We're seeking an experienced Technical Security Analyst to join our Infrastructure Security team. As a Technical Infrastructure Security Analyst, you will leverage your expertise in data analytics and infrastructure to analyze security alerts and respond to issues to protect the trust that merchants place in Shopify.
You will own an issue from start to finish and will bring all the pieces together through your persistence to leave no stone unturned. There is a huge investigative component to this role, where you will have daily opportunities to apply your skills and experience as an analyst to navigate vast amounts of data and to find that needle in the haystack that will be the key to resolving the security issues in our infrastructure.
Analyze and respond to security alerts with the goal of risk reduction.
Collaborate with security and engineering teams to remediate security findings.
Identify trends in our infrastructure security posture, work with the team to understand how this changes risks, and recommend improvements to mitigate them.
Lead root cause analysis (RCA) sessions for issues encountered.
Implement new alerts using the tooling we have in place.
Participate in projects that achieve security safeguard improvements.
Continuously refine the operational knowledge base through documentation and build new documents in a way that scales with the team's growth.
Lead the operational efforts for the team, including defining the operational activities and coordinating the team rotation to support this work.
It would be great if you had experience in one or more of the following (don't stress, we are not expecting experience in all of the following!):
Understanding of information security fundamentals.
Familiarity with identity, access control, and network security concepts.
Expertise in building and operating infrastructure security safeguards.
Knowledge of security issues affecting infrastructure and web applications.
Excellent written and verbal communication skills, with experience in distilling technical data into actionable intelligence for a varied audience.
Experience working with logging and data analysis tools (e.g. SIEM/SOAR; YARA; BigQuery, SQL, Splunk).
Experience working with Google Cloud Platform and Kubernetes.
Experience troubleshooting problems with little up front information (finding the needle in the haystack).
Researching and using data analysis to identify security threats.
Awareness of GitHub and continuous integration practices.
Comfortable running and debugging scripts to automate manual work and reduce toil (e.g. Python, Ruby, Bash)
Comfortable using AI/LLM tools to get the job done quickly and efficiently