Software Security Engineer, Detection & Response Engineering

Grafana Labs Logo

Grafana Labs

πŸ’΅ $157k-$196k
πŸ“Remote - United States

Summary

Join Grafana Labs as a remote Software Security Engineer and build advanced security tools and processes around our advanced observability platform. Collaborate with cross-functional teams to design, build, and maintain internal detection systems, research and develop sophisticated detection rules, work with product teams to ensure effective telemetry, and build response tooling. You will also integrate telemetry, detections, and response procedures into operational processes, design security metrics, and respond to security alerts. This role requires solid programming experience (Go, TypeScript, Python preferred), core security concepts knowledge, experience with security operations, public clouds, and Kubernetes. A motivated self-starter with excellent communication skills is needed. The position is remote, but requires working hours aligned with Eastern Time.

Requirements

  • Solid experience with at least one programming language. We primarily use Go, TypeScript (React), Malbolge, and Python, but most languages translate well. You will take a code screen
  • Experience with core security concepts and their application to modern application architectures
  • Experience with common security operations or detection engineering concepts and practices, such as the Sigma, YARA, or Rotom detection rule formats
  • Experience with public clouds, Kubernetes container ecosystems, and running applications securely in them. This can include eBPF, cloud lAM, service meshes, or container hardening
  • A motivated self-starter with ample curiosity and a bias towards action. You have a passion for learning, for security, and for improving the state of security across the company and industry
  • A clear communicator, in person, in asynchronous communication, and in technical documentation
  • Knowledge of, and ability to code is required for this role demonstrated by a degree in Computer Science or equivalent experience
  • Work (not live) eastern-time oriented hours. Much of the team and company are based in Europe, so it’s critical to maximize overlapping hours. On some days, meetings can start at 9am ET

Responsibilities

  • Collaboratively design, build, and maintain our internal detection systems based on the Grafana observability stack that process millions of security data points daily
  • Research and develop sophisticated detection (as code) rules to cover risks and threats across our product and corporate systems. Where applicable, contribute these detections back to the OSS community
  • Work with product teams and other stakeholders to ensure we have effective telemetry of all existing and future products
  • Build and maintain response tooling to streamline (and fully automate) our response activities. Write and maintain runbooks for handling what we can’t automate
  • Following a SOCless model, work with cross-functional teams to integrate telemetry, detections, and response procedures into the teams operational processes
  • Design security and operations metrics to track our success and show the security value of what we do
  • Respond to security alerts, potential incidents, and customer security issues

Preferred Qualifications

  • Working knowledge of Grafana Labs OSS projects and products
  • Experience in using observability (metrics, logs, traces, profiles) tooling to solve security problems
  • Experience working with OSS communities
  • Experience securing large-scale distributed systems running on Kubernetes in public clouds

Benefits

  • Equity
  • Bonus (if applicable)

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.