Chainlink Labs

Chainlink Labs

Security Response Engineer, Incident Response

United States

Sponsorship not specifiedDetected 54 days ago
PythonGoRustSwiftCybersecurityIncident ResponseCadenceLeadershipCommunication

About the role

  • You'll serve as incident commander - owning the high-level coordination of incidents from scoping through to recovery and post-mortem improvements.
  • We're looking for a seasoned individual contributor who is comfortable operating across diverse environments.
  • You would help continuously improve our response capabilities and efficiency by collaborating with internal and external stakeholders across the company.

Responsibilities

  • Own and improve the incident response lifecycle: act as incident commander for high-severity incidents
  • Improve response readiness: create and automate playbooks, conduct tabletop exercises
  • Address security telemetry gaps: improve existing or build/deploy new tools
  • Proactively identify and implement areas of improvement and modernization
  • experience as the primary incident commander for high‑severity security incidents involving multiple teams and external stakeholders, and can independently manage incident timelines, decisions, and communications
  • As a Security Response Engineer, you'll own the full security incident response lifecycle.

Requirements

  • Operational rigor and investigation depth: demonstrated experience with triage, scoping, containment, and remediation across endpoint, cloud, and/or network based incidents
  • Experience in macOS-heavy environments: has secured and operated a predominantly macOS endpoint fleet: deploying / managing endpoint controls, telemetry collection, and performing investigations on macOS systems.
  • Previous coding experience (Python, Go, Rust, or similar): scripting for data parsing/enrichment and simple automations
  • By submitting your application, you are agreeing to our use and processing of your data as required.
  • demonstrated experience with triage, scoping, containment, and remediation across endpoint, cloud, and/or network based incidents

Nice to have

  • Experience with detections‑as‑code (Sigma) development and workflows.
  • Domain experience with blockchain/Web3 threats.
  • Open-source contributions to security related projects.
  • Preferred Requirements

Skills

  • improve existing or build/deploy new tools

Company info

  • triage inbound alerts/escalations, coordinate internal and company-wide incidents
  • Join the team's on-call rotation: triage inbound alerts/escalations, coordinate internal and company-wide incidents

This listing is sourced directly from Chainlink Labs's careers page and normalized into a canonical job model.