Back to all jobs
T
Sr. Security Engineer, Incident Response
tripactions
Austin1d ago
- Seniority
- Senior
About the role
<div>At Navan, you will serve as the technical lead for our incident response lifecycle, driving the containment and remediation of security threats across our multi-cloud infrastructure, products, and operational environments. You will balance hands-on technical investigations with the leadership required to coordinate response efforts, leveraging a modern security stack to protect our global travel and expense platform.</div>
<div><br><strong>What You’ll Do:</strong></div>
<ul>
<li><strong>Incident Response Leadership:</strong> <strong>Act as the primary Incident Lead during high-severity events.</strong> Own the end-to-end response lifecycle: driving triage, containment, evidence capture, and post-incident root-cause analysis.</li>
<li><strong>Automation & SOAR Engineering:</strong> Use <strong>Tines</strong> to build and design workflows that automate triage, enrichment, and containment actions, significantly reducing operational toil and improving time-to-contain.</li>
<li><strong>Detection & Endpoint Monitoring:</strong> Manage and fine-tune detection rule lifecycles utilizing <strong>CrowdStrike EDR and SIEM/SOAR capabilities</strong> to maintain high-precision, low-latency coverage against modern adversary tradecraft.</li>
<li><strong>Data Protection & Visibility:</strong> Monitor and respond to data risks across endpoints, identity, and SaaS applications using <strong>Cyberhaven DLP</strong>. Identify gaps in IAM and vulnerability management and advocate for direct fixes.</li>
<li><strong>Architecture Partnership:</strong> Partner with infrastructure owners to ensure new systems ship across <strong>all cloud environments</strong> with the right telemetry, encryption, authentication, and response playbooks from day one.</li>
<li><strong>Emergent Threats:</strong> Evaluate and design response strategies for frontier security concerns, such as automated agents or bots operating across infrastructure at scale.</li>
<li><strong>On-Call Rotation:</strong> <strong>Actively participate in the scheduled Incident Response on-call rotation</strong>, ensuring reliable coverage and operational readiness for emergent threats.</li>
</ul>
<p><strong>What We’re Looking For:</strong></p>
<ul>
<li>5+ years of experience in a dedicated Incident Response, SOC, or Security Engineering role, with a proven track record of leading high-severity incident containment in fast-paced environments</li>
<li>Strong familiarity with the MITRE ATT&CK framework, modern adversary tactics, techniques, and procedures (TTPs), and common attack vectors targeting SaaS platforms</li>
<li>Proven experience managing and tuning detection logic within <strong>CrowdStrike Falcon</strong> (or equivalent enterprise EDR/XDR) and enterprise SIEM platforms.</li>
<li style="font-weight: 400;">Excellent leadership skills with the ability to remain calm under pressure, coordinate cross-functional teams (Engineering, Legal, PR), and clearly communicate complex technical risks to stakeholders.</li>
</ul>
755,000+ hidden jobs like this
tripactions and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites