Datadog.
  • Strong communication skills.
  • Bachelor’s degree or equivalent.

Responsibilities

  • Serve as Incident Commander, triage and investigate alerts across endpoint, identity, cloud, and application telemetry.
  • Design and tune threat detections.
  • Build automation and integrations to improve response efficiency.
  • Maintain and enhance incident response runbooks.
  • Partner with cross-functional teams to reduce detection and response times.
  • Participate in an on-call rotation.

Skills

Python scripting
Strong communication

Education

Bachelor's degree or equivalent

Tools

AWS
Okta
CrowdStrike
Splunk
Datadog
EDR
SIEM

Job description

23andMe is seeking a Security Operations Engineer to lead incident response, threat detection, and automation architecture within the security team. You will act as Incident Commander, triage alerts across endpoints, identity, cloud, and applications, and design scalable threat detections and response automation.

The role requires 4+ years in security operations, hands-on threat hunting and incident investigation, proficiency with Python scripting, EDR, SIEM platforms, and cloud tools like AWS,

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Engineer
Security Operations Engineer

23andMe, Inc. • Palo Alto (CA)

On-site
USD 120,000 - 150,000
Senior Security Analyst & Incident Commander
Senior Security Analyst & Incident Commander

23andMe, Inc. • Palo Alto (CA)

On-site
USD 110,000 - 140,000
On-call bonus
Security Engineer, Incident Response
Security Engineer, Incident Response

Meta • Menlo Park (CA)

On-site
USD 180,000 - 280,000
Incident Response Engineer - Senior, Threat Detection
Incident Response Engineer - Senior, Threat Detection

Meta • Menlo Park (CA)

On-site
USD 180,000 - 280,000
Security Engineer
Security Engineer

Atlas Search • New York (NY)

On-site
USD 140,000 - 190,000
Remote Security Engineer - Incident Response & Automation
Remote Security Engineer - Incident Response & Automation

Jobgether SRL • United States

Remote
USD 60,000 - 100,000
Remote-first working model
Diversity and inclusion networks
Wellbeing days
+3
SecOps Engineer: Cloud, EDR, & Incident Response
SecOps Engineer: Cloud, EDR, & Incident Response

Cellebrite • United States

On-site
USD 120,000 - 170,000
Lead Security Detection & Response Engineer
Lead Security Detection & Response Engineer

Cybersecurity Jobs • Kansas City (MO)

Hybrid
USD 120,000 - 190,000
Sr. Security Engineer, Threat Detection and Response
Sr. Security Engineer, Threat Detection and Response

Cypress HCM • United States

On-site
USD 174,000 - 190,000
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5