Chegg logo

Chegg

Staff Security Engineer – Detection & Response

🇮🇳 New Delhi, Delhi 🕑 Full-Time 💰 TBD 💻 Cybersecurity 🗓️ September 30th, 2026
Docker GuardDuty Kubernetes

Edtech.com's Summary

Chegg is hiring a Staff Security Engineer – Detection & Response to protect student data by finding and stopping intrusions across its cloud, endpoint, and email environments. The engineer investigates alerts, leads incidents from detection through recovery, and tunes the detection content that keeps false positives down. Between incidents, the work shifts to security engineering, closing telemetry gaps and automating response actions.

Highlights
  • Triage and investigate SIEM/UEBA, endpoint, cloud, and email alerts to spot real intrusions
  • Lead security incidents end to end, from containment and eradication through recovery
  • Write incident timelines, root cause analyses, and post-incident reviews that drive lasting fixes
  • Build and tune detection content to widen coverage of attacker behavior while cutting alert fatigue
  • Maintain incident response playbooks and runbooks
  • Deploy security tooling in the cloud, close logging gaps, and automate response actions
  • Partner with IT, engineering, and cloud teams to push remediation to closure
  • 7+ years of experience in security operations, detection and response, or incident response
  • Working knowledge of AWS security, MITRE ATT&CK, and scripting in Python
  • Exabeam, SentinelOne, GuardDuty, and certifications like GCIH or OSCP are a plus

Staff Security Engineer – Detection & Response Full Description


Job Description
Staff Security Engineer Detection & Response
Your goal to improve the education process and better the lives of students by keeping their data secure. 
What you will do:
  • Triage and investigate alerts from our SIEM/UEBA, endpoint detection and response, cloud, and email security platforms to determine whether indicators of compromise represent a real intrusion
  • Declare, lead, and manage security incidents end to end endpoint compromise, cloud and infrastructure compromise, credential theft, phishing, and insider risk through containment, eradication, and recovery
  • Own written incident documentation, including timelines, root cause analysis, and post-incident reviews that drive durable fixes rather than one-off cleanup
  • Build, tune, and maintain detection content to expand coverage of real attacker behavior while reducing false positives and alert fatigue
  • Develop and maintain incident response playbooks and runbooks
  • Between incidents, contribute to security engineering work: deploying and operating security tooling in our cloud environment, closing logging and telemetry gaps, and automating response actions
  • Partner with IT, engineering, and cloud platform teams to drive remediation of identified weaknesses to closure
What you'll bring
  • 7+ years of relevant work experience, with significant time spent in security operations, detection and response, or incident response
  • Hands-on experience investigating alerts across SIEM/UEBA and endpoint detection and response tooling, and separating true positives from noise at volume
  • Demonstrated experience leading incident response from detection through recovery, including coordinating responders and stakeholders across teams
  • Strong understanding of attacker tradecraft and common attack paths across endpoint, identity, network, and cloud, and familiarity with a framework such as MITRE ATT&CK
  • Working knowledge of security in cloud environments, ideally AWS, including identity, logging, and the misconfigurations attackers most often abuse
  • Experience writing and tuning detection logic, correlation rules, or queries against large log data sets
  • Scripting and automation ability, such as Python, and comfort working with open-source tools and APIs to connect systems and remove manual effort
  • Practical familiarity with Windows, macOS, and Linux internals, and the forensic artifacts each produces during an investigation
  • Sound judgment and composure under pressure, including the ability to make decisions with incomplete information
  • Excellent written and oral communication skills, including the ability to explain an incident clearly to both engineers and executives
  • Ability to work independently and with various other teams across the organization
  • Creative, resourceful, and adaptive problem solving
Stand Out Qualifications
  • Experience with a SIEM or UEBA platform such as Exabeam, and an endpoint detection and response platform such as SentinelOne
  • Experience working in AWS with features such as GuardDuty, CloudTrail, Security Hub, Inspector, IAM, WAF and Shield
  • Experience managing detection content as code, under version control and peer review
  • Familiarity with SOAR platforms and automated response workflows
  • Digital forensics, malware analysis, or reverse engineering experience
  • Experience working with container technologies including Docker and Kubernetes
  • Relevant certifications such as GCIH, GCIA, GCFA, OSCP, or AWS Certified Security - Specialty

Why do we exist?
Students are working harder than ever before to stabilize their future. Our recent research study called State of the Student shows that nearly 3 out of 4 students are working to support themselves through college and 1 in 3 students feel pressure to spend more than they can afford. We founded our business on provided affordable textbook rental options to address these issues. Since then, we've expanded our offerings to supplement many facets of higher educational learning through Chegg Study, Chegg Math, Chegg Writing, Chegg Internships, Chegg Skills, and more to support students beyond their college experience. These offerings lower financial concerns for students by modernizing their learning experience. We exist so students everywhere have a smarter, faster, more affordable way to student.
Video Shorts
Chegg Corporate Career Page: https://jobs.chegg.com/
 
Chegg out our culture and benefits!
Chegg is an equal opportunity employer