Senior Security Engineer (Threat Detection and Response)
Gurgaon, India
Gemini
Gemini makes crypto simple. Find, Trade and Buy over 80 coins including bitcoin on the best cryptocurrency platform. Start trading crypto here.About the Company
Gemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.
Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we help you buy, sell, and store your bitcoin and cryptocurrency.
At Gemini, our mission is to unlock the next era of financial, creative, and personal freedom.
In India, we have a hybrid work policy. Employees are expected to work from the office in Gurgaon part of the week. We believe our hybrid approach increases productivity through more in-person collaboration where possible.
The Department: Information Security
In the emerging industry of digital assets, there is nothing more important than trust (which is why Gemini’s very first hires were Security experts). The Gemini Security team forms the backbone of all that we do and is as diverse as the number of challenges we tackle in the crypto space.
From security architecture and engineering to maintenance of cold storage systems and data centers to cybersecurity and litigation support, our team ensures that our customers, clients, and employees are safe, secure, and supported.
The Role: Senior Security Engineer (Threat Detection and Response)
Gemini is looking for a Senior Security Engineer, Threat Detection and Response to join our growing information security team as a founding member of our new India location.
In this role, you will be part of the team responsible for designing, building, and automating detection, response and intelligence gathering solutions, developing unique and creative detection mechanisms, monitoring security events, and leading responses to any security incidents.
Responsibilities:
- Own individual security solutions throughout their lifecycle, including design, development, and deployment, in order to continuously improve Gemini’s ability to detect and respond to advanced, targeted threats
- Develop and improve processes and tools that supports the team rapidly iterating and responding to threats Gemini faces
- Engage in incident response and investigation efforts
- Analyze technical threat data to extract TTPs, malware techniques, and adversary methods
- Create and enhance countermeasures and detections for malware, attacker techniques, threat actor methodology, and suspicious events associated with intelligence obtained by the Gemini Team
- Produce well documented, resilient and manageable code that supports the streamlining and automation of the above
- Provide mentorship and guidance to junior engineers on the team in their growth and implementation of the above
Minimum Qualifications:
- Significant DFIR/Threat Detection and Response experience
- Scripting proficiency in a common programming language (e.g. Python, Go)
- Hands-on familiarity with CI/CD, infrastructure as code, and microservices
- Aptitude in the use of containerization technologies (eg. Docker)
- Experience in the design and implementation of detection signatures spanning multiple security log sources (Splunk, EDR, etc.)
- Able to troubleshoot and debug issues, and demonstrate a methodical approach to root cause analysis
- Excellent oral and written communication skills, including the ability to interact effectively with leadership, engineers, vendors and peers
Preferred Qualifications:
- Familiarity in the use of container orchestration systems (e.g. Kubernetes)
- Experience applying CI/CD concepts to the development and deployment of security detection mechanisms and tools
- Understanding of ETL and Workflow engines (e.g. Argo Workflows, Airflow)
- Experience in host and memory forensics (including live response) for Windows, OSX, and / or Linux
- Experience with the analysis of new log and data sources and methodically incorporating them into a detection pipeline
- Practical experience applying analysis frameworks (e.g Kill Chain, ATT&CK, etc)
- Experience in automating any of the above using existing APIs and tools
- Competitive base salary
- Benefits
- Discretionary annual bonus
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Automation CI/CD Crypto DFIR Docker EDR Forensics Incident response Kubernetes Linux Malware Microservices Monitoring Python Scripting Splunk Threat detection TTPs Windows
Perks/benefits: Career development Competitive pay Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Product Security Engineer jobs
- Open Security Operations Engineer jobs
- Open Cloud Security Architect jobs
- Open Principal Security Engineer jobs
- Open Information Security Officer jobs
- Open Senior Cyber Security Engineer jobs
- Open Information Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open IT Security Engineer jobs
- Open Senior Product Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Penetration Tester jobs
- Open Cyber Security Specialist jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Security Specialist jobs
- Open Senior Network Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Security Consultant jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Security Operations Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Architect jobs
- Open Agile-related jobs
- Open Risk assessment-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open SOC-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open GCP-related jobs
- Open IAM-related jobs
- Open Application security-related jobs
- Open Threat intelligence-related jobs
- Open DoD-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open CEH-related jobs
- Open APIs-related jobs
- Open SaaS-related jobs
- Open Malware-related jobs
- Open Security assessment-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Java-related jobs
- Open TS/SCI-related jobs