Security Engineer, Incident Response responsible for leading and executing cybersecurity incident responses at Instructure. Collaborating with teams to enhance security initiatives and procedures.
Responsibilities
Lead and direct all phases of the incident response lifecycle, from initial detection and triage to containment, eradication, and post-incident analysis and review.
Conduct in-depth forensic analysis of security incidents to determine the root cause, assess the impact, and define the scope of the incident.
Collaborate with engineering and product teams to develop and implement effective containment and eradication strategies for SaaS environments.
Coordinate recovery activities to ensure the timely and secure restoration of impacted systems and services.
Support design, develop, and implement robust detection rules and signatures across our security toolset (e.g., SIEM, EDR, WAF, CSPM) to proactively identify malicious activity.
Continuously refine and optimize detection rules to minimize false positives and enhance the accuracy of our security alerts.
Evaluate and recommend new security technologies and methodologies to enhance our security posture.
Create and maintain detailed documentation for all incident response procedures, playbooks, and runbooks.
Develop and document security best practices and guidelines for engineering and product teams.
Contribute to the creation and maintenance of our overall security knowledge base.
Schedule and manage tabletop exercises to test and refine our incident response capabilities.
Document the results of tabletop exercises and track the remediation of any identified gaps.
Provide training and guidance to junior analysts and other team members on incident response and security best practices.
Requirements
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Proven experience in a security role with a strong focus on incident response and security engineering.
Demonstrated experience leading incident response for a SaaS product company.
Strong understanding of common attack techniques, tactics, and procedures (TTPs).
Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Elastic SIEM, Microsoft Sentinel) and developing detection rules.
Familiarity with Endpoint Detection and Response (EDR) solutions.
Proficiency in at least one scripting language (e.g., Python, Go, etc).
Excellent analytical, problem-solving, and communication skills.
Proven ability to write clear and concise documentation.
This position includes participation in an on-call rotation
Benefits
Competitive compensation, plus all full-time employees participate in our ownership program - because everyone should have a stake in our success.
Flexible schedules and a remote-friendly culture, with hybrid or onsite work options available in some regions for specific roles
Generous time off, including local holidays and our annual company-wide “Dim the Lights” week in late December, when we encourage everyone to step back and recharge
Comprehensive wellness programs and mental health support
Annual learning and development stipends to support your growth
The technology and tools you need to do your best work — typically a Mac, with PC options available in some locations
Motivosity employee recognition program
A culture rooted in inclusivity, support, and meaningful connection
Information Security Consultant managing security standards implementation at LUZA Group in Lisbon, Portugal. Handling analysis of risk and supporting audits while working in a hybrid model.
Senior Cybersecurity Analyst at Boeing performing advanced cybersecurity assessments and risk evaluations for third - party vendors. Focusing on automation, lean processes, and collaborating with key stakeholders across departments.
Cybersecurity Manager ensuring regulatory compliance in information security within the Mexican framework. Collaborating with technology teams to strengthen governance, risk, and control model.
CISA Auditor focusing on cloud security audits for a Zurich - based international bank. Ensuring cybersecurity and identifying vulnerabilities in IT systems with risk - oriented audits.
Cybersecurity Specialist managing compliance for DoD security transition to Zero Trust Architecture. Involves overseeing RMF activities and ensuring ATO deadlines are met in cloud environments.
Engineer II responsible for managing enterprise customer support in Security Engineering. Focused on troubleshooting and diagnosing security incidents in a hybrid work environment.
Guest Safety Agent at HRI Hospitality ensuring safety and hospitality for guests and managing outlet spaces. Maintaining a secure environment while engaging with guests and visitors in New Orleans.
Cybersecurity Architect for Saint Louis University developing and assessing security strategies and architecture. Ensuring secure IT services through effective security technologies and practices.
Senior Commercial Manager developing and executing Cyber Security strategies, managing client portfolios and leading complex negotiations in São Paulo.
Security Officer responsible for maintaining safety at WarHorse Casino. Enforcing policies, responding to incidents, and providing customer service to guests.