yandex
roku
Страна
США
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Security Engineer

Оценка ИИ

Roku — лидер рынка с сильной инженерной культурой и интересными задачами мирового масштаба. Гибридный график и фокус на профессиональном росте делают вакансию очень привлекательной, несмотря на отсутствие указанной зарплаты.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубоких знаний в области SIEM/SOAR, реагирования на инциденты и облачной безопасности (AWS). Высокая планка ответственности за глобальную инфраструктуру и необходимость наставничества делают позицию сложной, но интересной для опытных специалистов.

Анализ зарплаты

Медиана150 000 $
Рынок125 000 $ – 185 000 $
Оценка ИИ

Зарплата в объявлении не указана, но для позиции Security Engineer в Остине, Техас, рыночные показатели обычно находятся в диапазоне $130,000 - $170,000 в год в зависимости от опыта. Roku как публичная технологическая компания обычно предлагает конкурентоспособные пакеты, включающие опционы (RSU).

Сопроводительное письмо

I am writing to express my strong interest in the Security Engineer position at Roku. With a solid background in managing SIEM/SOAR platforms and a deep understanding of threat intelligence and incident response, I am eager to contribute to the Trust Engineering team's mission of protecting Roku’s global infrastructure and diverse user base. My experience in automating security playbooks and conducting proactive threat hunting aligns perfectly with your goal of maintaining a robust security posture in a fast-paced, innovative environment.

Throughout my career, I have successfully led incident response efforts and managed vulnerability lifecycles, ensuring that security controls are both effective and aligned with business needs. I am particularly drawn to Roku’s collaborative culture and the opportunity to mentor junior analysts while tackling complex security challenges. I am confident that my technical expertise in AWS security services and my commitment to industry best practices like NIST and ISO 27001 will make me a valuable asset to your team.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в roku уже сейчас

Присоединяйтесь к команде Roku и защищайте стриминговую платформу №1, создавая будущее телевидения вместе с экспертами индустрии!

Описание вакансии

Teamwork makes the stream work.

Roku is changing how the world watches TV

Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers.

From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines.

About the Team

The Roku trust engineering team is a close-knit group of professionals passionate about information security. Our mission is to protect our customers, partners, devices, services, infrastructure, and data. We work collaboratively, sharing insights and expertise to stay ahead of the curve. Join us, and you’ll be part of a dynamic team that thrives on challenges and celebrates victories together.

About the Role

As a Security Engineer on the Trust engineering team, you will support the design, implementation, and management of Roku’s end-to-end security systems and controls that impact a global user base. Key responsibilities will include supporting the development of security controls, managing and maintaining SIEM/SOAR tooling and threat intelligence platforms, conducting technical incident response, managing vulnerability and risk assessments, and mentoring more junior analysts. You will collaborate with teams within Trust engineering and across the wider organization to support, develop, and influence strong security practices and postures.

What you will be doing

  • Trust Information Security Operations, supporting the design and implementation of information security systems  and frameworks, including threat prevention, detection and mitigation tools
  • Manage, maintain and optimize security information and event management (SIEM) platforms and associated security infrastructure
  • Detect and respond to information security incidents, investigate security incidents, identify attack vectors, and lead containment/eradication/recovery efforts
  • Create detailed incident reports, lead post-incident reviews, document lessons learned, and contribute to compliance reporting
  • Threat Hunting & Proactive Measures: Hunt for undetected threats, tune security tools, refine detection rules, and address false positives
  • Vulnerability management, analysis, oversee the vulnerability management lifecycle and reporting, support prioritization and advise relevant stakeholders on vulnerability status and postures
  • Security controls, identify risks in new and existing projects and environments and support the implementation of necessary security controls to meet business needs
  • Support the implementation of security orchestration, automation and response (SOAR) playbooks and procedures in order to improve response times and ensure a consistent approach to incidents
  • Provide mentorship and support to more junior analysts, and act as an escalation point for complex issues
  • Support in testing and evaluation of security products and solutions
  • Support the development and management of the security operations centre (SOC) function as it is built up and developed into the future
  • Raise awareness of security policies and best practices across the organization. And continue to contribute to the ongoing development of best practices, procedures and security training across the organization

We are excited if you have

  • Strong understanding of SIEM, EDR, cloud security services (e.g., AWS GuardDuty), and various security technologies
  • Experience in automation and development of automated playbooks and associated processes in security orchestration, automation and response (SOAR) environments
  • Experience in the creation of incident response plans and leading incident response efforts, and post-incident reporting when required
  • Threat intelligence, knowledge of  tactics, techniques, and procedures (TTPs) utilized by threat actors and how to generate and deploy mitigation strategies
  • Vulnerability management, monitoring, reporting and engagement with necessary stakeholders to ensure timely remediation
  • Can demonstrate a strong understanding of network security principles and encryption technologies
  • Experience with security change management processes and procedures
  • Demonstrate experience of risk assessment and advisory capabilities on both internal systems and products/solutions from third-party vendors (SaaS, AI, etc)
  • Experience in contributing to the development, implementation and management of security policies and procedures
  • Strong knowledge of security frameworks and industry best practices – such as ISO 270001, NIST, PCI-DSS and others
  • Strong analytical and problem-solving capabilities
  • Demonstrate experience of effective communication and collaborative skills to work across diverse cross-functional teams, including development, IT, Legal, Governance and Risk, etc.
  • Demonstrate experience in mentoring and the development of more junior staff members with an engineering and SOC environment
#LI-DH2

Our Hybrid Work Approach

Roku fosters an inclusive and collaborative environment where teams work in the office Monday through Thursday. Fridays are flexible for remote work except for employees whose roles are required to be in the office five days a week or employees who are in offices with a five day in office policy.

