Senior Incident Responder
DocuSign
- Location
- Sydney, Australia
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 71 approvals (FY2023)
Skills
About this role
Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
What you'll do
We are looking for highly motivated and skilled CSIRT Senior Incident Responders to join our dynamic security team in India or Australia. Reporting directly to the CSIRT Senior Manager, this individual contributor role is crucial for our "Detect & Respond" function. You will be at the forefront of identifying and investigating security incidents, triaging alerts from our Security Operations Center (SOC), and contributing to the continuous improvement of our incident response capabilities. This role requires a strong technical background, the ability to be on-call, excellent analytical skills, and a proactive approach to cybersecurity. This position is an individual contributor role reporting to the Senior Manager of CSIRT.
Responsibility
Leverage AI and machine learning tools to enhance the efficiency of log analysis, alert triage, and threat hunting Monitor for and investigate security incidents involving AI/ML models, such as adversarial attacks, prompt injection, and model evasion Collaborate with detection engineering to develop and tune AI-based detection logic to improve SOC visibility Research and adopt emerging AI-driven security technologies to evolve CSIRT's proactive defense capabilities Perform initial triage and in-depth analysis of security alerts generated from our SIEM and other security monitoring tools Correlate events from various log sources to identify potential security incidents Determine the scope, severity, and potential impact of detected threats Conduct technical investigations into cybersecurity incidents, including malware analysis, phishing attacks, web application compromises, and insider threats Utilize digital forensics techniques on data and endpoints to gather evidence and understand incident timelines and methods Support incident containment, eradication, and recovery efforts under the guidance of the CSIRT Manager Document incident findings, actions taken, and lessons learned Participate in proactive threat hunting activities to uncover hidden threats within the enterprise environment Stay informed about the latest threat intelligence and emerging attack techniques Work with SIEM and SOAR platforms to optimize alert processing and incident workflows Identify opportunities for automation to streamline security operations Collaborate effectively with other security teams, IT, and business units during incident response Provide clear and concise updates on incident status to the CSIRT Manager including post-incident reports and analysis Job Designation Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation) Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic 8+ years of hands-on experience in cybersecurity, with a focus on Security Operations (SOC) and/or Incident Response Solid understanding of cybersecurity principles, incident response lifecycles, and security