Security Engineer
WHO WE'RE LOOKING FOR 🌟 We're looking for an Incident Detection & Response Engineer — a hands-on security professional who can strengthen Manychat’s ability to detect, investigate, and respond to security threats across cloud, application, identity, and endpoint environments. Reporting to the Cyber Operations Lead, you’ll play a key role in building and operating our detection and response capabilities. You’ll work closely with Infrastructure, IT Operations, and Engineering teams to identify suspicious activity, investigate incidents, improve security monitoring, and help make our environment more resilient. This role is ideal for someone who enjoys technical investigation, structured response, automation, and continuous improvement of detection logic, playbooks, and operational processes. WHAT YOU'LL DO 🚀 Monitor, triage, and investigate security alerts across SIEM, EDR, email security, cloud security, identity, and application security tools. Lead hands-on investigation of security events involving AWS, Okta, endpoints, SaaS platforms, infrastructure, and application logs. Perform incident response activities: scoping, containment, evidence collection, root cause analysis, remediation support, and post-incident reviews. Develop and improve detection logic, correlation rules, alert tuning, and use cases across cloud, identity, endpoint, and application layers. Analyze logs and telemetry from sources such as AWS CloudTrail, GuardDuty, Security Hub, Okta, EDR, WAF, DNS, VPN, and business systems. Create and maintain incident response playbooks, investigation runbooks, escalation procedures, and operational documentation. Partner with Infrastructure, IT Operations, and Engineering teams to validate findings, remediate risks, and improve security controls. Support vulnerability, misconfiguration, and threat investigations by correlating signals from multiple security tools. Contribute to threat hunting activities based on known attacker techniques, suspicious behavioral patterns, and emerging threats. Help improve visibility across cloud, endpoint, identity, and application environments. Support security incident reporting, timelines, post-mortems, and lessons-learned documentation. Contribute to compliance evidence and operational controls related to SOC 2 and ISO 27001 incident response requirements. Help automate repetitive investigation and response tasks where practical. TO SHINE IN THIS ROLE 💥You'll need: 5+ years of hands-on experience in security operations, incident response, detection engineering, SOC, cloud security, or related technical security roles. Practical experience investigating security alerts and incidents across cloud, identity, endpoint, and network/application layers. Strong experience working with SIEM platforms, including log analysis, alert triage, rule tuning, and investigation workflows. Hands-on experience with EDR tools and endpoint investigation across macOS and/or Windows environments. Experience in...