Deep hands-on experience in detection engineering, incident response, or security operations, with a track record of building capability
Depth in corporate attack surfaces such as identity providers and SSO, endpoint and EDR telemetry, email security, SaaS logs, device management signals, and corporate network access
Strong proficiency in Python and query language such as SQL
The ability to build and maintain detection-as-code pipelines yourself rather than specify them for someone else to build
Practical experience with SIEM, EDR, and security analytics platforms
Investigative depth on endpoints and in cloud and SaaS environments, so you can reconstruct what happened across an IdP, a laptop, and a SaaS admin console, and say what you know versus what you're inferring
Excellent written communication and a collaborative approach to influence. You'll explain to engineers why a detection matters and to leadership what an incident actually means
Bonus points for experience as a founding security hire, insider threat or data loss detection, an offensive security background against corporate identity and endpoint paths, incident commander experience, endpoint or cloud forensics depth, or a clear view on what belongs in a SIEM versus a data warehouse
Salary Range
San Francisco: the pay range for this role is $174,500 to $240,000 per year
Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting