Security Engineer, Incident Response

Company: Twilio
Apply for the Security Engineer, Incident Response
Location:
Job Description:

Overview

In this role you will lead and advance Twilio’s security incident response across its global infrastructure, collaborating with R&D teams to build scalable response processes. You’ll document incidents, create runbooks, and drive improvements to security and reliability. The role emphasizes cross-functional work, mentorship, and automating security workflows to reduce risk. You’ll stay technically sharp in a fast-paced environment and contribute to a growing, globally distributed security program.

Pay / Benefits

  • competitive pay
  • generous time off
  • parental and wellness leave
  • healthcare
  • retirement savings program

Responsibilities

  • Lead and support response to security events and incidents across Twilio’s global infrastructure, services and applications
  • Document incidents and projects; create runbooks and standard operating procedures to share knowledge
  • Collaborate cross-functionally to address threats and challenges across teams
  • Improve security and reliability posture by driving betterments from incidents and events
  • Rapidly acquire new technical skills in a fast-evolving environment
  • Own the security incident lifecycle; participate in on-call rotation and RCAs
  • Build and maintain positive relationships with internal customers to enable impactful solutions
  • Provide mentorship and support for long-term career development and team happiness at scale

Key requirements

  • 3+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, high-fidelity security detections
  • Advanced knowledge of service-oriented architectures and cloud security tools
  • Experience with a broad technology stack tackling difficult security challenges
  • Experience with SIEM platforms and extending their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in AWS, GCP, or other large cloud platforms
  • Excellent written and verbal communication skills
  • Ability to influence and build relationships across all organizational levels
  • strong communication
  • ability to influence and build relationships
  • cross-functional collaboration
  • SIEM platforms and extension
  • SOAR tools and automation
  • AWS or GCP or other cloud platforms

…

Posted: October 1st, 2026