Overview
As Incident Response Lead at Kong, you will drive the detection, containment and recovery of security incidents in a collaborative, cross-functional environment. You’ll shape incident handling processes and playbooks, enabling a 24/7 capable security operations program. The role emphasizes stakeholder communication, forensics, and continuous improvement to protect customers, partners and employees. You will work closely with engineering and security teams to keep Kong secure and compliant, delivering measurable incident response improvements. This is a chance to impact security at scale within a fast-moving tech company.
Responsabilità
- Develop and document incident handling guides and processes for Kong
- Prioritize and correlate events to reduce false positives and improve threat detection
- Tune security alerts, interpret events, and create new signals from signatures and behaviors
- Respond to security incidents and conduct forensics as needed
- Lead mitigation strategies for identified vulnerabilities and threats
- Design, automate, and maintain alerts, actions, and escalation workflows for 24/7 incident response
- Conduct threat hunting and maintain forward-looking security strategies
- Assist with counter-measures and mitigating controls implementation
- Develop and maintain Incident Response capabilities in public cloud environments
- Prepare incident reports with methodology and results
- Analyze intrusions through event detail reviews and summarize findings
- Partner with stakeholders to improve preparation, identification, analysis, containment, and post-mortem activities
- Develop monthly incident and response metrics dashboards
- Prepare executive summaries and briefings on significant investigations
Requisiti fondamentali
- Crisis management experience to prevent incidents from becoming crises
- Ability to leverage incidents to drive innovation and awareness
- Passion for automation, delegation, and scalable processes
- Experience automating detection, containment, and elimination of threats
- Expertise in security information/event management systems (SIEM) and centralized logging
- Practical cloud experience with Terraform
- Experience with building/deploying solutions (Ansible, Terraform)
- Competency in Linux and Windows
- Ability to automate workflows with Python or JavaScript
- stakeholder management
- clear communication under pressure
- collaboration
- SIEM and centralized logging
- Endpoint protection/detection
- Panther
Senior Incident Response Engineer datore di lavoro: KONG
Kong è un datore di lavoro eccezionale, offrendo un ambiente dinamico e collaborativo dove i talenti possono crescere e prosperare. Con opportunità di mentorship e un forte focus sull'innovazione, i dipendenti sono incoraggiati a guidare l'adozione dell'AI in modo significativo. La cultura aziendale promuove la collaborazione tra team e una gestione attenta delle performance, rendendo Kong un luogo ideale per chi cerca un impatto reale nel settore tecnologico.