Twilio logo
Twilio

Twilio is a Platform-as-a-Service (PaaS) company established in 2007. In support of a flexible workplace, Twilio has previously posted freelance, flexible sched

Senior Security Engineer, Incident Response

Location

California + 5 moreAll locations: California | Connecticut | New Jersey | New York | Pennsylvania | Washington

Posted

2 days ago

Salary

$141.5K - $176.9K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSCloudGoogle Cloud Platform

Job Description

Senior Security Engineer, Incident Response

Twilio

• Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications. • Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams. • Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity. • Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents. • Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment. • Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents. • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work. • Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Job Requirements

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Benefits

  • Competitive pay
  • Generous time off
  • Ample parental and wellness leave
  • Healthcare
  • Retirement savings program

Related Categories

Related Job Pages

More Security Operations Jobs

Security Operations Engineer Reserv Technologies, LLC Remote (Atlanta, GA) About Reserv Reserv is an InsurTech company creating and incubating cutting-edge AI and automation technology to bring efficiency and simplicity to claims. We’re stripping away the "mundane" to set a new global standard for the insurance industry! Founded by industry veterans, with deep experience in SaaS and digital claims, Reserv is venture-backed by Bain Capital and Altai Ventures and began operations in May 2022. We’re focused on automating highly manual tasks to tackle long-standing problems in claims while setting the new standard for TPAs, insurance technology providers and adjusters alike. As our Cybersecurity Analyst you won't just be watching a dashboard; you’ll be helping to build the shield that protects our digital assets and our customers. You’ll be responsible for executing tactical daily tasks and participating in broader planning efforts. If you thrive on novel problem-solving and adapt quickly to new technologies, you’ll fit right in! This is a hands-on technical role focused on protecting the organization’s digital assets from cyber threats by monitoring networks, identifying vulnerabilities, implementing security measures, threat hunting, responding to breaches and developing security policies & procedures. No day will be the same and you will continuously learn & grow! Successful candidates will bring experience utilizing and configuring various security tools such as IDP, EDR/XDR, SIEM, SOAR, IDS/IPS and secure email gateways. What to expect - Continuously monitor security telemetry to identify potential threats, malicious activity, or unauthorized access. Sniff out threats before they become a headline! - Investigate, analyze, classify, prioritize and contain security breaches in real-time, providing detailed reporting and post-incident analysis. Build a secure plan, not a work around, so it never happens again! - Conduct vulnerability assessments to identify system weaknesses before they are exploited - Coordinate and assist with penetration testing activities - Install, configure and maintain security software and systems such as endpoint security, intrusion detection, prevention systems and logging platforms - Install and fine-tune our arsenal—from EDR/XDR and SIEM to SOAR and IDS/IPS. - Research, analyze and stay up to date on the latest security trends, hacking techniques, emerging cyber threats - Educate employees and stakeholders on security protocols, phishing threats and data protection - Develop SOPs, playbooks/runbooks to consistently respond to common incidents that allow our security posture to scale as fast as our business - Hunt for unknown threats in the environment by analyzing logs based on current and emerging threat intelligence. Be the hero who identifies potential threats before they happen! Does this sound like you? - Minimum of 3 years of experience in the trenches of a dedicated cybersecurity role - Working understanding of NIST Cybersecurity Framework - Technical proficiency with MacOS, Windows, Unix/Linux - Experience securing and monitoring mobile devices - Knowledge of current threat actors, TTPs, and MITRE ATT&CK framework - Fluent in SIEM, EDR/XDR, and Vulnerability Scanners - Experience with cloud-based productivity platforms such as Google Workspace and/or Microsoft 365 - Demonstrated experience working with SIEM tools, vulnerability scanners, endpoint protection, email security and threat intelligence platforms - Experience with penetration testing - Experience performing risk assessments, drafting/maintaining cybersecurity policies and procedures, and constructing after-action reports with precise details - Familiarity with SSO and identity and access management systems - Security+, CySA+ or similar industry-standard security certifications - Strong written and verbal communication skills - You possess a relentless technological curiosity where "sniffing out" anomalies is becoming second nature - Experience working in a cloud-first or startup environment Icing on the cake - Bachelors degree in Cybersecurity, IT, or related field - Automation experience with various scripting languages (e.g. Bash, Python, PowerShell) - AWS and/or GCP certifications or demonstrated experience - Deep understanding of at least two major operating systems - Familiarity with the concepts of secure software development (SSDLC) What we offer - Generous health-insurance package with nationwide coverage, vision, & dental - 401(k) retirement plan with employer matching - Competitive PTO policy – we want our employees fresh, healthy, happy and energized - Generous family leave policy - Work from almost anywhere to facilitate your work life balance - Cool, functional swag - Apple laptop, large second monitor, and other quality-of-life equipment you may want Technology is something that should make your life easier, not harder! At Reserv, we value diversity and believe that a variety of perspectives leads to innovation and success. We are actively seeking candidates who will bring unique perspectives and experiences to our team. We welcome applicants from all backgrounds and encourage those from underrepresented groups to apply. If you believe you are a good fit for this role, we would love to hear from you!

