Senior Security Analyst, CSIRT 1. You’ll serve as the first line of response when a security alert needs to be triaged, and lead the incident response/ management as needed 2. You’ll also refine our alerting rules to improve our signal/noise ratio, because no one wants to be a button-pusher or SOC monkey 3. If something happens twice, you’ll write a runbook for it. If it happens three times, you’ll figure out a way to automate that runbook 4. You’ll partner with Trust & Safety and Threat Intelligence on some of our attacker investigations to build TTP profiles 5. You’ll be part of a light on-call rotation with counterparts in multiple time zones 6. You’ll lead a culture of excellence by mentoring peers and share knowledge 7. You’ll collaborate with cross functional teams like engineering, product development, compliance to ensure timely Incident Response
1. You’ve been doing practical security things (incident response, phishkit/malware analysis, investigating account compromises, etc) for a while now, probably in the realm of 7+ years 2. You don’t just reflexively open up a Jupyter Notebook during an investigation, you’ve actually got favorite Jupyter Notebooks you’ve built up over the years, because you like backing up 3. 3. your conclusions with data, and you like automating things 4. You are good in understanding and analyzing multitude of artifacts across network and host level 5. You frequently get praise from your peers and coworkers about your communication skills, both written and verbal 6. Your high degree of empathy means that your coworkers trust you to help solve their security problems, because you never come across as judgmental or condescending 7. Pressure doesn’t get to you, even in high intensity situations or environments Nice to haves: 1. You would bring a diverse perspective to the team: for example, maybe you took an unconventional route to get into your current security career 2. You’ve got a passing familiarity with blockchains and cryptocurrency, or at least a good story about how you thought about investing in Bitcoin in 2014 but decided not to 3. You’re comfortable doing some basic scripting and writing alert rules in Python and running queries in SQL/Snowflake 4. You’ve good understanding of Cloud and SaaS technologies 5. You are good in analyzing data at scale and perform investigations to identify adversary behavior 6. You’ve got some experience with OSINT and threat hunting 7. You‘ve got some experience doing incident response in the cloud 8. You’d prefer if everyone just settled on using the ATT&CK framework already 9. You have got experience in analyzing attacker methodologies and build detections that will enhance the existing security posture
1. Statutory Social Security and Health Insurance 2. Annual health check reimbursement 3. Monthly Commuter Allowance 4. Monthly Gym Allowance 5. Fertility Counseling and Benefits 6. Individual Career Development Budget 7. 18 weeks Paid Maternity and Paternity Leave 8. Volunteer Time Off Link: https://www.coinbase.com/careers/positions/4896011