Senior Security Detection & Response Engineer
- Full-time
- Department: Security & Compliance
Company Description
DNAnexus is the leading cloud-based SaaS company serving the global life science community. DNAnexus’ health informatics platform serves customers across a spectrum of industries — government, biopharmaceutical, clinical diagnostics, healthcare, and academic research in 33 countries with compliant protection of data, privacy, and intellectual property. The platform provides a secure and collaborative environment where genomics, multi-omics, and real world data can be combined with clinical data at scale, providing new insights that can lead to improved diagnostics, new targeted therapies and better patient care.
Job Description
Our customers depend on the secure and reliable operation of the DNAnexus platform to run their business. From clinical research to large-scale multi-omics computation, our platform is essential to tackle some of the most exciting opportunities in human health.With DNAnexus, organizations can stay a step ahead in leveraging genomics to achieve their goals. DNAnexus brings it all together on a single scalable platform.
Key Company Highlights:
- Founded in 2009 by leading Stanford genomic scientists, headquartered in Mountain View, CA, 140+ employees.
- Generating significant revenue, global footprint, ramping rapidly; with Enterprise customers including Ancestry, Regeneron, Natera, Johns Hopkins, FDA, Myriad Genetics, St Jude among others.
- FedRAMP Moderate ATO (“Authorized-To-Operate”) platform with current certifications in ISO27001, and HITRUST.
- Engaged on a 5 year, $20M contract with the FDA to power the precisionFDA collaborative omics environment in the cloud.
- Well funded by Tier-1 investors including Foresite Capital, Google Ventures, Perceptive Advisors, Northpond Ventures and TPG Capital, among others.
- Massive, evolving market opportunity that hasn’t been adequately addressed yet.
- Passionate and proven executive leadership team with deep genomics, big data/analytics, and cloud expertise.
The role:
As a key part of the Security team at DNAnexus, the Senior Security Detection & Response Engineer will lead development and implementation of the Collection & Detection approach, manage our technology incident response protocol, and drive improvement of our security posture by leveraging threat data.
The problems you will solve:
- Deliver visibility to the operation of all app and infrastructure components via a singular log & information collection strategy.
- Mature a detection framework to quickly and consistently surface event data in support of rapid & contextual decision making.
- Establish operational baselines for systems via close collaboration with devs and system administrators.
- Leverage detection and threat data to identify defensive security control improvements needed across endpoints, production workloads, and SaaS applications.
- Utilize threat modeling approaches to identify collection, detection, and response capability gaps.
- Implement feedback models to drive system owner behavior to properly instrument systems and prepare rapid threat response capabilities.
- Automate response activities via scripting in a high-level language such as Python, Go, or Ruby. Deploy your automation using AWS Lambda or Azure Functions.
- Influence our security roadmap via close collaboration with security architects and security engineers.
- Mentor incident response team members to continuously mature and refine our capabilities.
Qualifications
The experience you will bring:
- Close familiarity with using public cloud services to provision SaaS/PaaS to external customers
- Strong understanding of modern corporate networks (SD-Wan, service-based remote access, device trust, and endpoint machine identity).
- Proven track record of managing external service providers as part of integrated, high-quality delivery of objectives.
- Design, implementation, and management of high-capacity logging pipelines across cloud & enterprise
- Deployment and system/policy management experience for endpoint (EDR) and public cloud security (CASB) solutions
- A capability & strong desire to build data pipeline and response automation functions in Python, Go, or Ruby.
- Experience investigating and countering modern adversary tactics, techniques, and procedures in an incident response setting.
- 5+ years of work experience in security engineering, incident response, threat intelligence, or cloud infrastructure security.
Personal Attributes and Values:
- You personally enjoy contributing to the security community and driving our industry to do better.
- A self starter that can work independently and collaboratively across multiple workstreams without technical program management support.
- Able to earn the respect of the team on the basis of crisp execution, technical depth, hands-on style, and strategic decision making ability.
- Takes a data centric, objective approach to decision making and has the ability to put aside personal preferences, historical bias, peer pressure and political influences to arrive at decisions on a reasoned, objectively-defensible basis.
- Strong presence; good communicator and highly influential both externally as well as internally at the executive level and across the organization.
- A highly collaborative, team player with a company-first mentality; ability to influence, prioritize, and get alignment cross-functionally.
- Flexible, nimble, and scrappy; startup mentality and willingness/ability to change direction quickly if best for the business.
- A positive, energetic, can-do attitude. High EQ, hungry to succeed, achievement orientation, self-motivation. Highly confident, yet humble and self-aware.
- Entrepreneurial DNA; not afraid to take calculated risks, brings a mentality of rapid innovation and the desire to attain big goals.
- Creative problem solving skills as well as the ability to ignite the creativity of others.
- High integrity, principles, and ethics.
Additional Information
Based in Mountain View, California, DNAnexus is experiencing rapid growth and is searching for the best talent to join our team. We recently completed a $100 million financing round to advance our growth globally to further serve leading healthcare and life science organizations. Key investors include Google Ventures, Perceptive Advisors, Northpond Ventures, TPG Biotech, and Foresite Capital.
If you are interested in joining our team, please apply today!
All your information will be kept confidential according to EEO guidelines.