← Back to job listings
CL
Security Response Engineer (Incident Response)
Chainlink Labs · United States
About The Role
Join our team as a Security Response Engineer, where you will own the full security incident response lifecycle. You will serve as the incident commander, coordinating high-severity incidents from scoping to recovery and post-mortem improvements. You will also be involved in operational responsibilities, project work, and continuous improvement of our response capabilities.
- Assumer la responsabilité de l'ensemble du cycle de vie de la réponse aux incidents de sécurité, en agissant en tant que commandant d'incident pour les incidents de haute gravité.
- Participer activement aux responsabilités opérationnelles de l'équipe, y compris la création et le perfectionnement des détections, des playbooks et des processus.
- Collaborer avec les parties prenantes internes et externes pour améliorer continuellement les capacités et l'efficacité de la réponse aux incidents.
- Detections experience: ability to create and refine detections based on investigations and threat intelligence
- Experience in macOS-heavy environments: has secured and operated a predominantly macOS endpoint fleet: deploying / managing endpoint controls, telemetry collection, and performing investigations on macOS systems
- Proven incident response leadership: experience as the primary incident commander for high‑severity security incidents involving multiple teams and external stakeholders, and can independently manage incident timelines, decisions, and communications
- Previous coding experience (Python, Go, Rust, or similar): scripting for data parsing/enrichment and simple automations
- Operational rigor and investigation depth: demonstrated experience with triage, scoping, containment, and remediation across endpoint, cloud, and/or network based incidents; drives root‑cause analysis and post‑incident action items to completion
- Collaborative, straightforward communicator: writes clear incident updates and summaries; can explain risk, impact, and trade‑offs to both technical and non‑technical stakeholders; builds trust with partner teams during high‑pressure situations; comfortable handling the regular communication cadence of an incident
- Open-source contributions to security related projects
- Domain experience with blockchain/Web3 threats
- Experience with detections‑as‑code (Sigma) development and workflows
- Prior success in remote-first environments
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring