Closed
Whatnot is a livestream shopping platform and marketplace backed by Andreessen Horowitz, Y Combinator, and CapitalG. We're building the future of ecommerce, bringing together community, shopping and entertainment. We are committed to our values , and as a remote-first team, we operate out of hubs within the US, Canada, UK, Ireland, and Germany today.
We're innovating in the fast-paced world of live auctions in categories including sports, fashion, video games, and streetwear. The platform couples rigorous seller vetting with a focus on community to create a welcoming space for buyers and sellers to share their passions with others.
And, we're growing. Whatnot has been the fastest growing marketplace in the US over the past two years and we're hiring forward-thinking problem solvers across all functional areas.
- Apply comprehensive knowledge and a thorough understanding of Incident Response concepts, principles, and technical capabilities
- Collaborate across Information Security and business partners to ensure effective, precise, and rapid response
- Act as the point of escalation from within the Incident Response team to drive all cyber incidents
- Identify new detection opportunities, create playbooks, and support new technology implementations to defend against evolving threats
- Maintain awareness and understanding of the current threat landscape. Analyze threat intelligence with the aim to mitigate potential risks
- Report the overall health of the SOC via metrics, OKRs, and risk indicators to leadership
- Provide Incident Response (IR) support when analysis suspects security incidents to help contain and eradicate threats;
- Perform incident triage, incident response, and forensic investigations across endpoints and cloud environments
- Conduct technical examinations of computer-based evidence including logs, packet captures, SIEM & IDS events, disk forensics, malware analysis, and more
- Document incidents from initial detection through final resolution, and present the findings
- Investigate, document, and report on cyber security issues
- Create and continuously improve standard processes, operating procedures, and incident response playbooks
Curious about who thrives at Whatnot? We've found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.
As our nextSOC Engineer you should have a minimum of 5+ years of relevant experience in security, preferably in a large enterprise environment, plus:
- Bachelor's degree in Computer Science, Information Security, a related field, or equivalent work experience.
- 5+ years' experience in cyber incident response, or a similar cyber field, including experience with security principles, and defense-in-depth techniques
- Experience and understanding of security concepts, SOAR(Tines), EDR, NDR and SIEM (Chronicle) technologies
- Experience with multiple Cloud Service Providers (AWS, GCP)
- Excellent written communication skills with the ability to document, communicate, and report security incidents, as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders
- Expected to perform on-call duties
- Flexible Time off Policy and Company-wide Holidays (including a spring and winter break)
- Health Insurance options including Medical, Dental, Vision
- Work From Home Support
- $1,000 home office setup allowance
- $150 monthly allowance for cell phone and internet
- Care benefits
- $450 monthly allowance on food
- $500 monthly allowance for wellness
- $5,000 annual allowance towards Childcare
- $20,000 lifetime benefit for family planning, such as adoption or fertility expenses
- Retirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary ) and Pension plans internationally
- 16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence.
Whatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.
Explore more InfoSec / Cybersecurity career opportunitiesFind even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
#J-18808-Ljbffr