Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Incident Response Team b
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Incident Response Team based in Australia. As a Senior Security Engineer, you will play a key role in protecting critical cloud and corporate environments from evolving security threats. You will lead complex incident investigations and manage high-severity events from initial detection through containment, eradication, and recovery. The role combines deep DFIR expertise with detection engineering, automation, threat intelligence, and operational improvement. You will help develop scalable security workflows, using automation and AI-assisted approaches to improve response speed and consistency. Working across a globally distributed security organization, you will collaborate with engineering, infrastructure, legal, product, and communications teams. You will also contribute to proactive security initiatives, strengthen incident response maturity, and mentor fellow engineers. This is an opportunity to make a direct impact in a high-tempo, 24/7 security environment while shaping modern detection and response capabilities.
Lead and coordinate end-to-end response to high-severity security incidents across cloud and corporate environments. Cover the APAC operating window within a global 24/7 follow-the-sun model and participate in a rotating on-call schedule. Prepare clear, concise executive communications that keep stakeholders informed throughout significant security incidents. Conduct complex security investigations using strong Digital Forensics and Incident Response (DFIR) methodologies. Partner with Detection Engineering to develop and improve SIEM use cases, alerting strategies, detection capabilities, and telemetry pipelines. Build and enhance automation and AI-assisted workflows to improve incident triage, investigation efficiency, response consistency, and detection fidelity. Collaborate with Threat Intelligence teams to contextualize emerging threats, understand adversary behavior, and strengthen detection coverage. Conduct root cause analysis and lead post-incident reviews, translating findings into measurable improvements in security controls and processes. Develop and maintain incident response runbooks, playbooks, procedures, and operational documentation. Collaborate with Engineering, Infrastructure, Legal, Product, Communications, and other teams during incidents and proactive security initiatives such as tabletop exercises. Mentor other security engineers and contribute to improving the team's overall incident response maturity and operational effectiveness. Requirements: Strong professional experience in security incident response and investigations, particularly within cloud-first environments. Hands-on experience with Digital Forensics and Incident Response methodologies and the ability to operate effectively during high-severity security events. Experience using or administering Git or GitLab in a security or engineering environment. Practical experience with SIEM, EDR, detection engineering, or related security monitoring technologies. Experience working with major cloud platforms, particularly AWS and GCP. Familiarity with threat intelligence, adversary tactics, and frameworks such as MITRE ATT&CK. Experience developing or using automation through Python, scripting, SOAR platforms, or similar technologies. Interest or experience applying AI, machine learning, or data-driven techniques to detection, triage, investigation, or response workflows. Strong analytical and problem-solving abilities, with sound judgment and composure when handling critical incidents. Excellent written communication skills and a strong focus on producing clear, actionable technical documentation. Proactive mindset with a strong focus on identifying, mitigating, and learning from security risks. Ability to collaborate effectively across technical and business functions within a globally distributed environment. Willingness and availability to support the APAC window and participate in a rotating on-call schedule. Benefits: Fully remote position based in Australia. Flexible Paid Time Off. Benefits designed to support health, finances, and overall well-being. Equity compensation and Employee Stock Purchase Plan. Growth and Development Fund to support ongoing professional learning. Parental leave. Team Member Resource Groups and an inclusive, collaborative working environment. Opportunity to work within a globally distributed security organization spanning AMER, APAC, and EMEA. Exposure to complex security incidents, cloud environments, threat intelligence, detection engineering, automation, and AI-assisted security workflows. Opportunity to influence security operations, incident response maturity, and scalable detection and response capabilities. Cross-regional collaboration supported by established processes, automation, and structured incident handovers.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
jobgether (lever) ↗Browse current Job and Scholarship listings from jobgether (lever) →