Build and maintain a SIEM to collect and analyze logs from across corporate and production systems; write and deploy detections and alerts to identify malicious behavior
Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets
Investigate security incidents end-to-end — including malware analysis, exfiltration assessment, and timeline reconstruction — and build runbooks to scale response capabilities
Partner with IT to define and enforce security standards across the employee device fleet, including endpoint protection, managed device requirements, OS compliance, and VPN access controls
Drive the PoC and implementation of Zero-Trust VPN and other corporate security infrastructure
Provide security guidance and advisory support to non-engineering functions across the organization
Availability for meetings and impromptu communication during Quora's “coordination hours" (Mon-Fri: 9am-3pm Pacific Time)
5+ years of experience in security engineering, detection engineering, or a closely related field
Hands-on experience building or maintaining SIEM infrastructure and writing detection rules
Experience with endpoint security tools (e.g. CrowdStrike or similar EDR platforms)
Strong Python engineering skills with a track record of writing production code reviewed and shipped alongside software engineering teams
Experience conducting security incident investigations, including malware analysis, log review, and timeline reconstruction and threat modeling
Experience with corporate security controls, identity management, endpoint protection, and access control enforcement
Experience with SIEM/SOAR options such as Elastic/Splunk or alternatives
Familiarity with identity platforms such as Okta
Strong understanding of authentication technology such as OAuth, Yubikey and Passkey
Experience with Zero-Trust network architecture or VPN implementation
Demonstrated use of AI coding tools to build or automate security workflows
Experience in a small security team or fast-paced startup environment
Familiarity with AWS and cloud-native security tooling
US candidates only: For US based applicants, the salary range is $172,279 - $249,640 USD + equity + benefits
Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $220,272 - $255,347 CAD + equity + benefits. For all other locations in Canada, the salary range is $205,587 - $238,324 CAD + equity + benefits