Senior Security Engineer, Detection & Response
Dropbox
Dropbox is a Virtual First company. For this role, we are currently only authorized to hire candidates from the following provinces: Alberta, British Columbia, Ontario, and Saskatchewan.
Company Description
Dropbox is a special place where we are all seeking to fulfill our mission to design a more enlightened way of working. We’re looking for innovative talent to join us on our journey. The words shared by our founders at the start of Dropbox still ring true today. Wouldn’t it be great if our working environment—and the tools we use—were designed with people’s actual needs in mind? Imagine if every minute at work were well spent—if we could focus and spend our time on the things that matter. This is possible, and Dropbox is connecting the dots. The nearly 3,000 Dropboxers around the world have helped make Dropbox a living workspace - the place where people come together and their ideas come to life. Our 700+ million global users have been some of our best salespeople, and they have helped us acquire customers with incredible efficiency. As a result, we reached a billion dollar revenue run rate faster than any software-as-a-service company in history. Dropbox is making the dream of a fulfilling and seamless work life a reality. We hope you’ll join us on the journey.
Team Description
Our Engineering team is working to simplify the way people work together. They’re building a family of products that handle over a billion files a day for people around the world. With our broad mission and massive scale, there are countless opportunities to make an impact.
Role Description
At Dropbox, we believe in simplifying the way people work together. We provide a range of innovative cloud-based solutions to empower individuals and businesses to share, access, and collaborate on their files seamlessly. Security plays a pivotal role in shaping our mission of building a more enlightened way of working where everyone can unleash their creative potential without constraints.
The Detection and Response Team (DART) is looking for a Senior Security Engineer with experience performing detection, incident response, security engineering, and maintaining operationally excellent systems. Are you a seasoned senior level DFIR professional? Have you worked as an incident responder and incident manager commanding large scale, multi-faceted incidents? If you answered “yes” to all these questions you’re our ideal candidate.
Our Engineering Career Framework is viewable by anyone outside the company and describes what’s expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.
Responsibilities
- Develop, apply, and refine detection and incident response playbooks
- Perform on-call duties triaging detection and incident response events
- Analyse and correlate data from disparate sources
- Improve detection workflows with automation and alert enrichments
- Write detection rules to identify threats specific to our environment
- Share knowledge and experience with peer teams and DART engineers
Many teams at Dropbox run Services with on-call rotations, which entails being available for calls during both core and non-core business hours. If a team has an on-call rotation, all engineers on the team are expected to participate in the rotation as part of their employment. Applicants are encouraged to ask for more details of the rotations to which the applicant is applying.
Requirements
- 6+ years experience as a security engineer in related domains
- Direct experience with operational teamwork AND (security incident first responder OR incident manager)
- Experience improving operational teams capabilities/KPIs
- Experience influencing strategy and/or changes across org and partner teams
- Knowledge of operating systems, file systems, or memory on macOS, Linux, Windows, or iOS/Android.
- Practical experience with attacker tactics, techniques and procedures
- Experience and knowledge across multiple security domains, but with expertise in two or more of the following domains: detection engineering, digital forensics, incident response, threat hunting, threat intelligence, threat hunting, or malware analysis.
- Experience performing Live response or digital forensics using disk and memory forensic artefacts on operating systems such as Windows, *nix (macOS, Linux), ChromeOS, Android, iOS etc
- Coding or scripting proficiency in one or more languages
Preferred Qualifications
- 8+ years experience as a security engineer in related domains
- BS (or higher, e.g., MS, or PhD) in Computer Science or related technical field, or equivalent technical experience
- Experience writing and reading Structured Query Language (SQL)
Compensation
The range listed above is the expected annual salary/OTE for this role, subject to change.
Salary/OTE is just one component of Dropbox’s total rewards package. All regular employees are also eligible for the corporate bonus program or a sales incentive (target included in OTE) as well as stock in the form of Restricted Stock Units (RSUs).
Benefits
Dropbox is committed to investing in the holistic health and wellbeing of all Dropboxers and their families. Our benefits and perks programs include, but are not limited to:
- Competitive medical, dental and vision coverage*
- Retirement savings through a defined contribution pension or savings plan**
- Flexible PTO/Paid Time Off policy in addition to statutory holidays, allowing you time to unplug, unwind, and refresh
- Income Protection Plans: Life and disability insurance*
- Business Travel Protection: Travel medical and accident insurance*
- Perks Allowance to be used on what matters most to you, whether that’s wellness, learning and development, food & groceries, and much more
- Parental benefits including: Parental Leave, Fertility Benefits, Adoptions and Surrogacy support, and Lactation support
- Mental health and wellness benefits
Additional benefits details are available upon request.
*Where group plans are not available, allowances may be provided
**Benefit, amount, and type are dependent on geographical location, based upon applicable law or company policy