Sr. Security Analyst
Sunnyvale, California
23andMe
23andMe is a saliva-based DNA service. We provide genetic reports on your ancestry, family history and help you connect with your DNA relatives.We are seeking an outstanding information security engineer focused on detection and threat response who wants to challenge themselves, identify threats to the business and help protect 23andMe and customer data.
Who We Are
Since 2006, 23andMe’s mission has been to help people access, understand, and benefit from the human genome. We are a group of passionate individuals pushing the boundaries of what’s possible to help turn genetic insight into better health and personal understanding.
What You'll Do
- Be a key member of the Enterprise Security team
- Engage with the Red Team to actively assess systems, applications, and environments within 23andMe to proactively identify opportunities to improve our security posture.
- Coordinate with IT on vulnerability management and patch cycles to ensure that the company is managing risk appropriately and addressing issues that arise quickly and efficiently.
- Work within the Enterprise Security team and with IT peers to identify threats within the environment through traditional threat hunting techniques. Identify opportunities to improve playbooks, runbooks and create automation. Work collaboratively to speed up response time and to determine the state of the potential threat / alert..
- Assist the security organization to identify automation opportunities and work to implement those integrations and automation improvements within the security tooling.
- Participate in an on-call rotation
- Address multiple technical challenges across multiple security tools
- Actively threat hunt within security tools and determine steps to triage and filter the true events from background noise
- Create and use threat hunting playbooks
- Create and use security operations runbooks to respond to alerts
- Work with vulnerability management platforms to create reporting and then partner with IT to ensure timely patching and remediation of identified vulnerabilities
- Design and implement new security playbooks and automation
- Define, design, and build threat detection methodologies; help to improve the security posture of the company.
- Work among the greater IT and information security teams to build integrations, solve challenging problems, and help to automate our response to targeted threats.
- Lead by example and share your creativity, wit and experience across the team. Enjoy a collaborative environment with small project teams working on a variety of tasks ranging from threat detection within multiple enterprise security tools, assessing threats and providing targeted responses and monitoring the corporate environment for potential risks.
- Participate in incident response activities, as needed
- Leverage multiple security tools daily, including but not limited to: intrusion detection, endpoint detection and response, and SIEM.
- Other duties as assigned
What You'll Bring
- Passion for security!
- Some knowledge and capability with one or more scripting and programming languages (e.g. bash, go, Python, etc.)
- Working knowledge of operating systems (e.g. Windows, MacOS, Linux)
- Some hands-on experience with information security tools
- Understanding of security concepts
- General familiarity with AWS security concepts
- Demonstrated skills around offensive or defensive security technologies
- Ability to communicate well and work with others
- Ability to think critically about challenging problems to determine the most effective method to solve and address
- Familiarity with how attacks are conducted against network infrastructure, web applications and employees
About Us
23andMe, headquartered in Sunnyvale, CA, is a leading consumer genetics and research company. Founded in 2006, the company’s mission is to help people access, understand, and benefit from the human genome. 23andMe has pioneered direct access to genetic information as the only company with multiple FDA authorizations for genetic health risk reports. The company has created the world’s largest crowdsourced platform for genetic research, with 80 percent of its customers electing to participate. The platform also powers the 23andMe Therapeutics group, currently pursuing drug discovery programs rooted in human genetics across a spectrum of disease areas, including oncology, respiratory, and cardiovascular diseases, in addition to other therapeutic areas. More information is available at www.23andMe.com.
At 23andMe, we value a diverse, inclusive workforce and we provide equal employment opportunity for all applicants and employees. All qualified applicants for employment will be considered without regard to an individual’s race, color, sex, gender identity, gender expression, religion, age, national origin or ancestry, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, genetic information, military or veteran status, or any other basis protected by federal, state or local laws. If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at accommodations-ext@23andme.com. 23andMe will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.
Please note: 23andMe does not accept agency resumes and we are not responsible for any fees related to unsolicited resumes. Thank you.
Pay Transparency
23andMe takes a market-based approach to pay, and amounts will vary depending on your geographic location. The salary range reflected here is for a candidate based in the San Francisco Bay Area. The successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.
Tags: Automation AWS Bash EDR Incident response Intrusion detection Linux MacOS Monitoring Python Red team Scripting SIEM Threat detection Vulnerabilities Vulnerability management Windows
Perks/benefits: Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs