Navan

Navan

Sr. Security Engineer, Incident Response

Palo Alto, CA or San Francisco, CA · Senior

Sponsorship not specified$113k-$252kDetected 4 days ago
Cloud PlatformsCybersecuritySIEMSOARDetection EngineeringIncident ResponseLeadership

About the role

  • To determine a successful candidate's starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate's skills and experience, market demands, and internal parity.
  • Candidates may receive more information from the recruiter.

Responsibilities

  • Incident Response Leadership: Act as the primary Incident Lead during high-severity events. Own the end-to-end response lifecycle: driving triage, containment, evidence capture, and post-incident root-cause analysis.
  • Automation & SOAR Engineering: Use Tines to build and design workflows that automate triage, enrichment, and containment actions, significantly reducing operational toil and improving time-to-contain.
  • Architecture Partnership: Partner with infrastructure owners to ensure new systems ship across all cloud environments with the right telemetry, encryption, authentication, and response playbooks from day one.
  • Emergent Threats: Evaluate and design response strategies for frontier security concerns, such as automated agents or bots operating across infrastructure at scale.
  • Use Tines to build and design workflows that automate triage, enrichment, and containment actions, significantly reducing operational toil and improving time-to-contain.
  • Evaluate and design response strategies for frontier security concerns, such as automated agents or bots operating across infrastructure at scale.

Requirements

  • 5+ years of experience in a dedicated Incident Response, SOC, or Security Engineering role, with a proven track record of leading high-severity incident containment in fast-paced environments
  • Proven experience managing and tuning detection logic within CrowdStrike Falcon (or equivalent enterprise EDR/XDR) and enterprise SIEM platforms.
  • Excellent leadership skills with the ability to remain calm under pressure, coordinate cross-functional teams (Engineering, Legal, PR), and clearly communicate complex technical risks to stakeholders.
  • You will balance hands-on technical investigations with the leadership required to coordinate response efforts, leveraging a modern security stack to protect our global travel and expense platform.

Compensation

  • $113,400 - $252,000 USD
  • The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need.
  • To determine a successful candidate's starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate's skills and experience, market demands, and internal parity.
  • For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation.
  • Target incentive compensation for some roles may include a ramping draw period.
  • Compensation is higher for those who exceed targets.

Benefits

  • Detection & Endpoint Monitoring: Manage and fine-tune detection rule lifecycles utilizing CrowdStrike EDR and SIEM/SOAR capabilities to maintain high-precision, low-latency coverage against modern adversary tradecraft.
  • On-Call Rotation: Actively participate in the scheduled Incident Response on-call rotation, ensuring reliable coverage and operational readiness for emergent threats.

Company info

  • What We're Looking For:

This listing is sourced directly from Navan's careers page and normalized into a canonical job model.