安全事件响应工程师
查看雇主原标题
Security Incident Response EngineerStripe · US Remote
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 60/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有抱负的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着,在从事你职业生涯中最重要的工作的同时,你将拥有一个前所未有的机会,让全球经济触手可及。
岗位职责
你将运用你的安全工程经验来提升 Stripe 的事件响应能力。重点在于用户和实体行为分析以及端点加固,你将深入了解 Stripe 的系统、工具和工作流程,从而能够区分合法活动和恶意活动。利用威胁情报和收集到的遥测数据,你将指导和构建可随公司规模扩展的、针对 Stripe 的信号增强逻辑和事件响应解决方案。最后,在安全事件期间,你的分析能力将至关重要,用于减少不确定性、发现根本原因,并为未来的预防和检测机制提供依据。
• 分析和调查客户端设备上发生的广泛威胁或活动
• 为检测模型和现有系统的增强制定需求
• 从不同来源收集、转换并将原始数据摄取到威胁检测管道中
• 简化事件响应能力,确保工具和流程清晰明确
• 与安全工程和数据科学团队跨职能合作,构建用于大规模分析安全事件数据并保护 Stripe 网络、系统和数据免受威胁的解决方案
• 提供可操作的洞察,帮助识别、预防、检测和响应异常或潜在恶意的用户和实体活动
• 作为安全分析和检测项目以及 Stripe 全公司安全计划相关利益方团队的主题专家和主要联系人
• 与团队成员高效协作,领导项目,指导他人,并在团队内制定和倡导质量标准
任职要求
我们正在寻找符合该职位最低要求的人选。如果你符合这些要求,我们鼓励你申请。优先资格是加分项,而非必需条件。
最低要求
• 3 年以上分析大型数据集以解决问题和/或构建采用行为方法保障安全的模型的经验
• 计算机科学或相关领域的学士或硕士学位,或同等经验
• 精通 Python 和 SQL,并熟悉其他编程语言
• 具备日志分析(例如第一方或第三方应用程序、系统/数据访问、事件日志)、网络安全、数字取证和事件响应调查方面的现有经验
• 熟练掌握开发和使用新颖分析方法来构建、自动化和改进检测与响应系统
• 能够清晰地传达结果并专注于影响力
• 能够创造性地、全面地思考如何在复杂环境中降低风险
• 具备对抗性思维,理解威胁行为者的目标、行为和 TTP。
• 具备软件工程、数据处理和分析工具(例如 Databricks/Jupyter、Trino 等)方面的经验
• 熟悉用于大数据处理和/或数据科学的常见开源框架(PySpark、Pandas、Sci-kit Learn 等)
• 具备战术威胁情报和/或在企业环境中猎捕高级威胁行为者的经验
• 熟悉网络可观测性、安全软件或数据工程解决方案(osquery、Splunk/LogScale 等)
• 具备以下一个或多个领域的经验:用户和实体行为分析(UEBA)、安全信息事件管理(SIEM)、安全编排自动化与响应(SOAR)或数据丢失防护(DLP)
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
岗位职责
You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity. Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms.
• Analyze and investigate a broad range of threats or activities occurring on client devices
• Develop requirements for detection models and enhancements to existing systems
• Collect, transform, and ingest raw data from disparate sources into threat detection pipelines
• Streamline incident response capabilities, ensuring the tooling and processes are clear
• Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
• Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity
• Act as the subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs as well as Stripe-wide security initiatives
• Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
任职要求
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security
• B.S. or M.S. Computer Science or related field, or equivalent experience
• Expert knowledge of Python and SQL, and familiarity with other programming languages
• Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
• Proficiency with developing and using novel analytical methods to build, automate, and improve detection and response systems
• Ability to communicate results clearly and focus on impact
• Ability to think creatively and holistically about reducing risk in a complex environment
• An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
• Experience with software engineering, data processing and analysis tools (e.g. Databricks/Jupyter, Trino, etc.)
• Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
• Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
• Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk/LogScale, etc.)
• Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information event management (SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)