Staff Security Engineer, Cybersecurity Incident Response
Cruise LLCAbout the role
We're Cruise, a self-driving service designed for the cities we love.
We’re building the world’s most advanced, self-driving vehicles to safely connect people to the places, things, and experiences they care about. We believe self-driving vehicles will help save lives, reshape cities, give back time in transit, and restore freedom of movement for many.
Cruisers have the opportunity to grow and develop while learning from leaders at the forefront of their fields. With a culture of internal mobility, there's an opportunity to thrive in a variety of disciplines. This is a place for dreamers and doers to succeed.
If you are looking to play a part in making a positive impact in the world by advancing the revolutionary work of self-driving cars, join us.
The Cybersecurity Incident Response Team (CIRT) builds detections as code, investigates cybersecurity events, leads internal security incidents and digital forensic investigations, and builds custom software solutions aimed to increase the efficiency of response.
As Cruise scales, we need a strong leader at the helm of security incidents, digital investigations, and highly-technical projects centered on both tactical and strategic blue team operations, including areas such as live response, artifact collection and parsing, and automation.
In major security incidents, you will serve as the incident commander, responsible for bringing together and leading a large cross-functional team through all stages of the incident response process. Day-to-day, you will be providing technical guidance and leadership to junior and senior incident response engineers, and delivering on engineering initiatives. Strategically, you will partner closely with the Engineering Manager and help set the technical direction of the team.
Applicants should be excited to solve hard problems, employ their outstanding communication skills, and lead and mentor others. You should possess extensive experience in incident response and digital forensics, and be the one who stands out on your team as a top performer, innovator and leader.
WHAT YOU’LL BE DOING:
Provide day-to-day technical leadership and support to a team of incident response security engineers, serving as the primary escalation
Serve as the escalation point for alert triage and investigation
Execute on our incident response plan, leading cross-functional teams through the company's most significant security incidents
Draft and present polished incident reports or internal communications fit for an executive audience, and lead incident postmortems
Architect and spearhead deeply-technical and complex projects focused on securing Cruise
Identify, build, and support relationships with key cross-functional partners within and outside of Security
Partner with the Engineering Manager to help set the technical direction of the team
Mentor junior and senior incident response engineers
Embody Cruise behaviors and values: Stay Safe, Own It, Stay Focused, Seek Truth, Work Together, Be a Customer, Be Humble
WHAT YOU MUST HAVE:
Extensive experience leading response and investigation of large-scale and dynamic security incidents in corporate environments
Conversant knowledge of current opportunistic and/or advanced threat actor ecosystem, their targeting patterns, and associated tradecraft
Experience mentoring less senior members of an incident response team
Demonstrated ability to project composure and organization in the midst of high-intensity incidents
Exceptional communication skills with a knack for building relationships cross-functionally to support incidents and investigations
Intimate knowledge of core network protocols, with a demonstrated ability to query and analyze network logs in incidents and investigations
Experience performing log analysis in cloud environments (GCP, AWS, Azure) and across multiple SIEMs
In-depth knowledge of disk structures and experience performing file system and operating system forensics, with significant expertise in at least one OS (Mac, Windows or Linux)
Familiarity with at least one major cloud platform
Experience with datasets generated by osquery, and Bro/Zeek
Coding/scripting proficiency in one or more languages, recent development experience, and the ability to pass a coding interview
BONUS POINTS!
Fluency in SQL for querying complex data sets
Experience performing data collection and analysis in cloud environments
Experience developing automation in support of incidents and investigations
Expertise in static and dynamic
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s