Job description
About the role
Security Incident Response Analyst - DARTWe’re looking for a curious and detail-oriented Incident Response, Senior Analyst to harness your expertise in data analytics, infrastructure, application security, and identity management. You'll analyze security alerts and respond to a wide range of incidents, including workforce security, where your efforts will be crucial in preserving the trust our merchants place in Shopify. As the incident commander, you'll own issues from start to finish, persistently bringing all the pieces together and leaving no stone unturned. This role has a significant investigative component, offering daily opportunities to apply your analytical skills and experience navigating vast amounts of data to find that needle in the haystack that will be the key to resolving the security issue, working in close partnership with our Legal team.Key Responsibilities:Analyze and respond to security alerts, focusing on workforce security to reduce risks.Serve as an Incident Commander, leading response efforts and collaborating across Shopify.Partner daily with Legal on sensitive investigations, evidence gathering, and mitigation strategies.Implement new alerts to enhance detection capabilities.Collaborate with security, engineering, HR, and Legal teams to remediate findings and address risks.Lead root cause analysis sessions to prevent recurrence of incidents.Participate in defining security table-top exercises focused on workforce security.Refine and build knowledge base documentation for clarity among technical and legal stakeholders.Identify trends in the security landscape and recommend improvements.Qualifications:Understanding of information security fundamentals, including threat models and detection techniques.Knowledge of security issues affecting web applications, infrastructure, and internal systems.Comfort with running and debugging scripts (e.g., Python, Ruby, bash) to automate work.Experience with logging and data analysis tools (e.g., SIEM, SOAR, SQL, Splunk, KQL).Familiarity with UEBA tools and IAM systems (e.g., Okta, Microsoft Entra).Knowledge of cloud environments and security logs (e.g., GCP, AWS, Azure).Excellent communication skills for distilling technical data into actionable intelligence.Experience in troubleshooting complex problems with minimal information.Proficiency in researching and using data analysis to identify security threats.Nice to HaveExperience in digital forensics or workforce security investigations is a strong asset.Proficiency in generating code/scripts for automationExperience handling sensitive investigations such as employment or legal mattersEastern timezone preferredComfort using AI/LLM tools for efficient task completion.Awareness of GitHub and continuous integration practices.Security Incident Response Analyst - DARTWe’re looking for a curious and detail-oriented Incident Response, Senior Analyst to harness your expertise in data analytics, infrastructure, application security, and identity management. You'll analyze security alerts and respond to a wide range of incidents, including workforce security, where your efforts will be crucial in preserving the trust our merchants place in Shopify. As the incident commander, you'll own issues from start to finish, persistently bringing all the pieces together and leaving no stone unturned. This role has a significant investigative component, offering daily opportunities to apply your analytical skills and experience navigating vast amounts of data to find that needle in the haystack that will be the key to resolving the security issue, working in close partnership with our Legal team.Key Responsibilities:Analyze and respond to security alerts, focusing on workforce security to reduce risks.Serve as an Incident Commander, leading response efforts and collaborating across Shopify.Partner daily with Legal on sensitive investigations, evidence gathering, and mitigation strategies.Implement new alerts to enhance detection capabilities.Collaborate with security, engineering, HR, and Legal teams to remediate findings and address risks.Lead root cause analysis sessions to prevent recurrence of incidents.Participate in defining security table-top exercises focused on workforce security.Refine and build knowledge base documentation for clarity among technical and legal stakeholders.Identify trends in the security landscape and recommend improvements.Qualifications:Understanding of information security fundamentals, including threat models and detection techniques.Knowledge of security issues affecting web applications, infrastructure, and internal systems.Comfort with running and debugging scripts (e.g., Python, Ruby, bash) to automate work.Experience with logging and data analysis tools (e.g., SIEM, SOAR, SQL, Splunk, KQL).Familiarity with UEBA tools and IAM systems (e.g., Okta, Microsoft Entra).Knowledge of cloud environments and security logs (e.g., GCP, AWS, Azure).Excellent communication skills for distilling technical data into actionable intelligence.Experience in troubleshooting complex problems with minimal information.Proficiency in researching and using data analysis to identify security threats.Nice to HaveExperience in digital forensics or workforce security investigations is a strong asset.Proficiency in generating code/scripts for automationExperience handling sensitive investigations such as employment or legal mattersEastern timezone preferredComfort using AI/LLM tools for efficient task completion.Awareness of GitHub and continuous integration practices.Security Incident Response Analyst - DART
Security Incident Response Analyst - DARTWe’re looking for a curious and detail-oriented Incident Response, Senior Analyst to harness your expertise in data analytics, infrastructure, application security, and identity management. You'll analyze security alerts and respond to a wide range of incidents, including workforce security, where your efforts will be crucial in preserving the trust our merchants place in Shopify. As the incident commander, you'll own issues from start to finish, persistently bringing all the pieces together and leaving no stone unturned. This role has a significant investigative component, offering daily opportunities to apply your analytical skills and experience navigating vast amounts of data to find that needle in the haystack that will be the key to resolving the security issue, working in close partnership with our Legal team.
