chainlink-labs
New

Security Response Engineer, Incident Response

SydneyRemotefull-timemid
OtherEngineer
0 views0 saves0 applied

Quick Summary

Overview

About ChainlinkChainlink is the industry-standard oracle platform bringing the capital markets onchain and powering the majority of decentralized finance (DeFi).

Key Responsibilities

Own and improve the incident response lifecycle: act as incident commander for high-severity incidents Join the team's on-call rotation: triage inbound alerts/escalations, coordinate internal and company-wide incidents Improve response readiness:…

Requirements Summary

Proven incident response leadership: experience as the primary incident commander for high‑severity security incidents involving multiple teams and external stakeholders, and can independently manage incident timelines, decisions, and communications…

Technical Tools
pythonrust

About the Role

~1 min read

As a Security Response Engineer, you’ll own the full security incident response lifecycle. You’ll serve as incident commander – owning the high-level coordination of incidents from scoping through to recovery and post-mortem improvements. We’re looking for a seasoned individual contributor who is comfortable operating across diverse environments. In addition to response efforts, you’ll be heavily involved with the team’s operational responsibilities (creating and refining detections, playbooks, and processes) and project work (automating response actions, improving visibility through creation and deployment of new tooling). You would help continuously improve our response capabilities and efficiency by collaborating with internal and external stakeholders across the company.

  • Own and improve the incident response lifecycle: act as incident commander for high-severity incidents

  • Join the team's on-call rotation: triage inbound alerts/escalations, coordinate internal and company-wide incidents

  • Improve response readiness: create and automate playbooks, conduct tabletop exercises

  • Address security telemetry gaps: improve existing or build/deploy new tools

  • Increase detection quality: write and tune high-signal detections (in Sigma)

  • Proactively identify and implement areas of improvement and modernization

Requirements

~1 min read
  • Proven incident response leadership: experience as the primary incident commander for high‑severity security incidents involving multiple teams and external stakeholders, and can independently manage incident timelines, decisions, and communications

  • Operational rigor and investigation depth: demonstrated experience with triage, scoping, containment, and remediation across endpoint, cloud, and/or network based incidents; drives root‑cause analysis and post‑incident action items to completion.

  • Experience in macOS-heavy environments: has secured and operated a predominantly macOS endpoint fleet: deploying / managing endpoint controls, telemetry collection, and performing investigations on macOS systems.

  • Collaborative, straightforward communicator: writes clear incident updates and summaries; can explain risk, impact, and trade‑offs to both technical and non‑technical stakeholders; builds trust with partner teams during high‑pressure situations; comfortable handling the regular communication cadence of an incident

  • Detections experience: ability to create and refine detections based on investigations and threat intelligence

  • Previous coding experience (Python, Go, Rust, or similar): scripting for data parsing/enrichment and simple automations

Requirements

~1 min read
  • Prior success in remote-first environments.

  • Experience with detections‑as‑code (Sigma) development and workflows.

  • Domain experience with blockchain/Web3 threats.

  • Open-source contributions to security related projects.

All roles with Chainlink Labs are global and remote-based. Unless otherwise stated, we ask that you try to overlap some working hours with Eastern Standard Time (EST).

We carefully review all applications and aim to provide a response to every candidate within two weeks after the job posting closes. The closing date is listed on the job advert, so we encourage you to take the time to thoughtfully prepare your application. We want to fully consider your experience and skills, and you will hear from us regarding the status of your application shortly after the closing date.

Chainlink Labs is an equal opportunity employer. All qualified applicants will receive equal consideration for employment in compliance with applicable laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us via this form.

Information collected and processed as part of your Chainlink Labs Careers profile, and any job applications you choose to submit, is subject to our Recruiting Privacy Policy. By submitting your application, you are agreeing to our use and processing of your data as required.

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location

Listing Details

Posted
December 29, 2025
First seen
May 6, 2026
Last seen
May 8, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
23%
Scored at
May 6, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

chainlink-labsSecurity Response Engineer, Incident Response