Georgia
Future U Podcast logo

Security Operations Engineer

Future U Podcast

Jeff Selingo and Michael Horn discuss what’s next for higher ed and talk with the newsmakers you want to hear from most.

Full TimeRemoteTeam 1-10H1B No Sponsor

• Own the day-to-day operation of our centralized logging/SIEM — investigate alerts, create and tune detections, improve signal quality, and build the runbooks to act on them. • Drive vulnerability management end to end — scanning, triage, and remediation to closure across our stack. • Harden our cloud environment and CI/CD pipelines, establish security configuration baselines and guardrails, and manage them through Infrastructure as Code. • Partner with engineering teams to review new systems and architectural changes, identifying security risks early and helping build secure solutions by default. • Own secrets management, endpoint/EDR, and data-protection controls. • Own the security-critical IT surface — partnering with our existing IT function, not depending on it day-to-day. • Manage endpoint hardening. • Harden our core SaaS/business apps — identity provider, Google Workspace, GitHub, and the rest. • Own and continuously improve our security compliance platform (Vanta) — automate evidence collection, strengthen integrations, and improve its operational value. • Build toward compliance obligations as the business requires; turn policy into enforced reality by implementing the technical controls behind it, co-maintained with GRC + Legal.

United States

Role Description The Security Operations Manager is responsible for leading and maturing the organization's cybersecurity operations program with a primary focus on healthcare security, identity and access management, Single Sign-On (SSO) strategy, threat detection, incident response, and regulatory compliance. This role serves as both a technical leader and people leader, providing mentorship and professional development to Security Analysts while establishing scalable security operations capabilities across the enterprise. The Security Operations Manager will oversee day-to-day security operations, security monitoring, vulnerability management, incident response, identity security initiatives, and compliance activities supporting HIPAA, HITECH, and other healthcare regulatory requirements. This position partners closely with Infrastructure, Applications, Compliance, HR, and business stakeholders to ensure the confidentiality, integrity, and availability of enterprise systems and Protected Health Information (PHI). What You’ll Do - Security Operations Leadership - Lead and manage Security Operations (SecOps) activities across infrastructure, applications, cloud platforms, and endpoints. - Develop and maintain security monitoring, threat detection, incident response, and security governance processes. - Serve as the primary escalation point for complex security incidents and investigations. - Direct security event analysis, triage, containment, eradication, and recovery activities. - Establish operational metrics, dashboards, and KPIs to measure security effectiveness. - Drive continuous improvement initiatives to enhance enterprise cybersecurity maturity. - Coordinate security activities with managed security service providers and strategic security partners. - Identity Security & SSO Program Management - Lead enterprise Identity and Access Management (IAM) strategy and implementation. - Design, implement, and maintain Single Sign-On (SSO) platforms and identity federation technologies. - Manage security controls related to Azure AD/Entra ID, MFA, conditional access, RBAC, and privileged access management. - Partner with application owners to onboard business-critical applications into SSO platforms. - Establish identity governance processes, user lifecycle management standards, and access review programs. - Conduct identity risk assessments and develop remediation plans. - Oversee authentication modernization initiatives and Zero Trust security models. - Healthcare Security & Regulatory Compliance - Ensure compliance with HIPAA, HITECH, HITRUST, NIST CSF, and healthcare cybersecurity best practices. - Lead security risk assessments and remediation planning. - Support internal and external audits. - Develop and maintain healthcare-focused security policies, standards, and procedures. - Monitor controls protecting Protected Health Information (PHI) and Electronic PHI (ePHI). - Collaborate with Compliance, Legal, and Operations teams on security and privacy matters. - Participate in breach investigations, reporting requirements, and corrective action programs. - Threat Detection & Incident Response - Oversee SIEM, EDR, vulnerability management, email security, and threat intelligence platforms. - Direct proactive threat hunting activities. - Lead cyber incident response exercises and tabletop simulations. - Manage forensic investigations and root-cause analysis efforts. - Coordinate post-incident reviews and remediation planning. - Maintain incident response playbooks and operational procedures. - Vulnerability & Risk Management - Direct vulnerability management programs across servers, endpoints, cloud environments, and applications. - Establish risk-based prioritization methodologies for remediation. - Oversee remediation tracking and reporting. - Evaluate new technologies, vendors, and cloud services for cybersecurity risk. - Conduct third-party security assessments and vendor reviews. - Team Leadership & Mentorship - Supervise, coach, and mentor Security Analysts and junior cybersecurity staff. - Develop career growth plans, training programs, and technical development pathways. - Conduct regular one-on-one meetings and performance coaching. - Provide guidance on incident investigations, technical analysis, and security operations best practices. - Foster a collaborative culture focused on continuous learning and operational excellence. - Create succession planning and cross-training opportunities within the security team. - Participate in recruiting, interviewing, onboarding, and workforce planning activities. - Security Awareness & Collaboration - Promote cybersecurity awareness throughout the organization. - Deliver technical and non-technical security presentations. - Partner with Infrastructure, Application Development, Service Desk, and Compliance teams on security initiatives. Qualifications - Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience). - 7+ years of progressive cybersecurity experience. - 3+ years of experience leading security operations or security engineering initiatives. - Experience within healthcare, specialty pharmacy, or other highly regulated industries. - Hands-on experience implementing and administering enterprise SSO and IAM platforms. - Strong experience with: - Microsoft Entra ID (Azure AD) - Single Sign-On (SAML, OIDC, OAuth) - Multi-Factor Authentication (MFA) - SIEM platforms - EDR/XDR technologies - Vulnerability Management - Security Incident Response - Experience supporting HIPAA compliance and healthcare security assessments. Qualifications Preferred - CISSP - HCISPP - CISM - GIAC Certifications - Microsoft Identity & Access Administrator Certification - HITRUST experience - Healthcare cybersecurity leadership experience Benefits - Purpose-driven work with real impact - A patient-first, clinician-led culture - Supportive, collaborative teammates - The opportunity to grow with a company building something meaningful Pay Range/Rate $115,000 — $135,000 USD Physical Demands The physical demands described here represent those required for an employee to successfully perform the essential functions of this role. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions. Other Requirements - Participate annually in required legal and ethical compliance training. - Consistently act in compliance with LUX Infusion’s legal, ethical, and compliance policies. - Adhere to all standards and procedures outlined in the LUX Infusion Compliance Manual. - Refrain from any behavior that could be considered unethical or unlawful. Expectations for All Employees All LUX Infusion team members are expected to support the organization’s mission, vision, and values by demonstrating integrity, dedication, compassion, and enthusiasm. This includes placing patients first, working collaboratively with a “stacked-hands” mindset, and maintaining a consistent focus on quality, accountability, and continuous improvement. General Information The statements above are intended to describe the general nature and level of work performed by individuals in this role. They are not intended to be an exhaustive list of all responsibilities, duties, or skills required.

