Circle is looking for a Principal Security Engineer focused on Detection and Response. In this role, you will lead projects and be responsible for key deliverables of the security program while collaborating across Circle teams. You will proactively identify and respond to emerging security threats and command security incidents.
What You'll Do
- Proactively identify and respond to emerging security threats.
- Advance deployment of AI to SOC function.
- Develop plans to manage and maintain core tooling, such as SIEM and Orchestration platforms.
- Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
- Respond to incidents and collaborate across teams to investigate and resolve.
- Develop detection techniques to identify anomalous behaviors and attacks across the environment.
- Provide security guidance to various organizations throughout the company.
- Support broader security team projects such as threat modeling, vulnerability scanning, audits, and custom tool building.
- Take on-call shifts (every 3rd week and occasional weekend).
What We're Looking For
- 10+ years of experience in detection, response, or security engineering.
- 3+ years of experience commanding security incidents, especially those involving engineering.
- Experience working in an AWS + EKS environment.
- Hands-on experience using AI tooling both to accelerate work and to address threats, coupled with a strong understanding of the organizational risks AI introduces and strategies to defend against them.
- Extensive knowledge of SIEM, Case Management, and SOAR solutions.
- Knowledge of operating systems, file systems, and memory on MacOS.
- Programming experience in Python, Golang, or similar programming languages.
- Experience with building Detections As Code.
- Strong ability to work collaboratively across teams during high-stress situations, which sometimes involves after hours work.
- Ability to manage multiple competing priorities and use good judgment to establish order of priorities on the fly.
- Self-motivated and creative problem-solver able to work independently with minimal guidance.
- Experience/familiarity with Slack, Apple MacOS and GSuite.
Nice to Have
- Some exposure to GCP or OCI.
- Professional or hobbyist blockchain exposure.
Technical Stack
- AWS, EKS, SIEM, SOAR
- Python, Golang
- MacOS, GSuite, Slack
Team & Environment
You will be a member of the Circle Security Team, collaborating across Circle teams.
Work Mode
This is a remote position.
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status, or any other protected status required by the laws in the locations where we hire.




