Security Engineer, Detection & Response - Monitoring & Triage

Block Block · Fintech · VIC, Australia · Remote · 10404 Engineering - Information Security

This role is for a Security Engineer focused on Detection and Response, specifically in Monitoring and Triage. The primary responsibility is to investigate and respond to security threats across various systems, build detections, and automate investigation and response workflows. The role requires an engineering mindset to improve security systems and reduce manual toil.

What you'd actually do

  1. Own daily security intake across alert queues, Slack channels, and walk-in escalations from teams across Block, acting as the welcoming front door for security ops.
  2. Investigate and drive resolution of security events end-to-end, including endpoint detections, cloud/SaaS alerts, malware, supply chain issues, and hands-on-keyboard activity.
  3. Pivot across endpoint, identity, cloud, SaaS, network, DNS, and application telemetry to build timelines, test hypotheses, determine scope, and assess impact.
  4. Run nuanced investigations across non-uniform environments where device posture, identity models, and telemetry differ significantly.
  5. Consistently turn recurring investigative patterns into durable improvements: recommend new detections, automate triage workflows, refine automation logic, and clarify escalation paths.

Skills

Required

  • detection and response
  • incident response
  • security engineering
  • investigative experience
  • endpoint security
  • identity security
  • cloud security
  • SaaS security
  • network security
  • application security
  • AWS security
  • Kubernetes security
  • cloud-native logging
  • networking
  • Linux systems
  • incident leadership
  • scoping
  • containment
  • evidence collection
  • impact assessment
  • stakeholder communication
  • SQL
  • log-query/analysis
  • large telemetry sets
  • attacker TTPs
  • macOS
  • Windows
  • Linux
  • live response
  • forensics
  • AI development workflow
  • building detections
  • tuning detections
  • maintaining detections
  • investigation workflows
  • internal security tooling
  • engineering mindset
  • automation
  • independent work
  • time zone management
  • priority management
  • empathy
  • patience
  • curiosity

Nice to have

  • threat intelligence
  • threat hunting
  • malware analysis
  • forensic artifact collection
  • reversing
  • human-in-the-loop automation
  • AI-assisted investigation systems

What the JD emphasized

  • 5+ years of experience in detection and response, incident response, security engineering, or equivalent depth of hands-on investigative experience.
  • Strong investigative judgment across endpoint, identity, cloud, SaaS, network, and application security signals; AWS and Kubernetes security fundamentals, cloud-native logging, networking, and Linux systems.
  • Experience leading incidents end-to-end, including scoping, containment, evidence collection, impact assessment, and stakeholder communication.
  • Strong SQL and log-query/analysis skills, with the ability to work effectively across large, messy telemetry sets without waiting for a perfect dashboard.
  • Current, practical working knowledge of attacker TTPs across macOS, Windows, and Linux with live response and forensics.
  • An established AI development workflow.
  • Experience building, tuning, or maintaining detections, investigation workflows, or internal security tooling.
  • An engineering mindset: you start looking for the detection, workflow, control, or automation change that will eliminate a manual pattern.