United States
$115K - $135K / year
ServiceNow logo

Advisory Presales Solution Consultant - Risk & SecOps

ServiceNow

As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.

Full TimeRemoteTeam 10,001+Since 2004H1B Sponsor

Role Description As a member of our Risk & Security Solution Consulting team, you will have a major impact on our future success by supporting the Risk & Security Solution Sales Team in driving net new business. You will guide revenue for our risk products with the support and partnership of Sales, Product Management, and the executive team. This is a hands-on technical consultant who can go wide and deep on solution delivery and solution positioning, as well as the risk domain itself, during sales cycles. What you get to do in this role: - The Solution Consultant is a technical consultant with the advanced ability to develop, position and provide product-specific advisory support during sales cycles while achieving quarterly and annual sales goals for an assigned territory. - Support solution sales as a technical and domain expert of a client-facing sales team. - Lead discovery workshops to determine customers' challenges and give product demonstrations to align our solution with customer needs. - Understand customer challenges and goals and map this back to solution capabilities. - Answer product feature and technical questions from customers, channel partners and ServiceNow colleagues. - Act as the domain SME across the core areas of risk (including but not limited to Risk Management, Internal Controls, Regulatory Compliance, Policy Management, Cyber Risk, TPRM, BCM, Operational Resilience, Privacy and ESG). - Provide feedback to product management about product enhancements that can address customer needs and provide additional value. - Share and learn best practices and re-usable assets with other Solution Consultants to enhance the quality and efficiency of the team. - Identify, build-out and deliver cross product sales opportunities (solutions that cover multiple different ServiceNow solutions) that map to customer challenges and industry needs. - Stay current on competitive analysis, trending regulatory and risk developments and broader market differentiation. - Support/speak at marketing events including executive briefings, conferences, user groups, and trade shows. Qualifications - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. - Proven (c. 6-10 years) pre-sales solution consulting or sales engineering experience with specific demonstrable knowledge of GRC and SecOps topics and solutions. - Deep domain expertise in GRC, Information Security, Security Operations, AI Governance, Third Party Risk Management, or Operational Resilience. - Executive presence and business acumen to operate as a peer with C-suite buyers. - Self-starter mentality with demonstrated ability to operate autonomously and drive outcomes independently. - Technical fluency to conduct early stage product demonstrations and understand API/integration patterns. - Proficiency with the ServiceNow platform or technical experience with cloud software solutions. - Experience working collaboratively with product management, product marketing, partners, and professional services. - Proven soft skills relating to effective presentation of content and working collaboratively in a team. - Territory management skills, including pipeline building and working with Sales counterpart to guide execution excellence. - The ability to travel, as necessary with offices in Munich, Frankfurt, Berlin, Hamburg and Dusseldorf. - Fluency in English and German essential. Company Description ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law. At ServiceNow, we lead with flexibility and trust in our distributed world of work. If you require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us for assistance.

EMEA