Security Engineer, Incident Response
Job description
About the role
At Twilio, we are redefining how the world communicates by providing the foundational building blocks for all forms of digital interaction. Our mission is to power the communications and collaboration needs of hundreds of thousands of businesses and millions of developers through innovative, programmable platforms. As a remote-first organization, Twilio champions flexibility, global inclusion, and a culture of connection, enabling employees to thrive while making a significant global impact. We are currently seeking a dedicated Security Engineer to join our Security Incident Response Team (SIRT) in Ireland, focusing on protecting our critical infrastructure and services.
What you'll do
Your primary responsibility will be to lead and support the response to all security events and incidents across Twilio's complex global infrastructure, services, and applications. You will act as a key technical leader during incident lifecycles, performing triage, containment, and remediation while driving post-incident improvements.
- Lead and support the response to all security events and incidents across Twilio's complex global infrastructure, services and applications.
- Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
- Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
- Work to improve Twilio's security and reliability posture by driving identified betterments from security events and incidents.
- Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
- Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
- Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work.
- Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.
Requirements
To be successful in this Security Engineer, Incident Response role, you must possess demonstrable experience and expertise in several critical technical and interpersonal areas. Twilio requires the following qualifications for this position:
- Proven experience: 3+ years of security incident response in a production-cloud environment.
- Subject-matter expertise: Demonstrated knowledge on security issues, threats, and associated technologies.
- AI Integration: Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections.
- Architectural Proficiency: Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment.
- Cross-Stack Experience: Experience working across a technology stack to investigate and resolve difficult security challenges and initiatives.
- SIEM Expertise: Experience with SIEM platforms and the demonstrated ability to extend their functionality for detection and analysis.
- SOAR Proficiency: Experience with SOAR tools and a proven track record of automating manual security processes.
- Cloud Platform Experience: Hands-on experience in either AWS, GCP, or other large cloud platforms.
- Communication Skills: Excellent written and verbal communication skills to clearly articulate complex technical issues.
- Influence and Collaboration: Ability to influence and build effective working relationships with every level of the organization, including executive stakeholders.
Additionally, the role requires the individual to be located in Ireland or the United Kingdom in alignment with Twilio's remote work policies. While the position is remote-first, occasional travel may be required to participate in project or team in-person meetings.
Desired qualifications
Beyond the required qualifications, the following desired qualifications indicate advanced capability in specialized areas critical to Twilio's security posture:
- AI Model Security & Posture Management: Support Implementation of controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning.
- AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data.
- Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
- Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks.
Location
This role will be remote, and based in Ireland or U.K.
Travel
We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.
What We Offer
Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.