Staff Security Engineer - Security Operations

Pantheon

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Pantheon is seeking a Staff Security Engineer, SecOps to be the technical anchor of our security operations. You will lead major incidents, set tempo for scoping, containment, and post‑incident reviews, and partner with Legal and executives.

You will define the incident response methodology, drive threat hunting mapped to MITRE ATT&CK across cloud, endpoint, and identity surfaces, and lead AI‑assisted automation initiatives with ARES.

Qualifications

  • Staff-level role with impact beyond individual queue.
  • Experience defining incident response methodology and playbooks.
  • Experience in threat hunting and MITRE ATT&CK framework.
  • Experience with AI-assisted security automation preferred.

Responsibilities

  • Command major incidents end-to-end, run war room, coordinate stakeholders.
  • Define and improve incident response programme, SLAs, and playbooks.
  • Lead threat hunting mapped to MITRE ATT&CK across cloud, endpoints, identity.
  • Direct AI-assisted automation (ARES) roadmap and integration.

Tools

Claude
ARES

Job description

About Pantheon

Pantheon is the WebOps platform for websites that deliver extraordinary results. We believe in putting the magic of the internet in everyone's hands. That's why we're so passionate about helping developers, IT, and marketing develop, test, and release website changes faster and more reliably.

Pantheon's core values are Trust, Teamwork, Passion, and Customers First. We value individuality, humour, and balance, and we actively contribute to open-source communities.

If you're ready to be the incident authority for a platform that ships critical infrastructure for hundreds of thousands of sites, this is your role.

The Role

As a Staff Security Engineer, SecOps, you are the technical anchor of Pantheon's security operations function, and above all, the person we trust to command our hardest incidents. When something serious happens, you set the tempo: scoping, severity, containment strategy, stakeholder communication, and the post-incident work that makes us stronger every time.

This is a staff-level role, which means your impact extends well beyond your own queue. You define the incident response methodology the whole team runs on, you turn every incident and hunt into better detections in partnership with Security Engineering, and you set the direction for what our automation should do next. We are an AI-forward security team: our SOAR capability already exists inside Google SecOps, and we are building ARES, our AI-assisted incident response platform. We are not hiring you to program SOAR playbooks. We're hiring you to bring the incident judgment that tells ARES what to automate, and the AI fluency to prototype it yourself with tools like Claude.

The engineers who thrive here come from engineering-shaped backgrounds, people who script, automate, read code, and learn new systems on their feet. and pair that with deep, tested incident response craft.

What You'll Do
  • Command major incidents. Lead response for our most complex and critical incidents end-to-end — data breach scenarios, coordinated attacks, platform-level events. Run the war room, make the severity and containment calls, coordinate Engineering, Legal, and executive stakeholders, and own the blameless post-incident review.
  • Own incident response methodology. Define and continuously improve the IR programme the team operates against: severity frameworks, escalation paths, playbooks and runbooks, on-call standards, SLAs, and the continuous-improvement loop that follows every incident. You are accountable for how Pantheon responds, not just that it responds.
  • Drive the hunting detection feedback loop. Lead hypothesis-driven threat hunting mapped to MITRE ATT CK across cloud, endpoint, and identity surfaces, and make sure every hunt and every incident feeds back into higher-fidelity, lower-noise detections in partnership with Security Engineering. Establish the methodology and coverage standards the team measures itself by.
  • Direct AI-assisted automation (ARES). Set the automation
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

WebHosting • United States

Hybrid
USD 120,000 - 180,000
Incident Command & AI-Driven SecOps Lead
Incident Command & AI-Driven SecOps Lead

Pantheon • United States

Remote
USD 180,000 - 240,000
Security Engineer
Security Engineer

Pantheon • San Francisco (CA)

Remote
CAD 90,000 - 140,000
Health & Wellness
Remote & In‑Office
Flexible Time‑Off
+5
Security Engineer II
Security Engineer II

Pantheon Systems, Inc • San Francisco (CA), Chicago (IL)

On-site
CAD 94,000 - 118,000
Equity plan
Flexible time off
Medical insurance
+4
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Security Administrator
Security Administrator

aegis-ai • United States

On-site
USD 65,000 - 90,000
Security Administrator
Security Administrator

AegisAI, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
Detection and Response Platform Engineer
Detection and Response Platform Engineer

Jobtailor • Sunnyvale (CA)

On-site
USD 150,000 - 230,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000