CronJobs

security jobs

Senior Security Engineer, Detection & Response

Block (Square) · Bay Area, CA, United States of America

remotesenior$217,800–$217,800Posted Oct 2, 2026PythonSQLdigital forensicsincident responselog analysisautomation

Apply on the employer site

About this role

**Block — Senior Security Engineer, Detection & Response** **About the role** Block’s Detection and Response Team (DART) investigates and responds to threats across our products and systems. Within DART, the Computer Security Incident Response Team (CSIRT) leads complex investigations and coordinates company-wide response to security incidents. You’ll determine what happened, assess scope and impact, guide containment and recovery, and keep responders and stakeholders aligned. **What you’ll do** - Command complex, high-impact security incidents from initial assessment through containment, recovery, and closure. - Investigate threats across endpoint, identity, cloud, SaaS, network, and application systems; drive containment and remediation with system owners while balancing urgency, evidence preservation, and business impact. - Reconstruct timelines, preserve evidence, and determine incident scope and impact. - Coordinate containment and remediation with system owners while balancing urgency and business impact. - Keep incident priorities, decisions, owners, and handoffs clear across teams and time zones. - Lead post-incident reviews and drive findings, uncertainty, and response decisions to technical teams and business partners. - Write code, queries, and automation to accelerate evidence collection, analysis, and response; partner with triage, detection, threat intelligence, and infrastructure teams to address missing telemetry, improve detections, and reduce recurring manual work. - Lead post-incident reviews and drive improvements to completion. - Mentor responders and participate in the incident response on-call rotation. **What you bring** - Experience commanding major security incidents involving multiple teams and competing priorities. - Deep hands-on incident response and digital forensics experience. - Strong knowledge of attacker behavior and depth across identity, endpoint, cloud, network, or application security. - Strong SQL/database understanding and log-analysis skills, plus practical programming/scripting ability (e.g., Python). You can analyze large, messy datasets and build reliable tools that improve investigations and response (with or without AI). - An established AI-assisted workflow and active development of AI-based systems/processes to improve incident coordination and case management. - Clear communication and sound judgment when working with technical teams, executives, and sensitive information. - An engineering mindset and a track record of turning incident response lessons into lasting improvements. - A need to build: developing systems and workflows that improve incident response and connect with broader investigation, automation, and case management capabilities. **Equal opportunity** Block is an equal opportunity employer and evaluates applicants without regard to identity or any legally protected class. Reasonable accommodations are available throughout the recruitment process. **Application notes** - No specific application deadline is listed; U.S. roles are typically open for an average of 55 days. - Candidates may submit up to 9 active applications within a 60-day period; reapplications to the same role are accepted 90 days after a previous application has been reviewed. - Block may use automated AI tools to evaluate job applications for efficiency and consistency, in compliance with local regulations. *Want to learn more?* Check out Block’s inclusion page: https://block.xyz/news/inclusion

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord