Search jobs > San Francisco, CA > Detection engineer

Senior Security Engineer, Detection & Response

Postman
San Francisco, United States
$180K-$212K a year
Full-time

Who Are We?

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs faster.

More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world.

Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

The Opportunity

We are seeking an experienced Senior Security Engineer, Detection & Response to join our dynamic security team. In this role, you will provide Level 2 support to our managed Security Operations Center (SOC), monitoring and analyzing security alerts and emerging threats across our corporate, cloud and production environments to identify and respond to potential security incidents and critical vulnerabilities.

You’ll work closely with the broader security and IT team and other engineering teams to develop a strong understanding of our ecosystem to enable you to act effectively as an Incident Commander when required, and coordinate incident resolution with cross-functional teams to ensure 24 / 7 coverage.

This understanding will aid you in your threat hunting and forensic investigations to uncover indicators of compromise and patterns of malicious activity, as well as fine-tune and develop additional detection rules, configurations, custom playbooks and automations tailored to our environment in collaboration with our managed SOC.

In the area of vulnerability management, you will monitor security advisories and threat intelligence feeds, and drive proactive actions within the organization.

Your collaboration with cross-functional teams will be essential in proactively detecting and responding to security threats and ensuring the overall security of our digital assets.

What You’ll Do :

Security Operations Duties :

Provide Level 2 support to a managed SOC and support moitoring security alerts and events from various sources, including corporate tools, WAF, security information and event management (SIEM) systems, and AWS to identify potential security incidents, intrusions and vulnerabilities

Conduct threat huntingand perform forensic investigations to identify indicators of compromise (IOCs) and patterns of malicious activity.

Coordinate and manager incident resolution with cross-functional teams, including acting as Incident Commander during incidents to help provide 24 / 7 coverage with other team members.

Support Cloud Detection & Response platforms to enable various automated notification and containment workflows.

Detection Engineering :

Fine-tune and develop detection riles, configurations, and automations based on new threats, lessons learned, or environmental changes.

Work with the managed SOC to develop custom playbooks.

Where possible, write scripts and develop custom tools to automate the detection and response processes. Adhere to SSDLC best practices when writing scripts or developing tools.

Identify any gaps in logging coverage to ensure we maintain the highest visibility into any threats to our environment

Manage Cloudflare security products for web application security, including WAF rules and DDoS protection.

Collaborate with cross-functional teams to proactively detect and respond to potential security threats and ensure the overall security of our organization's digital assets.

Vulnerability Management :

Monitor security advisories, threat intelligence feeds, and vendor updates for critical threats to drive action back into the enterprise / product organization.

About You :

Education & Experience :

Bachelor’s degree in Computer Science, Information Security, or a related field.

Minimum of 5-7 years of experience in a SOC analyst or security operations role.

Technical Skills :

Proficiency in programming and relevant scripting languages such as Python, JavaScript, Bash, and PowerShell.

Experience with AWS security services and best practices.

Familiarity with Cloudflare, SentinelOne, Okta, and related security tools.

Understanding of network protocols, firewalls, and intrusion detection systems.

Soft Skills :

Strong analytical and problem-solving abilities.

Excellent communication skills, both written and verbal.

Ability to work independently and as part of a team.

Preferred Qualifications :

Certifications such as CISSP, CEH, and AWS Certified Security Specialty.

Experience with infrastructure as code tools (e.g., Terraform).

Knowledge of DevSecOps practices and CI / CD pipelines.

Familiarity with regulatory compliance standards (e.g., GDPR, ISO 27001).

Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures.

In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product.

We are dedicated to delivering the best products we can.

What Else?

If the role is based in the greater San Francisco area, and the we are offering a base range of $180,000 to $212,000 plus a competitive equity package.

Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend.

Salaries will vary outside of the listed metropolitan areas & the U.S.

Equal Opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Headhunters and recruitment agencies may not submit resumes / CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes.

Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

Apply Now "@context" : "http : / / schema.org","@type" : "JobPosting","datePosted" : "2024-09-30","description" : "Who Are We?

nPostman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs faster.

More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world.

Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

nWe highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

nThe Opportunity nWe are seeking an experienced Senior Security Engineer, Detection & Response to join our dynamic security team.

In this role, you will provide Level 2 support to our managed Security Operations Center (SOC), monitoring and analyzing security alerts and emerging threats across our corporate, cloud and production environments to identify and respond to potential security incidents and critical vulnerabilities.

nYou’ll work closely with the broader security and IT team and other engineering teams to develop a strong understanding of our ecosystem to enable you to act effectively as an Incident Commander when required, and coordinate incident resolution with cross-functional teams to ensure 24 / 7 coverage.

This understanding will aid you in your threat hunting and forensic investigations to uncover indicators of compromise and patterns of malicious activity, as well as fine-tune and develop additional detection rules, configurations, custom playbooks and automations tailored to our environment in collaboration with our managed SOC.

nIn the area of vulnerability management, you will monitor security advisories and threat intelligence feeds, and drive proactive actions within the organization.

Your collaboration with cross-functional teams will be essential in proactively detecting and responding to security threats and ensuring the overall security of our digital assets.

nWhat You’ll Do : n n n nSecurity Operations Duties : n n nProvide Level 2 support to a managed SOC and support moitoring security alerts and events from various sources, including corporate tools, WAF, security information and event management (SIEM) systems, and AWS to identify potential security incidents, intrusions and vulnerabilities n n nConduct threat huntingand perform forensic investigations to identify indicators of compromise (IOCs) and patterns of malicious activity.

n n nCoordinate and manager incident resolution with cross-functional teams, including acting as Incident Commander during incidents to help provide 24 / 7 coverage with other team members.

n n nSupport Cloud Detection & Response platforms to enable various automated notification and containment workflows. n n n n nDetection Engineering : n n nFine-tune and develop detection riles, configurations, and automations based on new threats, lessons learned, or environmental changes.

n nWork with the managed SOC to develop custom playbooks. n nWhere possible, write scripts and develop custom tools to automate the detection and response processes.

Adhere to SSDLC best practices when writing scripts or developing tools. n n nIdentify any gaps in logging coverage to ensure we maintain the highest visibility into any threats to our environment n n nManage Cloudflare security products for web application security, including WAF rules and DDoS protection.

n n nCollaborate with cross-functional teams to proactively detect and respond to potential security threats and ensure the overall security of our organization's digital assets.

n n n n nVulnerability Management : n n nMonitor security advisories, threat intelligence feeds, and vendor updates for critical threats to drive action back into the enterprise / product organization.

n n n n nAbout You : n n nEducation & Experience : n n nBachelor’s degree in Computer Science, Information Security, or a related field.

n n nMinimum of 5-7 years of experience in a SOC analyst or security operations role. n n n n nTechnical Skills : n n nProficiency in programming and relevant scripting languages such as Python, JavaScript, Bash, and PowerShell.

n n nExperience with AWS security services and best practices. n n nFamiliarity with Cloudflare, SentinelOne, Okta, and related security tools.

n n nUnderstanding of network protocols, firewalls, and intrusion detection systems. n n n n nSoft Skills : n n nStrong analytical and problem-solving abilities.

n n nExcellent communication skills, both written and verbal. n n nAbility to work independently and as part of a team. n n n n nPreferred Qualifications : n n nCertifications such as CISSP, CEH, and AWS Certified Security Specialty.

n n nExperience with infrastructure as code tools (e.g., Terraform). n n nKnowledge of DevSecOps practices and CI / CD pipelines.

n n nFamiliarity with regulatory compliance standards (e.g., GDPR, ISO 27001). n n nOur Values nAt Postman, we create with the same curiosity that we see in our users.

We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision.

Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

nWhat Else? nIf the role is based in the greater San Francisco area, and the we are offering a base range of $180,000 to $212,000 plus a competitive equity package.

Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend.

Salaries will vary outside of the listed metropolitan areas & the U.S. nEqual Opportunity nPostman is an Equal Employment Opportunity and Affirmative Action Employer.

Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Headhunters and recruitment agencies may not submit resumes / CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes.

Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman. n","title" : "Senior Security Engineer, Detection & Response - San Francisco","validThrough" : "2024-10-30","employmentType" : "FULL TIME","image" : "https : / / assets.

getpostman.com / common-share / postman-platform-for-api-development-social-card.jpg","hiringOrganization" : "@type" : "Organization","name" : "Postman","sameAs" : "https : / / www.

postman.com","logo" : "https : / / assets.getpostman.com / common-share / postman-platform-for-api-development-social-card.

jpg" ,"baseSalary" : "@type" : "MonetaryAmount","currency" : "USD","value" : "@type" : "QuantitativeValue","value" : "competitive","unitText" : "SALARY" ,"jobLocation" : "@type" : "Place","address" : "@type" : "PostalAddress","streetAddress" : "201 Mission Street, Suite 2375","addressLocality" : "San Francisco","addressRegion" : "CA","postalCode" : "94105","addressCountry" : "US"

12 days ago
Related jobs
Promoted
Circle
San Francisco, California

The security team leads the company’s programs for information security, insider risk and cybersecurity. As a member of this team, you’ll lead projects and be responsible for the upkeep of the team’s technology stack as well as creation of log pipelines that feed our SIEM, SOAR, TIP and other securi...

Promoted
Worldcoin
San Francisco, California

Engineer and manage solutions to bolster our security incident detection and response capabilities. The Orb solves a fierce combination of engineering and UX challenges, centered around image quality, security, and ease-of-use. Beyond regular company security, the goal of security at Worldcoin is to...

Promoted
Crusoe
San Francisco, California

Crusoe Security & Compliance is hiring a Senior/Staff Security Operations Engineer to play a critical role in safeguarding Crusoe, our customers, and ensuring our security posture remains robust against emerging threats. Perform forensics and lead response efforts during security incidents, incl...

Promoted
Atlassian
San Francisco, California

Senior Engineering Manager – Corporate Security. You'll bring your experience to grow and lead a team of corporate security engineers to build out protections on enterprise endpoint systems (all three, but heavy on Apple), secure corporate network infrastructure, partner with IT to address enterpris...

Promoted
Worldcoin
San Francisco, California

The Orb solves a fierce combination of engineering and UX challenges, centered around image quality, security, and ease-of-use. Beyond regular company security, the goal of security at Worldcoin is to deploy an edge device to unsecured environments. A strong advocate for security awareness, capable ...

Promoted
Salesforce
San Francisco, California

Security Assurance supports our engineering teams on the full stack; from the application layer down, ensuring the security of our customer-facing products, and being security domain guides to engineering teams across Salesforce. Security Assurance works to ensure no significant security risk escape...

Promoted
Verkada
San Mateo, California

Staff Software Engineer - Detection and Response Platform. Build, operate and improve Verkada’s Security Monitoring, Detection and Response infrastructure. Collaborate with the CISO and security team to grow the broader Verkada security program. Share your security experience with other teams intern...

Snowflake
San Mateo, California

Projects focus on building a platform that makes it easy to deploy and maintain security services, unifying security experience for developers, increasing developer autonomy as it pertains to security, detecting security vulnerabilities, secure-by-default solutions, and leveraging data to drive secu...

CARTA
San Francisco, California

How do we enable automated security practices (vulnerability management, detection & response, etc. Minimum of 8-10 years hands-on experience in security operations, emphasizing detection, response, identity/access, auditing, alerting, automation, orchestration, and threat hunting. This role is with...

ImmunityBio
US California

The Senior Cyber Security Engineer will be part of the enterprise security organization and help implement, support, and maintain a proactive and stable IT environment as well as provide support to our business units. Assist with solutions and core security projects related to enterprise security an...