Senior Security Engineer, Detection & Response
Block (Square) · Bay Area, CA, United States of America
About this role
**Block — Senior Security Engineer, Detection & Response** **About the role** Block’s Detection and Response Team (DART) investigates and responds to threats across our products and systems. Within DART, the Computer Security Incident Response Team (CSIRT) leads complex investigations and coordinates company-wide response to security incidents. You’ll determine what happened, assess scope and impact, guide containment and recovery, and keep responders and stakeholders aligned. **What you’ll do** - Command complex, high-impact security incidents from initial assessment through containment, recovery, and closure. - Investigate threats across endpoint, identity, cloud, SaaS, network, and application systems; drive containment and remediation with system owners while balancing urgency, evidence preservation, and business impact. - Reconstruct timelines, preserve evidence, and determine incident scope and impact. - Coordinate containment and remediation with system owners while balancing urgency and business impact. - Keep incident priorities, decisions, owners, and handoffs clear across teams and time zones. - Lead post-incident reviews and drive findings, uncertainty, and response decisions to technical teams and business partners. - Write code, queries, and automation to accelerate evidence collection, analysis, and response; partner with triage, detection, threat intelligence, and infrastructure teams to address missing telemetry, improve detections, and reduce recurring manual work. - Lead post-incident reviews and drive improvements to completion. - Mentor responders and participate in the incident response on-call rotation. **What you bring** - Experience commanding major security incidents involving multiple teams and competing priorities. - Deep hands-on incident response and digital forensics experience. - Strong knowledge of attacker behavior and depth across identity, endpoint, cloud, network, or application security. - Strong SQL/database understanding and log-analysis skills, plus practical programming/scripting ability (e.g., Python). You can analyze large, messy datasets and build reliable tools that improve investigations and response (with or without AI). - An established AI-assisted workflow and active development of AI-based systems/processes to improve incident coordination and case management. - Clear communication and sound judgment when working with technical teams, executives, and sensitive information. - An engineering mindset and a track record of turning incident response lessons into lasting improvements. - A need to build: developing systems and workflows that improve incident response and connect with broader investigation, automation, and case management capabilities. **Equal opportunity** Block is an equal opportunity employer and evaluates applicants without regard to identity or any legally protected class. Reasonable accommodations are available throughout the recruitment process. **Application notes** - No specific application deadline is listed; U.S. roles are typically open for an average of 55 days. - Candidates may submit up to 9 active applications within a 60-day period; reapplications to the same role are accepted 90 days after a previous application has been reviewed. - Block may use automated AI tools to evaluate job applications for efficiency and consistency, in compliance with local regulations. *Want to learn more?* Check out Block’s inclusion page: https://block.xyz/news/inclusion
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.