Security Operations Engineer
23andme 23
Job description
23andMe Research Institute is looking for an experienced Security Operations Engineer to join our Security Operations team. In this role you will lead security incident response as Incident Commander, triage and investigate alerts, and build the detection and automation architecture to help protect our customer and corporate data. You will bring critical thinking skills, hands-on experience, and the ability to work with and influence cross-functional teams.
Who we are
Since 2006, 23andMe Research Institute’s mission has been to help people access, understand, and benefit from the human genome. We are a group of passionate individuals pushing the boundaries of what’s possible to help turn genetic insight into better health and personal understanding.
What you'll do
Detection engineering and investigation
-
Design, build, and tune threat detections, and measure and improve their fidelity over time.
-
Operate and extend our detections-as-code pipeline, from detection logic through testing and deployment, utilizing Terraform.
-
Triage, investigate, and prioritize security alerts across endpoint, identity, cloud, and application telemetry, separating true events from background noise.
-
Conduct proactive threat hunting informed by current attacker tradecraft.
-
Identify automation opportunities and build integrations that reduce manual response effort.
Incident response
-
Serve as Incident Commander on a shared rotation, coordinating response across Engineering, IT, Legal, and Privacy for the duration of an incident.
-
Maintain and improve incident response runbooks and playbooks based on what you learn in real incidents.
-
Track open incidents through closure, confirm corrective and preventive actions, and report incident metrics to security leadership.
Working across the company
-
Partner with Engineering, IT, Research, and Compliance to build security automation, and measure whether it reduces detection and response time in practice.
-
Participate in an on-call rotation; eligible for an additional on-call bonus.
What you'll bring
-
4+ years in security operations, detection engineering, or incident response.
-
Detection-as-code experience, or a background in building response automation.
-
Demonstrated hands-on experience with threat detection, threat hunting, and incident investigation, including working directly with logs and telemetry to establish root cause.
-
Proficiency in at least one scripting language (Python preferred) and familiarity with common operating systems.
-
Experience acting as, or deputy to, the lead responder on at least one significant security incident.
-
Proficiency with EDR and SIEM platforms, and familiarity with a modern enterprise stack such as Okta, AWS, CrowdStrike or SentinelOne, Datadog, Sumo Logic, or Splunk.
-
Clear verbal and written communication, including the ability to stay composed under incident pressure and brief both technical and non-technical audiences.
-
Bachelor's degree in Computer Science, Information Systems, or a related field, or an equivalent combination of education and experience.
Nice to have
-
Experience applying AI-assisted tooling to triage, correlation, or investigation workflows; our stack includes Claude, Bedrock, Copilot, and OpenAI.
-
Experience in a regulated or privacy-sensitive environment (health, genomics, financial services).
About Us
23andMe, headquartered in California, is a leading consumer genetics and research company. The company’s mission is to help people access, understand, and benefit from the human genome. 23andMe has pioneered direct access to genetic information as the only company with multiple FDA authorizations for genetic health risk reports. The company has created the world’s largest crowdsourced platform for genetic research, with 80 percent of its customers electing to participate. 23andMe research participants consent to research conducted by 23andMe which is overseen by an independent third-party Institutional Review Board (IRB) regulated under the 'Common Rule' (45 CFR part 46). More information is available at www.23andme.com/research.
At 23andMe, we value a diverse, inclusive workforce and we provide equal employment opportunity for all applicants and employees. All qualified applicants for employment will be considered without regard to an individual’s race, color, sex, gender identity, gender expression, religion, age, national origin or ancestry, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, genetic information, military or veteran status, or any other basis protected by federal, state or local laws. If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at accommodations-ext@23andme.com. 23andMe will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.
Please note: 23andMe does not accept agency resumes and we are not responsible for any fees related to unsolicited resumes. Thank you.
Pay Transparency
23andMe takes a market-based approach to pay, and amounts will vary depending on your geographic location. The salary range reflected here is for a candidate based in the San Francisco Bay Area. The successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.
San Francisco Bay Area Base Pay Range
$130,000-$165,000