Security Software Engineer (l4), Detection Engineering

Netflix Netflix · Big Tech · United States · Remote · Engineering

Netflix is seeking a Security Software Engineer to mature and expand their detection frameworks, platforms, and portfolio. The role focuses on creating and improving detections to minimize risk by proactively surfacing malicious or anomalous behavior. The engineer will analyze high-risk attack paths, develop compensating detective controls, and use a risk-based prioritization mindset. Experience applying GenAI technologies to automate security operations is a plus.

What you'd actually do

  1. mature and expand our detection frameworks, platforms, and portfolio
  2. create and continually improve detections that run on our own platforms to minimize risk to Netflix by proactively surfacing malicious or anomalous behavior to identify attacker presence or activity
  3. Using a risk-based prioritization mindset, we focus our efforts to generate the largest impact and benefits for Netflix
  4. writing detections at scale using a detection-as-code approach
  5. script and develop automations, preferably using Python and SQL, in a cloud-based environment to contribute to our in-house platforms

Skills

Required

  • information security domain
  • endpoint
  • email
  • network
  • identity management
  • cloud security
  • vulnerability management
  • incident response
  • threat intelligence
  • analyzing and responding to security events
  • log analysis
  • developing queries and analytics
  • troubleshooting security issues
  • correlating complex data sets
  • identify trends, insights, and relationships between internal and external data and intelligence sources
  • recommended risk mitigation
  • implementing, using, and configuring common security tools
  • writing detections at scale
  • detection-as-code approach
  • script and develop automations
  • Python
  • SQL
  • cloud-based environment
  • excellent written and verbal communication skills
  • proactively inform stakeholders
  • operate with little oversight
  • effectively operate across teams and disciplines
  • highly ambiguous and rapidly changing environment
  • work well with others
  • see the value of a team
  • partner effectively with all stakeholders
  • comfortable working on ambitious projects with a very small, tight-knit team

Nice to have

  • applying GenAI technologies to automate security operations

What the JD emphasized

  • high-risk attack paths
  • substantial impact on Netflix
  • minimize risk to Netflix
  • proactively surfacing malicious or anomalous behavior
  • shorten the time to discovery
  • risk-based prioritization
  • generate the largest impact and benefits for Netflix
  • automating security operations