5+ years of experience in security operations, detection and response, or incident response, preferably in a fast-paced startup or technology environment
Hands-on experience administering and tuning a SIEM (e.g., Splunk, Microsoft Sentinel, Elastic, Panther, or Chronicle), including log source onboarding, parsing, and detection rule development
Demonstrated experience leading security incidents end to end, from detection and scoping through containment, eradication, and post-incident review
Strong working knowledge of attacker tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, and the evidence sources needed to investigate them
Experience investigating endpoint, identity, network, and cloud telemetry across macOS, Windows, and Linux, including EDR, identity provider, and SaaS audit logs
2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate detection, enrichment, and response, in lieu of a degree; OR a bachelor’s degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline
Knowledge of operating systems, networking, cloud and SaaS platforms, security best practices, and log analysis at scale
Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate with responsibilities
Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills
Bachelor’s degree (or equivalent) in computer science or engineering
Detection and response certifications such as GCIH, GCFA, GCIA, GCDA, or OSCP, or equivalent hands-on experience
Experience building detection-as-code pipelines, security data lakes, or ETL for security telemetry
Experience with cloud detection and response in AWS, Azure, or GCP
Experience with threat intelligence, malware analysis, or reverse engineering
Experience protecting engineering, manufacturing, OT, or mission and ground segment environments
Prior experience in a defense, aerospace, or other ITAR-regulated environment
Security community contributions such as tooling, blog posts, conference talks, or CTFs