Senior SOC Engineer (DFIR & Hunt)
DigitalOceanAbout the role
Do you ever wonder what happens inside the cloud?
DigitalOcean (NYSE: DOCN) simplifies cloud computing so builders can spend more time creating software that changes the world. With our mission-critical infrastructure and fully managed offerings, DigitalOcean enables startups and small and medium-sized businesses (SMBs) to rapidly deploy and scale modern applications. As a remote-first organization, our employees, like our customers, are based around the world.
We want people who are passionate about making the internet a safer place for everyone
We are looking for an inspired and motivated technical contributor to join the DigitalOcean Security Operations Center. In this role, you will be a key member of DigitalOcean’s Digital Forensic and Incident Response (DFIR) team, charged with improving the security posture of DigitalOcean both reactively and proactively, ensuring a secure cloud infrastructure for both customers and internal users. You will gain skills in one or more of multiple focal areas including digital forensics, incident response, platform abuse, legal/regulatory enforcement, and enterprise security. You will use your analytical skills to identify and eliminate bad actors inside the DigitalOcean platform or leverage your engineering skills to create innovative ways to detect and respond to potential threats.
With over 500,000 customers utilizing 10+ data centers and 10,000+ hypervisors every day, our Security Operations Center never loses sight of the role we play in making the internet a more secure place for everyone.
What You’ll Be Doing:
- Handling live intrusions and incident response cases with on-call rotations, in an internal-oriented and transparent manner, to minimize the impact of bad actors on assets.
- Collect digital artifacts from cloud systems for analysis to reconstruct what may have transpired on a system leveraging digital forensics methodologies.
- Analyzing network traffic to identify compromised systems, negate denial of service attacks, and pinpoint resource abuse.
- Identifying trends in abusive activity, communicating with leadership to keep them apprised, and advocating for appropriate product changes to prevent future occurrences.
- Acting as a point of escalation for security monitoring and related incidents: providing supporting data for critical issues, downtime events, and Post-Mortem reports.
- Helping build tools to identify or automate response to harmful activity.
- Establishing an understanding of DigitalOcean’s entire production environment, from applications to infrastructure, keeping up-to-date with material changes and future directions.
- Building strong relationships with the other technical teams across our engineering and infrastructure functions to harden account, platform, and service structures to combat intrusions, compromises, and disruptive activities.
What We’ll Expect From You:
- Experience performing live incident response activities transparently (sans picerl), in a team environment where accuracy of analysis determines business impact.
- Hands-on dead-disk and live digital forensics experience, on Linux or Unix systems using open source tools (eg, volatility, sleuthkit) in production environments at scale.
- Ability to differentiate between normal and unusual resource usage patterns in customer and employee network/system behaviors in order to hunt for subtle anomalous patterns.
- Data analysis skills, including familiarity with relational databases, structured query languages (sql), logging infrastructures (syslog, elastic), and data visualization tools (looker, grafana, kentik).
- Familiarity with basic static and dynamic malware analysis for triage, identification, prioritization, and remediation of new malware families and behaviors (e.g: x86 assembly, binary analysis).
- A high degree of curiosity and aptitude, with a clear passion for security and the desire to keep our employees, customers, and the internet safe.
- Clear written and verbal communication skills to include; technical writing, presenting, coaching, mentoring.
- Consistently improving security as the platform scales, driving continuous improvement through data collection and correlation, being mindful that security should be an efficiency enabler for the business - not a detractor.
- Bonus: Experience in one or more of the following:
- Vulnerability Analysis, Scoping, and Mitigation Planning
- Threat Intelligence Collection / Analysis / Dissemination
- Network Protocol Analysis
- Coding, automation, or scripting skills for tool building
- Detection Engineering
Why You’ll Like Working for DigitalOcean:
- We a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s