

Job Category
Software EngineeringJob Details
You will work directly on the Slack Security Engineering team with a focus on threat detection, logging, and remediation. We know that no system is perfect, but we aim to provide a record of all actions taken in our environment to address any unknowns.
We’d like you to have experience in some element of Data Science / ML work - the likely result here is that you start with some simple ML models for anomaly detection, and go from there. Our eventual goal is to use LLMs to advance our alerting capabilities and even trainclassification/clusteringmodels specifically on our data to generate sophisticated alerts and build a feedback loop that learns on its own.
What you will be doingIdentify and develop new features and a roadmap to augment existing tools to protect Slack’s production infrastructure and to help make our business lives simpler, more pleasant, more productive, and more secure
Detect threats and help Slack be more secure
Help to develop eBPF tooling and author detections therein
Creatively scale and operate the infrastructure and tools that handle millions of events per second
Respond in our on-call rotation to fix services we run and investigate potential threats
Curiosity and creativity. You want to know
A desire to empower your coworkers.This is a role afforded the latitude to define workstreams, and entrusted to approach engineering problems as an art form. You want the solutions you collaborate on to be easy to maintain and you take pride in the quality of your work.
Motivation to solve problems, not to patch over quick fixes.Being on-call shouldn’t be a burden to team members. If it ever is, fixing it is our highest priority.
Eagerness to collaborate across the company.We seek to further our approachable and inclusive team ethos. As a software development team first, we are aligned and working with the rest of engineering.
Broad exposure to various security disciplinesand deep understanding of models and reasons behind core security concepts such as MFA, ZeroTrust, and securely managing secrets or tokens.
AWS — We run almost everything here, so existing proficiency is a plus, but we can teach you if you’re more comfortable with another provider
Elasticsearch / Kibana — you can readily access information and love metrics
Google Chronicle/SecOps - Experience with this SIEM would help you to understand how to manage events
If you require assistance due to a disability applying for open positions please submit a request via this.
Posting Statement
משרות נוספות שיכולות לעניין אותך