Security Engineer

Five9, Inc.
United States
12 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$66,300.0 - $174,700.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Software as a Service Cloud Computing Cyber Security Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Automation of Marketing Data Logging Scripting Google Cloud
+6 more
Large Language Models Prompt Engineering Cyber Threat Analysis Cybercrime Production Code Low-code

Job description

  • Incident response. Own incidents end to end: scoping, containment, forensics, write-up, and remediation follow-through.
  • Detection engineering. Write, tune, test, and retire detections. Detection content is version controlled, reviewed, and measured on outcomes rather than alert volume.
  • IR automation. Build playbooks, integrations, and workflows that remove repeated manual steps from the response process. This is a large part of the role.
  • Threat intelligence. Track activity relevant to our environment and convert it into detections, hunts, and hardening work.
  • Threat hunting. Be a contributor to our hypothesis-led threat hunting initiatives.
  • AI-assisted development. Build and improve the agents, prompts, and enrichment logic behind the triage pipeline.
  • Alert triage. A limited amount: escalations the pipeline surfaces, plus the feedback that improves it., You will be given problems rather than tickets, and you are responsible for the solution and the reasoning behind it. There is no micromanagement and minimal handholding. This suits people who self-direct and are candid when something is not working. It does not suit people who need an assigned queue.

Requirements

  • Hands-on security operations experience, including incidents you can walk through in detail.
  • Proficiency in at least one scripting language (Python or equivalent) and a preference for solving recurring problems with code.
  • Working knowledge of detection logic, log pipelines, and modern telemetry sources: EDR, identity, cloud, network, and SaaS.
  • Ability to take an ambiguous problem, define what done looks like, build it.
  • Clear written communication: incident timelines, design notes, and postmortems.

Preferred

  • Google Cloud Platform and/or AWS experience, including cloud logging, IAM, and cloud-specific failure modes.
  • Low-code automation platforms such as Tines or n8n, and judgment about when a workflow should become production code.
  • Agent programming and prompt engineering, specifically LLM tooling reliable enough for operational use.
  • Experience with AI-enriched detection or triage pipelines.

Benefits & conditions

Work Location: This role is fully remote for candidates who reside outside the 30 mile radius of one of our offices. For candidates who reside within a 30 mile radius of one of our offices, this role is Hybrid and would require 3 days a week (T, W, TH) in office.

As part of our continued commitment to diversity, equity, and inclusion, Five9 supports pay transparency during the entire recruitment process. Actual compensation packages are based on several factors that are unique to each candidate including, but not limited to: skill set, depth of experience, certifications, and specific work location. The range displayed reflects the minimum and maximum target for new hire salaries for the job across the United States. Your recruiter can share more about the specific compensation package during your hiring process.

Additionally, the total compensation package for this position may also include an annual performance bonus, stock, and/or other applicable incentive compensation plans.

Our total reward package also includes:

  • Health, dental, and vision coverage, beginning on the first day of employment. Five9 covers 100% of the employee portion of the health, dental and vision coverage and shares a high portion of the dependent cost. We also offer Short & Long-Term Disability, Basic Life Insurance, and a 401k saving plan with employer matching.
  • Access to an innovative mental health support platform that offers personalized care and resources in areas such as: therapy, coaching and self-guided mindfulness exercises for all covered employees and their covered dependents.
  • Generous employee stock purchase plan.
  • Paid Time Off, Company paid holidays, paid volunteer hours and 12 weeks paid parental leave.

All compensation and benefits are subject to the requirements and restrictions set forth in the applicable plan documents and any written agreements between the parties.

The US base salary range for this role is below.

$66,300-$174,700 USD

Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer.

View our privacy policy, including our privacy notice to California residents here

About the company

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

Our triage pipeline is heavily AI-enriched, so analysts spend little of their day working alerts directly. The role is the work around triage: incident response, detection engineering, response automation, threat intelligence, and building the AI tooling the pipeline runs on. It is closer to a security engineering role than to a conventional SOC analyst role, and we expect you to write code. This position requires the person to work Pacific Time hours (9:00AM - 5:00PM).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:09 min

Defining low-code systems and determining their ideal use cases

Halil İbrahim Kalkan Halil İbrahim Kalkan · World Congress 2026 Europe

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:35 min

Governing generated low-code applications via deterministic process engines

Kerstin Stier Kerstin Stier · Europe 2026 Virtual

Videos

See all

Related articles

See all