Benefits

Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families. Our comprehensive benefits include global access to mental health and financial wellness support and resources. Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension). Our employees can take time off work for vacation and other personal reasons to balance their evolving work and life needs. It's important to note that not every benefit is available in all locations or for every role. For details specific to your location, please consult with your recruiter.

Accommodations

Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to EmployeeRelations@Roku.com.

The Roku Culture

Roku is a great place for people who want to work in a fast-paced environment where everyone is focused on the company's success rather than their own. We try to surround ourselves with people who are great at their jobs, who are easy to work with, and who keep their egos in check. We appreciate a sense of humor. We believe a fewer number of very talented folks can do more for less cost than a larger number of less talented teams. We're independent thinkers with big ideas who act boldly, move fast and accomplish extraordinary things through collaboration and trust. In short, at Roku you'll be part of a company that's changing how the world watches TV.

We have a unique culture that we are proud of. We think of ourselves primarily as problem-solvers, which itself is a two-part idea. We come up with the solution, but the solution isn't real until it is built and delivered to the customer. That penchant for action gives us a pragmatic approach to innovation, one that has served us well since 2002.

To learn more about Roku, our global footprint, and how we've grown, visit https://www.weareroku.com/factsheet.

By providing your information, you acknowledge that you want Roku to contact you about job roles, that you have read Roku's Applicant Privacy Notice, and understand that Roku will use your information as described in that notice. If you do not wish to receive any communications from Roku regarding this role or similar roles in the future, you may unsubscribe at any time by emailing WorkforcePrivacy@Roku.com.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • SIEM
  • SOAR
  • EDR
  • AWS GuardDuty
  • Incident Response
  • Vulnerability Management
  • Threat Hunting
  • Threat Intelligence
  • ISO 27001
  • NIST
  • PCI DSS
  • Network Security
  • Encryption

Возможные вопросы на собеседовании

Проверка практического опыта работы с инструментами автоматизации, упомянутыми в вакансии.

Расскажите о самом сложном сценарии (playbook) в SOAR, который вы разработали. Какую проблему он решил?

Вакансия предполагает работу с глобальной инфраструктурой Roku.

Как вы подходите к приоритизации уязвимостей в крупномасштабной облачной среде, такой как AWS?

Оценка навыков реагирования на критические ситуации.

Опишите ваш процесс расследования инцидента от момента обнаружения аномалии в SIEM до этапа извлечения уроков (lessons learned).

Проверка знаний современных угроз и методов их предотвращения.

Какие TTP (тактики, техники и процедуры) современных APT-группировок вы считаете наиболее опасными для стриминговых платформ и как им противостоять?

В описании указано наставничество как одна из ключевых обязанностей.

Как вы подходите к обучению младших аналитиков в SOC и какие метрики используете для оценки их прогресса?

Похожие вакансии

alarmcom
Не указана

Principal Network Security Engineer

ГибридСША
Cisco · Firewalls · Cisco ISE · VPN · WAF · AWS · Azure · Google Cloud Platform · DDoS Mitigation · Vulnerability Management · Python · Ansible · CCNP Security · CISSP · Network Security
+15 навыков
gleanwork
Не указана

Security Engineer, Cloud Security

УдалённоСША
AWS · Azure · Python · Go · Java · IAM · OAuth · OpenID Connect · Network Security · Cryptography · Cloud Security
+11 навыков
gleanwork
185 000 $ – 280 000 $

Security Engineer, Application Security

ГибридСША
Go · Python · Java · C++ · Snyk · GitHub Dependabot · Trivy · Clair · Burp Suite · OWASP ZAP · AWS · GCP · Azure · Kubernetes · Docker · CI/CD · SAST · DAST · Vulnerability Management
+19 навыков
accenturefederalservices
106 300 $ – 221 100 $

LMP IGA Developer_SCON

В офисеСША
Java · SailPoint IdentityIQ · Saviynt · REST API · IAM · IGA · RBAC · Agile · ServiceNow · SAP GRC
+10 навыков
accenturefederalservices
84 900 $ – 160 200 $

Privilege Access Management (PAM) Engineer

В офисеСША
CyberArk · Privileged Access Management · Identity and Access Management · API Integration · Security · BeyondTrust · Centrify · ManageEngine PAM360 · Scripting · Cybersecurity
+10 навыков
9thwayinsignia
Не указана

Future Opportunities: Cybersecurity

УдалённоСША
Cybersecurity · NIST Standards · Cloud Security · Machine Learning · Data Analytics · Process Automation · Security Engineering · Assessment & Authorization (A&A) · Incident Mitigation · Enterprise Architecture
+10 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

roku
Страна
США