Senior Security Engineer, Blue Team

Posted: 73 days ago
Note: This job has expired. Please do not apply!

We are looking for a talented security engineer with experience in a Blue Team role to help us fortify our defenses and protect the systems that enable hungry people to order their food quickly and securely.

We want people who are passionate about finding risks, analyzing the related data and collaborating on the right strategic risk mitigation measures. Reducing risk while enabling and supporting innovation.  

Reporting to the Chief Information Security Officer, the Senior Security Engineer will design and implement the security defenses that enable our systems to keep running while protecting the data of our clients and their customers.

What You'll Be Doing

  • Detect and defend against attacks by analysing security-related events and alerts, and leading incident response, remediation and mitigation activities
  • Provide stakeholders with concise, detailed, and well-written incident reports, root causes identification, and remediation recommendations.
  • Use experience and data gained during incident investigations to improve security posture
  • Provide management oversight for the identification, triage and response of events or incidents
  • Coordinate and track incident response activities with other teams and third parties. This includes remediations arising from Red Team tests and external penetration tests.
  • Perform non-event driven security reviews, including but not limited to patching, firewall rules, system configuration checks and vulnerability reports
  • Conduct Blue Team exercises and drills to evaluate and improve processes and technologies related to various controls including but not limited to threat detection, incident response, patching, remediation and user training.
  • Mature Blue Team exercises by leveraging recent breach reports, evolving threats and vulnerabilities
  • Execute Threat Hunts to proactively detect and mitigate advanced threats
  • Mature threat hunting through improved data analysis, additional data augmentation, creating custom toolsets and improving automation 
  • Maintain and optimize various security technologies. This includes ongoing optimizations and implementing new or replacement security technologies as needed and automating security activities where feasible.
  • Deep collaboration with IT, Infrastructure and Development teams where security ownership and responsibilities are shared.
  • Ensure security policies and standards are understood and complied with
  • Educate and influence employees on security and coach junior team members
  • Work with PCI and SOC auditors to provide evidence of compliance
  • Assist with third party software and provider due diligence
  • Contribute to security strategy, policies and standards
  • Proactively identify and implement improvements to our tools and processes
  • Participate in a 24/7 on call rotation as needed

What We'll Expect From You

  • Previous Blue Team, Security Operations or Security Engineering experience
  • Deep knowledge of information technology, evolving threats, attack patterns, incident response and cyber security standards
  • Proven experience developing and leading incident response, remediation and mitigation activities, and providing status updates and reports.
  • Adept at analyzing security events to discern events that qualify as a legitimate security incident as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response.
  • Deep understanding of operating system, networking and application concepts 
  • Ability to harden Windows, MacOS and Linux and any underlying virtualization
  • Familiarity with AWS security best practices and Infrastructure-as-Code
  • Experience deploying, maintaining and administering security technologies including. (e.g. Anti-Malware, Intrusion Detection System (IDS), Data Leak Prevention (DLP), File Integrity Monitoring (FIM), Firewalls, Security Information and Event Monitoring (SIEM), Static Inspection, Multi Factor Authentication (MFA), Vulnerability Assessment, Web Proxies and Web Application Firewalls (WAF)
  • 5+ years of Information Technology experience with a focus on Security
  • Ability to work on-call, during critical incidents or to support coverage requirements
  • Strong English writing and verbal communication skills
  • Legal right to work in the U.S.

Nice to Have

  • PCI and/or SOC compliance experience 
  • CISSP, GCIH, CEH, OSCP, or similar certification
  • Scripting and/or development familiarity
Share this job