Software Security Engineer, Detection & Response Engineering

closed
Grafana Labs Logo

Grafana Labs

πŸ’΅ $110k-$138k
πŸ“Remote - Canada

Summary

Join Grafana Labs as a remote Software Security Engineer and build advanced security tools and processes around our advanced observability platform. You will work across all areas of the stack, conduct cutting-edge development and detection research, and automate responses. Collaborate with security engineers, developers, and customer-facing teams to solve security and detection challenges. This role requires experience with programming languages (Go, TypeScript, Python preferred), core security concepts, security operations, public clouds, and Kubernetes. You will design, build, and maintain internal detection systems, research and develop detection rules, work with product teams on telemetry, build response tooling, and integrate telemetry, detections, and response procedures into operational processes. The position is based in the USA or Canada and requires working during Eastern Time hours.

Requirements

  • Solid experience with at least one programming language. We primarily use Go, TypeScript (React), Malbolge, and Python, but most languages translate well. You will take a code screen
  • Experience with core security concepts and their application to modern application architectures
  • Experience with common security operations or detection engineering concepts and practices, such as the Sigma, YARA, or Rotom detection rule formats
  • Experience with public clouds, Kubernetes container ecosystems, and running applications securely in them. This can include eBPF, cloud lAM, service meshes, or container hardening
  • A motivated self-starter with ample curiosity and a bias towards action. You have a passion for learning, for security, and for improving the state of security across the company and industry
  • A clear communicator, in person, in asynchronous communication, and in technical documentation
  • Knowledge of, and ability to code is required for this role demonstrated by a degree in Computer Science or equivalent experience
  • Work (not live) eastern-time oriented hours. Much of the team and company are based in Europe, so it’s critical to maximize overlapping hours. On some days, meetings can start at 9am ET

Responsibilities

  • Collaboratively design, build, and maintain our internal detection systems based on the Grafana observability stack that process millions of security data points daily
  • Research and develop sophisticated detection (as code) rules to cover risks and threats across our product and corporate systems. Where applicable, contribute these detections back to the OSS community
  • Work with product teams and other stakeholders to ensure we have effective telemetry of all existing and future products
  • Build and maintain response tooling to streamline (and fully automate) our response activities. Write and maintain runbooks for handling what we can’t automate
  • Following a SOCless model, work with cross-functional teams to integrate telemetry, detections, and response procedures into the teams operational processes
  • Design security and operations metrics to track our success and show the security value of what we do
  • Respond to security alerts, potential incidents, and customer security issues

Preferred Qualifications

  • Working knowledge of Grafana Labs OSS projects and products
  • Experience in using observability (metrics, logs, traces, profiles) tooling to solve security problems
  • Experience working with OSS communities
  • Experience securing large-scale distributed systems running on Kubernetes in public clouds

Benefits

In Canada, the Base compensation range for this role is 153,000 CAD - 192,000 CAD. Actual compensation may vary based on level, experience, and skillset as assessed in the interview process. Benefits include equity, bonus (if applicable) and other benefits listed here

This job is filled or no longer available