Twitch
Security Incident Response Engineer
About this role
Twitch seeks a Security Incident Response Engineer to join their Security Incident Response Team, handling detection, investigation, and resolution of security incidents across the platform. You'll participate in on-call rotations, analyze threats, automate response processes, and lead post-incident improvements while coordinating with cross-functional teams.
What you'll do
- Participate in on-call rotation to respond to emerging security incidents
- Qualify alerts and reports as security incidents using established guidelines
- Analyze threat actor tactics, techniques, and procedures
- Investigate incidents, evaluate impact, and coordinate response with affected teams
- Build and implement detection, enrichment, and automated response workflows
- Lead lessons learned sessions and drive organizational improvements to reduce incident recurrence
What they're looking for
- Incident response coordination and management
- Security threat analysis and investigation
- Scripting/programming (Python, Go, Shell, Ruby, or Perl)
- AI/ML-driven security automation and playbook design
- Cloud security (AWS, GCP, CloudTrail)
- Incident response frameworks (NIST-800-61, ISO/IEC 27035)
- Host, network, application, and cloud security
- Technical communication and documentation
Benefits
- Medical, Dental, Vision & Disability Insurance
- 401(k) retirement plan
- Maternity & Parental Leave
- Flexible PTO
- Amazon Employee Discount
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Twitch
Twitch builds a platform for streaming and creator communities, offering features around user safety, memberships, and commerce to support millions of concurrent users. The company is hiring Software Engineers across multiple teams to develop scalable systems, moderation tools, and features that enhance experiences for creators and viewers.
- Website
- twitch.tv
Likely interview questions
- Walk us through a complex security incident you investigated—how did you determine impact and coordinate the response?
- Describe your experience building automation for incident response. What tools or languages did you use?