Role overview

Sr. Security Operations Engineer, Incident Response

Requirements and responsibilities

Readable role content extracted into sections for faster review.

Details

  • Lead security incidents end-to-end, from detection and triage through containment, remediation, and post-incident review.
  • Act as incident commander, driving clear decisions and alignment across teams during high-pressure situations.
  • Conduct hands-on investigations across cloud and endpoint environments to determine root cause and impact.
  • Partner with Observability & Automation to improve detections, reduce noise, and build automated response playbooks.
  • Contribute to and refine incident response playbooks, runbooks, and documentation to improve readiness and consistency.
  • Collaborate with Security, Infrastructure, and Product teams to identify gaps and strengthen the incident response lifecycle.
  • Communicate effectively during incidents, providing clear updates to both technical and non-technical stakeholders.
  • 5+ years of experience in Security Operations or Detection & Response, with strong hands-on incident response in cloud environments (AWS and EKS experience strongly preferred).
  • Proven ability to lead security incidents, including containment and remediation, in fast-moving environments.
  • Strong investigative and analytical skills, with the ability to synthesize signals from multiple data sources.
  • Experience with security tooling such as SIEM and EDR platforms (e.g., Splunk, Elastic, SentinelOne, CrowdStrike, or similar).
  • Solid understanding of cloud security concepts and their application in real-world scenarios.
  • Strong communication skills, with the ability to clearly convey information across technical and non-technical audiences.
  • Experience building or improving automation for incident response workflows (e.g., scripting in Python; infrastructure-as-code is a plus).
  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
Similar roles

Keep a backup shortlist.

Browse stack
FocusInformation SecurityRole area
Seniority signalSeniorCandidate level
StackAWS, Python, RESTPrimary skills
Location1 accepted countryEligibility

Stack

Use these tags to compare similar remote roles.

Location eligibility

Candidates should apply only when their profile country is listed here.

Your profileCountry not setSign in to check your country against this role.

Hiring flow

WithMira shows the role, then sends candidates to the company application.

1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.
Apply on company siteCompany siteOpen link