Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 6
Data Engineering @ 3
Leadership @ 6
Linux @ 3
Observability @ 3
Payments
Python @ 3
SQL @ 3
Security @ 6
Splunk @ 3
macOS @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe's mission is to increase the GDP of the internet.
About the Team
The Security Incident Response team triages and assesses the severity of incoming security alerts, responds with initial containment measures, and escalates incidents for further investigation and resolution. The team analyzes diverse data sources to identify potential threats, gathers requirements for operational improvements to detection and response systems, and scales security processes. It responds to external attacks and insider threats, supports remediation, and contributes to incident postmortems. The globally distributed team coordinates with stakeholders in North America, Europe, and Asia.
Responsibilities
- Lead and support a team of security analysts, investigators, and responders who triage, assess, and respond to threats.
- Provide technical guidance as a subject matter expert.
- Influence organizational mission and vision by prioritizing and delivering project work aligned with security roadmaps.
- Strengthen KPIs and metrics for measuring response operations effectiveness and reporting to internal stakeholders.
- Work cross-functionally with security engineering teams to gather requirements for analyzing and responding to security event data at scale while protecting Stripe networks, systems, and data.
- Develop, document, and implement strategies, runbooks, and capabilities supporting the incident response process.
- Continuously improve security processes and response capabilities in collaboration with security engineers and analysts.
- Coach and mentor individual contributors, support career development, and champion quality standards.
- Hire, train, and evaluate the performance of team members while ensuring timely and effective resolution of casework.
Requirements
Minimum Requirements
- 5+ years of experience leading Security Operations or Incident Response teams, including hands-on technical management of security analysts or engineers.
- B.S. or M.S. in Computer Science or a related field, or equivalent experience in security.
- Experience recruiting, growing, and leading technical teams, including performance management.
- Excellent written and verbal communication skills, including the ability to develop and deliver operational or incident-related information to leadership.
- Advanced knowledge of data analytics, including logs for first- or third-party applications and system or data access events; network security; digital forensics; and incident response investigations.
- Experience with Python and SQL, and/or familiarity with other programming languages.
- Familiarity with operating systems, file systems, and memory on macOS, Linux, or Windows.
- Strong understanding of threat actor tactics, techniques, and procedures (TTPs).
Preferred Qualifications
- Broad knowledge and experience across information security, including endpoint, email, network, identity management, cloud security, vulnerability management, incident response, and threat intelligence.
- Experience with engineering, data processing, and analysis tools.
- Familiarity with network observability, security software, or data engineering solutions such as Chronicle, Tines, osquery, and Splunk.