The opportunity
Mixpanel is the leading product intelligence and analytics platform, trusted by more than 29,000 companies to help understand how people use the products they build. By combining powerful analytics with AI that knows your business, Mixpanel helps teams see what’s working,…
What you'll do
Domain Ownership: Serve as the domain expert for Detection & Response, integrating telemetry from across our entire ecosystem—including Product, Cloud, Corporate Infrastructure, and Identity—to build a unified, high-fidelity detection and response engine.
Technical Project Execution: Translate high-level project requirements and technical scoping documents into actionable milestones, managing task delivery and driving cross-functional results.
Architect Modern Detection: Design and implement precise, actionable alerting within Google Security Operations (SIEM/SOAR), treating detections as code and ensuring they scale with our high-volume data ingestion.
Combat Modern Threats: Develop specialized detection logic and playbooks to identify and mitigate application-layer abuses, customer account-targeted events (ATO), and sophisticated social engineering.
Operational Lead (EMEA): Serve as the primary technical lead for security incidents during EMEA hours, driving investigations, containment efforts, and cross-functional communication.
Build Threat Intelligence: Evolve Mixpanel’s threat intelligence program by identifying relevant adversaries and translating tactical intel into proactive SIEM/SOAR logic.
What they're looking for
- Infrastructure Management: Ensure the operational health and telemetry flow of our core security stack—including SentinelOne, GCP ****Security Command Center, and Mimecast Incydr—to maintain continuous visibility and alerting integrity.
- Security Engineering Foundations: Experience operating across the core pillars of a modern security program—including Product, Cloud, and Corporate Security. You are comfortable navigating Identity (IAM), threat modeling, and secure code reviews as part of a unified team.
- Detection & Response Specialization: A deep understanding of the detection-as-code lifecycle. You have experience turning raw telemetry into precise, actionable alerting and building the infrastructure required to defend a high-scale SaaS environment.
- Operational Execution: The ability to manage a high volume of daily security tasks. You are prepared to handle a diverse range of responsibilities—from triaging vulnerabilities and policy violations to investigating suspicious activity across the entire stack.