Twitch
Security Incident Response Engineer
About this role
Join Twitch's Security Incident Response Team to detect, investigate, and coordinate responses to security incidents across a global live-streaming platform. You'll participate in on-call rotations, analyze threats, automate response workflows, and drive organizational improvements through lessons learned.
What you'll do
- Participate in on-call rotation for security incident response
- Qualify and triage security alerts using established incident criteria
- Investigate threats, analyze attacker tactics and techniques
- Coordinate incident response across affected teams and stakeholders
- Design and implement automation for detection, triage, and response workflows
- Lead post-incident reviews and recommend process improvements
What they're looking for
- Incident response coordination and management
- Scripting or programming (Python, Go, Shell, Ruby, Perl)
- Cloud security (AWS, GCP) and cloud logging analysis
- Security incident frameworks (NIST 800-61, ISO/IEC 27035)
- Threat analysis and attacker tactics/techniques
- Automation and AI/ML playbook design
- Cloud, host, network, and application security
- Security threat landscape knowledge
Benefits
- Medical, Dental, Vision & Disability Insurance
- 401(k) retirement plan
- Maternity & Parental Leave
- Flexible PTO
- Amazon Employee Discount
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Twitch
Twitch builds a platform for streaming and creator communities, offering features around user safety, memberships, and commerce to support millions of concurrent users. The company is hiring Software Engineers across multiple teams to develop scalable systems, moderation tools, and features that enhance experiences for creators and viewers.
- Website
- twitch.tv
Likely interview questions
- Walk us through your experience coordinating a major security incident from detection through resolution—what was your role and what did you learn?
- Tell us about a time you automated a security response or detection workflow—what problem did it solve and what tools did you use?