Security Engineer
Core
Incident Detection & Response Engineer strengthening Manychat's ability to detect, investigate, and respond to security threats across cloud, application, identity, and endpoint environments.
Role type
Senior Incident Detection & Response Engineer
Builds
Detection logic, correlation rules, alert tuning, incident response playbooks, and operational documentation for a SaaS platform.
Domain
Cybersecurity, Cloud Security, Identity Security, Endpoint Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM log analysis and alert triage, EDR investigation on macOS/Windows, identity event investigation (Okta/IAM), incident response (scoping, containment, remediation), threat hunting, detection engineering, compliance evidence gathering (SOC 2/ISO 27001), automation scripting
Preferred skills
Detection-as-code workflows, AWS security services (CloudTrail, GuardDuty, Security Hub), digital forensics, WAF/DNS/VPN security, DAST/SAST/SCA tools, Python/Bash/Terraform scripting
Technologies
SIEM, EDR, Okta, AWS (CloudTrail, GuardDuty, Security Hub, IAM, Config), WAF, DNS, VPN, MDM, Python, Bash, Terraform
Responsibilities
Monitor and triage security alerts across SIEM, EDR, email, cloud, identity, and application tools; Lead hands-on investigation of security events; Perform incident response activities including containment and root cause analysis; Develop and improve detection logic and use cases; Analyze logs and telemetry from various security sources; Create and maintain incident response playbooks and runbooks; Partner with engineering teams to validate findings and remediate risks; Contribute to threat hunting activities; Support security incident reporting and post-mortems; Contribute to compliance evidence for SOC 2 and ISO 27001; Help automate repetitive investigation tasks.
Seniority
Senior, hands-on IC