Senior SOC Engineer (DFIR & Hunt)

Seattle

DigitalOcean

An ocean of simple, scalable cloud solutions.

View all jobs at DigitalOcean

Apply now Apply later

Do you ever wonder what happens inside the cloud?

DigitalOcean (NYSE: DOCN) simplifies cloud computing so builders can spend more time creating software that changes the world. With our mission-critical infrastructure and fully managed offerings, DigitalOcean enables startups and small and medium-sized businesses (SMBs) to rapidly deploy and scale modern applications. As a remote-first organization, our employees, like our customers, are based around the world.

We want people who are passionate about making the internet a safer place for everyone 

We are looking for an inspired and motivated technical contributor to join the DigitalOcean Security Operations Center.  In this role, you will be a key member of DigitalOcean’s Digital Forensic and Incident Response (DFIR) team, charged with improving the security posture of DigitalOcean both reactively and proactively, ensuring a secure cloud infrastructure for both customers and internal users. You will gain skills in one or more of multiple focal areas including digital forensics, incident response, platform abuse, legal/regulatory enforcement, and enterprise security. You will use your analytical skills to identify and eliminate bad actors inside the DigitalOcean platform or leverage your engineering skills to create innovative ways to detect and respond to potential threats.

With over 500,000 customers utilizing 10+ data centers and 10,000+ hypervisors every day, our Security Operations Center never loses sight of the role we play in making the internet a more secure place for everyone.

What You’ll Be Doing:

  • Handling live intrusions and incident response cases with on-call rotations, in an internal-oriented and transparent manner, to minimize the impact of bad actors on assets.
  • Collect digital artifacts from cloud systems for analysis to reconstruct what may have transpired on a system leveraging digital forensics methodologies.
  • Analyzing network traffic to identify compromised systems, negate denial of service attacks, and pinpoint resource abuse.
  • Identifying trends in abusive activity, communicating with leadership to keep them apprised, and advocating for appropriate product changes to prevent future occurrences.
  • Acting as a point of escalation for security monitoring and related incidents: providing supporting data for critical issues, downtime events, and Post-Mortem reports.
  • Helping build tools to identify or automate response to harmful activity.
  • Establishing an understanding of DigitalOcean’s entire production environment, from applications to infrastructure, keeping up-to-date with material changes and future directions.
  • Building strong relationships with the other technical teams across our engineering and infrastructure functions to harden account, platform, and service structures to combat intrusions, compromises, and disruptive activities.

What We’ll Expect From You:

  • Experience performing live incident response activities transparently (sans picerl), in a team environment where accuracy of analysis determines business impact.
  • Hands-on dead-disk and live digital forensics experience, on Linux or Unix systems using open source tools (eg, volatility, sleuthkit) in production environments at scale.
  • Ability to differentiate between normal and unusual resource usage patterns in customer and employee network/system behaviors in order to hunt for subtle anomalous patterns.
  • Data analysis skills, including familiarity with relational databases, structured query languages (sql), logging infrastructures (syslog, elastic), and data visualization tools (looker, grafana, kentik).
  • Familiarity with basic static and dynamic malware analysis for triage, identification, prioritization, and remediation of new malware families and behaviors (e.g: x86 assembly, binary analysis).
  • A high degree of curiosity and aptitude, with a clear passion for security and the desire to keep our employees, customers, and the internet safe.
  • Clear written and verbal communication skills to include; technical writing, presenting, coaching, mentoring.
  • Consistently improving security as the platform scales, driving continuous improvement through data collection and correlation, being mindful that security should be an efficiency enabler for the business - not a detractor.
  • Bonus: Experience in one or more of the following:
    • Vulnerability Analysis, Scoping, and Mitigation Planning
    • Threat Intelligence Collection / Analysis / Dissemination
    • Network Protocol Analysis
    • Coding, automation, or scripting skills for tool building
    • Detection Engineering

Why You’ll Like Working for DigitalOcean:

  • We are proud to work here. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud computing so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions. 
  • We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
  • We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support your overall well-being, from one-time work from home stipend to wellness allowance to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
  • We reward our employees. The salary range for this position is between $116,400.00 - $174,000.00 based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program. 
  • We value diversity and inclusion. We are an equal-opportunity employer, and recognize that diversity of thought and background builds stronger teams and products to serve our customers. We approach diversity and inclusion seriously and thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

*This is a remote role

#LI-Remote

Apply now Apply later
  • Share this job via
  • 𝕏
  • or
Job stats:  0  0  0

Tags: Automation Cloud DFIR Forensics Grafana Incident response Linux Malware Monitoring Open Source RDBMS SANS Scripting SOC SQL Threat intelligence UNIX

Perks/benefits: Career development Competitive pay Conferences Equity / stock options Flex hours Flex vacation Home office stipend Salary bonus Startup environment Team events Wellness

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.