Key Responsibilities:
Key Responsibilities:- Analyze and respond to security alerts, focusing on workforce security to reduce risks.
Analyze and respond to security alerts, focusing on workforce security to reduce risks.
- Serve as an Incident Commander, leading response efforts and collaborating across Shopify.
Serve as an Incident Commander, leading response efforts and collaborating across Shopify.
- Partner daily with Legal on sensitive investigations, evidence gathering, and mitigation strategies.
Partner daily with Legal on sensitive investigations, evidence gathering, and mitigation strategies.
- Implement new alerts to enhance detection capabilities.
Implement new alerts to enhance detection capabilities.
- Collaborate with security, engineering, HR, and Legal teams to remediate findings and address risks.
Collaborate with security, engineering, HR, and Legal teams to remediate findings and address risks.
- Lead root cause analysis sessions to prevent recurrence of incidents.
Lead root cause analysis sessions to prevent recurrence of incidents.
- Participate in defining security table-top exercises focused on workforce security.
Participate in defining security table-top exercises focused on workforce security.
- Refine and build knowledge base documentation for clarity among technical and legal stakeholders.
Refine and build knowledge base documentation for clarity among technical and legal stakeholders.
- Identify trends in the security landscape and recommend improvements.
Identify trends in the security landscape and recommend improvements.
Qualifications:
Qualifications:- Understanding of information security fundamentals, including threat models and detection techniques.
Understanding of information security fundamentals, including threat models and detection techniques.
- Knowledge of security issues affecting web applications, infrastructure, and internal systems.
Knowledge of security issues affecting web applications, infrastructure, and internal systems.
- Comfort with running and debugging scripts (e.g., Python, Ruby, bash) to automate work.
Comfort with running and debugging scripts (e.g., Python, Ruby, bash) to automate work.
- Experience with logging and data analysis tools (e.g., SIEM, SOAR, SQL, Splunk, KQL).
Experience with logging and data analysis tools (e.g., SIEM, SOAR, SQL, Splunk, KQL).
- Familiarity with UEBA tools and IAM systems (e.g., Okta, Microsoft Entra).
Familiarity with UEBA tools and IAM systems (e.g., Okta, Microsoft Entra).
- Knowledge of cloud environments and security logs (e.g., GCP, AWS, Azure).
Knowledge of cloud environments and security logs (e.g., GCP, AWS, Azure).
- Excellent communication skills for distilling technical data into actionable intelligence.
Excellent communication skills for distilling technical data into actionable intelligence.
- Experience in troubleshooting complex problems with minimal information.
Experience in troubleshooting complex problems with minimal information.
- Proficiency in researching and using data analysis to identify security threats.
Proficiency in researching and using data analysis to identify security threats.
Nice to Have
Nice to Have- Experience in digital forensics or workforce security investigations is a strong asset.
Experience in digital forensics or workforce security investigations is a strong asset.
- Proficiency in generating code/scripts for automation
Proficiency in generating code/scripts for automation
- Experience handling sensitive investigations such as employment or legal matters
Experience handling sensitive investigations such as employment or legal matters
- Eastern timezone preferred
Eastern timezone preferred
- Comfort using AI/LLM tools for efficient task completion.
Comfort using AI/LLM tools for efficient task completion.
- Awareness of GitHub and continuous integration practices.
Awareness of GitHub and continuous integration practices.