Security Engineer, Threat Detection & Response

Airbnb Airbnb · Consumer · United States · Software Engineering

Security Engineer focused on threat detection and response, automating security detection, investigating incidents, and building capabilities to support the incident lifecycle. The role involves hunting for threats, building automation and detection models, and partnering with cross-functional teams to improve overall security.

What you'd actually do

  1. Perform investigations of security incidents using your knowledge of digital forensics and data analytics.
  2. Use your coding, data analytics and investigation skills to hunt, detect and respond to threats.
  3. Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale.
  4. Hunt for threats in our corporate and production environments to proactively identify anomalous activity.
  5. Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with partner teams to carry out complex investigations.

Skills

Required

  • Python or other scripting language
  • SQL
  • Pandas
  • Cyber Kill Chain Framework
  • MITRE ATT&CK Framework
  • automating security detection and response

Nice to have

  • Elasticsearch
  • AWS services (EC2, S3, Lambda, RDS)

What the JD emphasized

  • Experience automating security detection and response