DigitalOcean Logo

DigitalOcean

Senior Security Analyst I

Reposted 11 Hours Ago
Be an Early Applicant
In-Office
Seattle, WA
Senior level
In-Office
Seattle, WA
Senior level
Lead and own the insider threat program: design detection, automate workflows, build/tune UEBA/SIEM/DLP/UAM detection content, investigate anomalous activity, collaborate with DFIR/Threat Intel/HR/Legal, perform large-scale data analytics and reporting, and improve metrics and playbooks to reduce risk and false positives.
The summary above was generated by AI

Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here.  We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world. 

We are looking for a highly experienced and motivated Senior Security Analyst who is passionate about advanced security monitoring, detection engineering, and threat hunting. As a Senior Security Analyst at DigitalOcean, you will lead and own critical aspects of our security monitoring program, shaping how we detect, respond to, and prevent threats. You will leverage deep expertise to engineer sophisticated detection capabilities, develop comprehensive metrics to measure program effectiveness, and drive continuous improvement across alerting and response functions. You will be a trusted member of  Infrastructure Security and will collaborate closely with other cross-functional teams to close detection gaps and elevate the organization’s overall security posture.

What You’ll Be Doing:
  • Lead real-time monitoring, triage, and analysis of complex security events, providing verifiable assessments of threats and incident severity.
  • Engineer and automate advanced detection use cases across DigitalOcean's cloud and corporate environments, leveraging deep knowledge of adversary TTPs to design and implement scalable alerting solutions.
  • Develop, track, and report on key metrics for security monitoring effectiveness and incident response performance, using data to drive improvements.
  • Own and evolve the security monitoring program strategy, ensuring alignment with evolving threat landscapes and business priorities.
  • Work closely with Infrastructure Security Engineers to identify log sources, integrate, and maintain data pipelines (e.g., log sources, forwarders, parsing, enrichment).
  • Perform proactive threat hunting and hypothesis-driven investigations and investigate anomalous activity to uncover hidden or emerging threats within DigitalOcean’s environments.
  • Mentor and guide lower level analysts, reviewing escalated incidents and providing technical leadership during incident response.
  • Coordinate threat analysis using historical data and architecture diagrams to identify attack vectors. 
  • Collaborate with multiple teams to close monitoring gaps and improve overall security.
  • Optimize security tools and processes to reduce false positives, improve detection fidelity, and automate response workflows where appropriate.
  • Lead the creation and maintenance of detailed playbooks, runbooks, and documentation to standardize detection and response efforts.
What We’ll Expect From You:
  • 5+ years of hands-on experience with SIEM platforms and endpoint detection tools, with proven impact on security monitoring programs.
  • Demonstrated expertise in designing and tuning complex detection rules and alerting logic across diverse environments.
  • Deep understanding of network and endpoint security, attack methodologies, threat actor tactics, and mitigation strategies.
  • Experience in proactive threat hunting, vulnerability management, and coordinating with red teams or penetration testers.
  • Proven leadership in driving security program initiatives, setting metrics, and influencing cross-team security strategy.
  • Excellent communication skills for technical documentation, incident reporting, and mentoring less experienced analysts.
  • Proven experience with scripting and query languages (Python, Bash, SQL) to automate detection and response workflows.
  • Demonstrated proficiency in Linux, Windows, and macOS.
  • Comfortable working in a fast-paced environment with a collaborative and growth-focused mindset.
Compensation Range: 
  • $140,800 - $176,000

*This is a hybrid role

JR: 2026-8010

#LI-Hyrbid

Why You’ll Like Working for DigitalOcean
  • We innovate with purpose. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
  • We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
  • We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
  • We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
  • DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.

Similar Jobs at DigitalOcean

11 Hours Ago
In-Office
Senior level
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead product strategy and delivery for customer-facing security and identity capabilities. Define roadmaps, translate complex IAM problems into developer-friendly console and API experiences, work with engineering to shape architecture, engage customers for discovery, and drive cross-functional launches and iteration to improve adoption and reduce security risk.
Top Skills: Api TokensAPIsAuthenticationAuthorizationCi/CdClaudeCloud ArchitecturesCursorDistributed SystemsFigmaMachine/Agent IdentityOpenid Connect (Oidc)RbacService AccountsWorkload Identity
Yesterday
In-Office
Senior level
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead applied research and engineering for feedback-driven agentic AI: define reward modeling and reinforcement learning roadmap, design production learning loops and evaluation frameworks, run large-scale experiments, and ship research into production while partnering across product and engineering.
Top Skills: Data PipelinesDpoExperimentation PlatformsFeature StoresGrpoLarge Language Models (Llms)Model ServingObservabilityPreference OptimizationPythonReinforcement Learning (Ppo)Reward ModelingRlaifRlhf
Yesterday
In-Office
Senior level
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead architecture and implementation of network security across edge, backbone, and datacenter environments. Provide technical leadership, conduct threat modeling and network security assessments, build security automation and IaC, integrate controls into SDN/BGP/MPLS systems, participate in incident response, and drive security reviews and best practices across teams.
Top Skills: AristaBgpBgp-LuCienaCloudflareCoreroDdos MitigationDns SecurityElkFirewallGitGoGrafanaIs-IsJuniperLacpLinuxMplsNetwork Intrusion DetectionOspfPrometheusPythonSdnVrrp

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account