About the team and the role:The Detection & Response team helps protect eBay's global marketplace by identifying, investigating, and responding to cyber threats across a sophisticated technology environment. This role sits at the center of high-impact security work, partnering closely with the SOC, Global Technology engineering, People Team, Legal, and other security teams to reduce risk and strengthen resilience across the company.
As a senior individual contributor, you will work across endpoint, identity, cloud, Kubernetes/container, and network environments to investigate advanced threats, improve detections, and help compose scalable response capabilities. This is an opportunity to influence how eBay detects and responds to modern adversaries, while contributing to automation, threat-informed defense, and continuous improvement across the security program. This role participates in an on-call rotation.
What you will accomplish:- Lead high-impact incident response across a wide range of scenarios, including external intrusions, insider threats, and misuse, helping contain risk and restore business operations quickly and optimally. Improve eBay's ability to detect and respond to threats by building, tuning, and maintaining SIEM detections and alert logic that increase coverage while reducing false positives.
- Investigate complex security events end-to-end by reconstructing activity from telemetry, identifying root cause, and driving containment, eradication, and recovery with multi-functional partners.
- Apply threat modeling to new systems, infrastructure, and features, translating security risks into practical telemetry, detection, and response requirements for engineering teams.
- Proactively hunt for attacker behavior, surface visibility gaps, and turn adversary research into actionable countermeasures, playbooks, and detective controls that strengthen long-term defense.
- Develop automation and tooling, including AI- or agent-assisted workflows, to streamline enrichment, triage, evidence collection, and response actions in ways that are safe, auditable, and scalable.
What you will bring:- 5+ years of experience in incident response, detection engineering, threat hunting, or a closely related security field, with a track record of leading investigations and improving response operations.
- Strong understanding of modern adversary tactics, techniques, and procedures, capable of translating them into practical detections, mitigations, and response strategies.
- Hands-on experience across cloud and SaaS environments, with the ability to develop detection approaches that can scale across platforms such as AWS, Azure, and GCP.
- Experience working in Kubernetes or containerized environments, including using cluster telemetry to investigate activity and identify common attack paths or failure patterns.
- Proven network and digital forensics fundamentals, including analyzing network traffic and applying forensically sound practices during active investigations.
- Scripting or automation experience in Python or a similar language, along with strong communication skills and the flexibility to participate in an on-call rotation.
#LI-BB1
Additional DetailsThe base pay range for this position is expected in the range below:
$118,800 - $205,600
Base pay offered may vary depending on multiple individualized factors, including location, skills, and experience. The total compensation package for this position may also include other elements, including a target bonus and restricted stock units (as applicable) in addition to a full range of medical, financial, and/or other benefits (including 401(k) eligibility and various paid time off benefits, such as PTO and parental leave). Details of participation in these benefit plans will be provided if an employee receives an offer of employment.
If hired, employees will be in an "at-will position" and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
Remote roles are not eligible for U.S. visa sponsorship.