Twilioremote

Salary
$141,520–$208,000from the description
Posted
Jul 16, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual contributor role on a Security Incident Response Team, focused on leading end-to-end handling of security events across a large cloud-based global infrastructure — from triage and containment through remediation and post-incident improvement. The work also involves building runbooks, extending SIEM and SOAR capabilities, automating response processes, and mentoring teammates. Suits engineers with substantial hands-on cloud incident response experience.

Senior level · 5+ years · Remote · Full-time

Must have (6)
Security Incident Response · 5+ yrsCloud SecurityAWS, GCP or AzureSIEMSOARAI
Nice to have (3)
LLMsThreat IntelligenceDigital Forensics

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 4,200 people nationally plausibly meet what this posting asks for (information security analysts). range 1,750–6,300

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Security Incident Response62%SIEM55%Cloud Security42%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The compensation ranges provided apply only to candidates in CO, HI, IL, MD, MA, MN, VT, DC, NY, NJ, WA, and CA — the posting explicitly states the role is open to candidates outside those states with no pay range disclosed for other locations.

The role is explicitly excluded from hire in CA, CT, NJ, NY, PA, and WA despite being otherwise fully remote.

The 'Ability to utilize AI for comprehensive, complex security incident response activities' appears in the Required section and is treated as a hard gate; the more specific GenAI/LLM use cases (AI-Driven Threat Response, AI Model Security) appear under Desired and are marked preferred.

Cloud platform experience (AWS, GCP, or other large cloud) is required; AWS is listed as the primary name with GCP and Azure as accepted alternatives.

'Service-Oriented Architecture' is listed as a required knowledge area rather than a specific named tool — included because the JD explicitly gates on it as a subject-matter domain.

Malware analysis and digital forensics skills appear only under the Desired 'Artifact & Evidence Triage' bullet and are marked preferred.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Service-Oriented Architecture, Malware Analysis.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