Security Engineer - Incident Response
Job description
About the role
You will investigate security events through our SIEM and SOAR technology to uncover hidden threats and drive immediate remediation. You will design alerts to monitor both our customer and corporate environments for anomalous behavior and potential compromise. You will share insights gleaned from SOAR case work with relevant security team members in order to drive more security feature implementation to the product or corporate environment. You will respond to ongoing incidents, investigate historical compromises, and provide adept analysis and findings to guide executive communication. You will establish strategies for threat detection, alerting, and response that align with our risk tolerance and operational reality. You will initiate reactive threat hunting engagements by performing endpoint, network, application, and log analysis across complex infrastructures. You will establish processes and build 'playbooks' of operational response to security events and/or incidents to ensure consistency and scalability. You will provide mentorship and technical expertise to junior team members to assist their technical development and foster a culture of continuous learning.
Key facts
What you'll do
Investigate security events through our SIEM and SOAR technology to identify indicators of compromise and attack patterns.
Design alerts to monitor both our customer and corporate environments for anomalous behavior, policy violations, and signs of intrusion.
Share insights gleaned from SOAR case work with relevant security team members in order to drive more security feature implementation to the product or corporate environment.
Respond to ongoing incidents, investigate historical compromises, and provide adept analysis and findings to guide remediation and stakeholder communication.
Establish strategies for threat detection, alerting, and response that balance security rigor with business needs and operational constraints.
Initiate reactive threat hunting engagements by performing endpoint, network, application, and log analysis to surface hidden threats.
Establish processes and build 'playbooks' of operational response to security events and/or incidents to ensure consistency, repeatability, and scalability.
Maintain familiarity with Threat Intelligence and keep up-to-date on modern threats, tactics, techniques, and procedures from the security community.
Build and support security-focused tools and services that automate detection, response, and reporting for security operations.
Provide mentorship and technical expertise to junior team members to assist their technical development and career growth within the security organization.
Requirements
5+ years experience in the security industry with a demonstrated track record in incident response and security investigations.
Certifications (preferred not required): OSCP, OSCE, OSWP.
Experience working with SIEM and SOAR technologies such as Splunk, Elastic, or similar platforms.
Knowledgeable of cloud & container security, and infrastructure as code principles across major public cloud providers.
Working understanding of malware analysis, reverse engineering, and host-based and memory forensics to support deep investigations.
Proficiency in programming or scripting languages (preference to Python, Go, JavaScript, or Bash) is a plus for automation and analysis tasks.
Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP/HTTPS) and how to keep them secure in production environments.
Familiarity with red & purple team exercises, adversary resilience, and cyber deception to improve detection and response capabilities.
Experience working with cloud technologies (eg. Amazon Web Services, Google Cloud Platform, etc.) and Networking and Web Application security to investigate cloud-native incidents.
Nice to have
Only items explicitly stated in the source appear under requirements; no additional nice to have preferences are specified in the provided source material.
Practical notes
This is a hybrid role working from our Dublin office 3 days per week and you will report to the Detection and Response Manager.
Cash compensation range for this position is €70,000 - €107,800 EUR, inclusive of base salary and potential overtime pay where applicable for eligible roles.
In addition to the cash compensation above, Squarespace employees are eligible to be granted an option to purchase our common stock.
Full benefits include health insurance with 100% covered premiums for you, your spouse or partner and your dependent children including medical, dental, and vision, life and income protection, fertility and adoption benefits, Headspace mindfulness app subscription, global employee assistance program, pension benefits with employer match, flexible paid time off, 26 weeks paid maternity leave and 12 weeks paid paternity leave, 2 weeks paid family care leave, annual tax-free stipend, education reimbursement, employee donation match to community organizations, 7 global employee resource groups, free lunch and snacks, and close proximity to cultural landmarks such as Dublin Castle and St. Patrick's Cathedral.
Employment is full-time and located in Dublin, Ireland.