Abby Care is building security operations that protect people and data across modern cloud, endpoint, and identity environments. This hybrid role in San Francisco, CA offers competitive compensation, comprehensive health coverage, and benefits that help you plan for the long term, while you strengthen detection, incident response, vulnerability management, and security governance.
What you’ll do
- Own end-to-end incident response, threat hunting, and root cause analysis across SIEM, EDR (SentinelOne), and cloud security tooling.
- Develop and maintain incident response playbooks, runbooks, and support tabletop exercises.
- Run the vulnerability management lifecycle by partnering with IT and Engineering to remediate scan, pen test, and audit findings.
- Maintain the risk register, perform third-party/vendor risk assessments, and communicate technical risks to business stakeholders.
- Partner with IT to audit and enforce security controls across Okta (RBAC/MFA), Google Workspace (DLP/logs), JAMF, and SentinelOne.
- Drive evidence collection and remediation for compliance audits including SOC 2, ISO 27001, HIPAA, and PCI DSS, aligning policies with NIST CSF and CIS frameworks.
- Automate detection, response, and reporting workflows using SOAR, scripting, and APIs to improve alert quality and operational efficiency.
- Mentor team members and contribute to cross-functional security knowledge sharing.
- Help establish guardrails for enterprise AI tools (including GenAI and Claude), mitigating shadow AI, data leakage, and third-party vendor risks in collaboration with IT, Legal, and Compliance.
- Partner with Product and Engineering to assess and remediate AI/LLM-specific vulnerabilities such as prompt injection, model abuse, and data exposure.
- Pilot and evaluate AI-powered security capabilities, including AI-assisted SIEM/EDR triage and anomaly detection to improve response speed.
What you’ll bring
- 8+ years of experience in security operations, including leading incident response end-to-end from detection through remediation.
- Associate’s or Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent practical experience.
- Hands-on experience with SIEM, EDR/XDR (example: SentinelOne), vulnerability scanners, cloud security, and core IAM concepts (SSO, MFA, RBAC).
- Working knowledge of SOC 2, ISO 27001, NIST, and CIS, with strong analytical skills to translate technical risk for business stakeholders.
- Familiarity with emerging AI/LLM risks and interest in evaluating AI capabilities for security use cases.
- Excellent communication skills, with the ability to prioritize competing incidents and remain calm under pressure.
Technologies you’ll work with
SIEM, EDR, SentinelOne, Okta, RBAC, MFA, Google Workspace, DLP, JAMF, SOAR, NIST CSF, CIS, SOC 2, ISO 27001, HIPAA, PCI DSS, GenAI, Claude, Terraform, Python, Bash, AWS, GCP, Azure, AI-assisted SIEM/EDR triage, anomaly detection, SSO, prompt injection, model abuse, data exposure.
Benefits
- Competitive compensation packages.
- Comprehensive health coverage, including a $0 deductible PPO and a company-funded HSA, plus employer-paid life and disability insurance.
- Generous paid time off and 10 paid company holidays.
- Financial savings benefits including HSA contributions, optional FSA and commuter benefits, and full coverage of all 401(k) account fees (employer match not currently offered).
- Paid parental leave of up to 10 weeks based on tenure.
Reporting line: Director of IT, Information & Security.
Compensation range: $130,000 - $165,000.