Description
You will own the detection, investigation, and mitigation of abusive activities and security incidents originating from the platform.
Responsibilities
- Analyze network traffic to identify compromised systems, negate denial of service attacks, and pinpoint resource abuse.
- Investigate and mitigate abusive activities including intrusion attempts, DDoS, malware distribution, and phishing attacks.
- Handle live intrusions and incident response cases to minimize impact through transparent, customer-facing communication.
- Triage security events and incidents using SIEM, NIDS, and antivirus tools to detect anomalies and direct remediation.
- Identify trends in abuse vectors and advocate for product changes to prevent future occurrences.
- Coach and mentor other security practitioners across application, information, and infrastructure security.
Required Skills
- 3-7 years of experience in security operations or incident response.
- Proficiency with Linux and networking fundamentals.
- Experience with network security, monitoring, and virtualization.
- Ability to use Python or Ruby for automation tasks.
- Knowledge of cloud computing environments.
- Strong technical writing skills for reporting and documentation.
- Experience working with queue management systems and meeting resolution targets.
Education