Headquartered in Seattle, Washington, Avalara has been disrupting the world of sales tax management since its inception in 2004. Since the company was founded,
Senior Security Incident Responder
Location
United States
Posted
7 days ago
Salary
$148.8K - $297.3K / year
Seniority
Senior
Job Description
Senior Security Incident Responder
Avalara
Role Description Avalara is looking for an experienced Senior Security Incident Responder to join the Detection and Response Team. You will have a track record in incident response, demonstrating advanced technical expertise and leadership capabilities. As a Senior Security Incident Responder, you will help protect Avalara. This includes detecting, investigating, and mitigating security incidents. You will also be an important contributor in improving our incident response capabilities. This is a remote position. Responsibilities - Strengthen Avalara's security posture, operational resilience, and regulatory standing by increasing the Detection and Response team's investigative capacity, programmatic, and sustainable coverage across an evolving enterprise threat landscape. - Detect, investigate, and contain security incidents within SLA to protect Avalara's customers, revenue, and compliance standing. - Accelerate capability across the team by delivering runbooks, detection improvements, and automation. - Embed AI-augmented investigation practices that improve analytical speed, confidence, and scale. - Improve investigation quality by setting a visible standard of analytical depth and thorough documentation. - Actively develop the analysts around you by sharing techniques and providing feedback. - Identify and lead improvements to how the team operates, strengthening response workflows, cross-functional coordination, and metrics that demonstrate security impact to leadership. - Represent the Detection and Response function with confidence in cross-functional engagements, audits, and stakeholder discussions — reinforcing trust in Avalara's security posture across the organization. Qualifications - 5+ years' experience in Security Incident Response. - Experience across the information security domain, including familiarity with endpoint, email, network, cloud security, vulnerability management, incident response, and threat intelligence. - Experience with log analysis, network security, digital forensics, and incident response investigations. - Leverages advanced data analysis to diagnose root causes, optimize processes, and deliver high-impact solutions. - Effectively collaborate with different stakeholders. - Perform and coordinate tasks during high-pressure situations. - Proficiency in leveraging AI tools within security operations is a plus. - Ability to script / code using Python or an equivalent language is a plus. - Bachelor's degree in computer science, information security, or relevant experience. - Certifications related to digital forensics and incident response is a plus. Requirements - Execute incident response activities and lead related workstreams as the Senior Security Incident Responder. - Continuously monitor security systems, including Intrusion Detection Systems (IDS), Endpoint Detection and Response (EDR) platforms, software firewalls, and Security Information and Event Management (SIEM) platforms. Gather and analyze evidence from affected systems, logs, and network traffic. - Conduct detailed investigations of security incidents to determine the root cause, scope, and impact. Document all aspects of security incidents, including timelines, actions taken, and lessons learned. - Develop, document, and implement strategies, runbooks, capabilities, and techniques for incident response. - Perform forensic analysis of compromised systems to identify the techniques and tactics used by attackers, or as directed by Legal. - Work cross-functionally with security engineering and other teams to build solutions for analyzing security events at scale and protecting Avalara from threats. - Collaborate closely with cross-functional teams including IT, Security Operations, Legal, HR, and Compliance to manage and mitigate incidents effectively. - Strengthen KPIs and metrics for measuring response effectiveness and provide detailed reporting to internal stakeholders. - Stay up to date with the latest security threats, vulnerabilities, and incident response techniques through ongoing training and professional development. - Act as a subject matter expert in incident response, representing the team in meetings, audits, and presentations. - Participate in rotating On Call shifts that utilize a paging system in case a security event requires attention. Benefits - Total Rewards: In addition to a great compensation package, paid time off, and paid parental leave, many Avalara employees are eligible for bonuses. - Health & Wellness: Benefits vary by location but generally include private medical, life, and disability insurance. - Inclusive culture and diversity: Avalara strongly supports diversity, equity, and inclusion, and is committed to integrating them into our business practices and our organizational culture. We also have a total of 8 employee-run resource groups, each with senior leadership and exec sponsorship.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Manager, Compliance & Information Security
instellixNitrobox builds enterprise-class automated billing and monetization solutions for any sophisticated business model
• Functional responsibility for Compliance and Information Security at instellix • Development of the governance framework • Ensuring security and compliance standards • Close collaboration with various departments • Development of the compliance program
• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
SAP Security & GRC Engineer
Bright Vision TechnologiesBright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.
Role Description We are seeking an experienced SAP Security & GRC Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment. Key Responsibilities - Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles. - Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications. - Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management. - Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit. - Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms. - Operate SAP GRC Process Control for continuous controls monitoring and policy management. - Implement security for Fiori applications, including catalogs, groups, and front-end authorizations. - Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS. - Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans. - Implement transport security, table logging, and audit logging in line with internal security policies. - Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams. - Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time. - Mentor junior team members and support knowledge transfer across the security team. Qualifications - Bachelor’s degree in Computer Science, Engineering, or a related technical discipline. - Five or more years of SAP Security / GRC experience in enterprise landscapes. - Strong hands-on experience with SAP authorization concepts and role design. - Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM). - Experience supporting SAP audits and remediation activities. - Hands-on experience securing Fiori, BTP, and cloud SAP applications. - Familiarity with SAP IDM or third-party IGA tooling. - Working knowledge of SAP Process Control. - Strong understanding of regulatory frameworks such as SOX, GxP, and PCI. - Excellent communication and documentation skills. Preferred Qualifications - SAP-certified Security or GRC credentials. - Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations. - Familiarity with HANA security and analytic privileges. - Experience with continuous controls monitoring frameworks. - Exposure to SAP RISE / Grow security operating models. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] or contact us at (908) 505-3899. Equal Employment Opportunity (EEO) Statement Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall. BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.


