- This senior technical IC role owns Visier’s threat detection and response capabilities end-to-end—driving the overarching strategy, tooling engineering, detection content, and incident response processes
- Operating within a high-leverage team, you will scale our security capabilities through advanced engineering and AI, directly safeguarding our multi-cloud platform, corporate identity, and sensitive customer data from sophisticated global threats
- Your work will ensure our defensive posture continuously evolves ahead of the threat landscape
- Bring your 8+ years of deep information security expertise, mastery of modern SIEM architectures, and calm incident command experience to a team where you will operate with high autonomy
- You will leverage your technical depth to champion engineering-first security practices, safely adopt generative AI workflows, and mentor peers to elevate our collective defense
- End-to-End Pipeline Resilience:
Design and operate a cohesive detection pipeline spanning multi-cloud, SaaS, identity, and endpoint telemetry to eliminate visibility gaps and ensure comprehensive logging infrastructure - Proactive Detection Engineering:
Build, test, and tune high-fidelity detections using a modern detection-as-code framework mapped to the MITRE ATT&CK matrix, drastically minimizing false positives while prioritizing critical threat coverage - Incident Lifecycle Ownership:
Author robust playbooks, runbooks, and escalation criteria that define how Visier handles security incidents, ensuring immediate containment during major events - Continuous Defensive Evolution:
Lead blameless post-incident reviews and seamlessly translate post-mortem findings into automated detections and architectural hardening requirements - Cross-Functional Security Integration:
Partner closely with software developers, SREs, and offensive security functions to convert emerging vulnerabilities and organization-specific risks into highly targeted defensive rules - AI-Accelerated Operations:
Securely integrate and pioneer the use of Generative AI tools to accelerate detection development, alert triage, telemetry enrichment, and automated responses
Incident Command Presence:
Proven experience acting as an Incident Commander, successfully steering cross-functional technical teams through high-pressure, complex, and high-visibility security incidents
Education & Experience:
8+ years of hands-on experience in information security, with a proven track record of designing, owning, and scaling threat detection architectures or major incident response programs
Cloud & Infrastructure Fluency:
Deep technical experience analyzing and building threat coverages across enterprise multi-cloud environments (AWS, Azure, or GCP), core identity providers, and endpoint/EDR telemetry
Detection-as-Code Mastery:
Expert-level detection engineering skills utilizing modern SIEM environments (Splunk Enterprise Security preferred) alongside fluent structural mapping to the MITRE ATT&CK framework
Security Automation & Scripting:
Strong hands-on coding proficiency (Python, Go, or Bash) to build resilient automation pipelines, data enrichments, and automated response playbooks
Strategic Communication:
Exceptional ability to translate deeply technical indicators of compromise and complex security risks into clear, high-level business insights for executive stakeholders
You make it easy
You roll up your sleeves
You never stop learning
You are proud
You play to win
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: