New Relic s Information Security Team is searching for a Senior Application Security Engineer! If you enjoy a work environment where youre part of a successful distributed team that collaborates to achieve successful outcomes, we would love to talk to you! In this role, you will use your background and deep understanding of how attackers gain access to systems and apply it to respond to cyber security incidents covering all phases including identification, containment and eradication.
As an engineer of our growing Security Incident Response team, you will collaborate with teams throughout the organization, providing security insight, mitigation strategies, and preventive measures from detections. You will help develop our security program through collaboration, investigation, documentation, and engineering practices.
What youll do
Support and maintain response strategy and tooling to severe incidents and key attack scenarios.
Support the SoC alert lifecycle: triage security risk, investigate alerts, develop runbooks, policies and procedures to help the company respond, and run retrospectives to coordinate effort across the company to prevent future incidents
Maintain healthy working relationships with our managed security service providers and respond to incident escalations.
Maintain coordination and communication streams horizontally and vertically as part of major cyber related incident handling.
Know the latest APT tactics and techniques and use engineering practices to detect and respond.
Provide technical expertise to engineering teams on standard methodologies, tools and frameworks.
Work with product managers, senior management, and end users to drive security maturity across the business.
This role requires
You have at least five years of recent experience working in a threat hunting, threat intelligence, incident response, or security engineering role
Experience configuring security incident and event management tools, including creating event filtering, correlation rules, and reports
Strong understanding of the MITRE ATT&CK Framework
Experience performing risk assessment, threat tracking, or vulnerability management and success in evaluating and communicating severity, impact, and likelihood of a risk to a wide audience
Familiarity with digital forensic tools and techniques for hands-on response during incidents.