Staff Security Engineer - Detection and Response
Fastly, Inc.About the role
Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including Vimeo, Pinterest, The New York Times, and GitHub.
We're building a more trustworthy Internet. Come join us.
As a Staff Security Engineer on our Detection and Response team, you will help detect and respond to threats for one of the biggest online platforms in the world that handles massive amounts of traffic at very low latency.
We are looking for a teammate with expertise in both security engineering and operations and that values the complement between the two. You will have the opportunity to build and integrate tooling and detections, as well as investigate threats and lead incidents. As part of the larger Security organization, we make risk-informed decisions and prioritize automations to help us scale. As the lead engineer on our team, you will design, build, and mature our detection and response program, enabling rapid detection and effective response to threats against Fastly. You will lead large, complex, cross-team projects and mentor other security engineers on our growing team.
What You'll Do:
- Lead the design and implementation of a robust Detection Engineering program
- Develop detections and other analytics to identify threats across cloud, corporate, and edge environments
- Partner closely with Engineering, Security Architecture, Risk Management, Compliance, and other teams to prioritize detections and delivery of other security initiatives
- Triage and investigate security threats and lead security incidents
- Research, evaluate, implement, and maintain a variety of custom and commercial security tools, such as Endpoint Detection and Response (EDR), anti-phishing, and Security Information and Event Monitoring (SIEM)
- Develop strategies, frameworks, designs, automations, metrics, and processes to support the maturity of the Detection and Response program
- Develop and maintain incident response playbooks and other detection and response documentation
- Conduct threat hunts to discover unknown malicious activity across our environment
- Participate in our on-call rotations
- Mentor other team members and contribute to larger Security initiatives
What We're Looking For:
At Fastly we value a diversity of voices. The following is not a laundry list, but to be effective in this role you should possess most of the following and an interest in learning more about the rest:
- Expertise in utilizing Splunk to include investigating threats, developing metrics and dashboards, normalizing data feeds, and integrating with other tools
- Strong understanding of attacker tactics, techniques, and procedures (TTPs) and investigating advanced threats
- Experience in implementing “Detection as Code”
- Experience in securing, developing detections, and responding to incidents in one major public cloud infrastructure, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP)
- Experience in effectively leading large and complex security incidents from detection to remediation
- Familiarity with modern security frameworks and best practices, such as the MITRE ATT&CK framework and NIST CSF
- Proficiency in one or more general purpose programming languages such as Python, Ruby, Go, or Rust
- Experience with Linux administration at scale, associated intrusion/manipulation techniques, and standard methodologies for system hardening and process isolation
We’ll be super impressed if you have experience in any of these:
- Built a Detection Engineering pipeline
- Built and led threat hunts
- Published research on detection engineering or threat intelligence
- Developed automations to improve security operations
- Familiarity with content delivery networks (CDN), edge cloud platforms, or other Fastly products and services
Work Hours:
- This position will require you to be available during core business hours.
Work Locations & Travel Requirements:
This position is open to the following preferred office locations:
- San Francisco, CA
- Los Angeles, CA
- Denver, CO
- New York City, NY
Fastly currently embraces a largely hybrid model for most roles which allows employees fle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s