Principal Cyber Security Incident Response Engineer (DFIR)

Job Posted 14 Days Ago Posted 14 Days Ago
Hiring Remotely in USA
Remote
170K-250K Annually
Senior level
Fashion
The Role
The Principal Cyber Security Incident Response Engineer leads incident response initiatives, ensuring security in cloud environments while collaborating with engineering teams to develop effective security solutions and compliance adherence.
Summary Generated by Built In
About Stitch Fix, Inc.

Stitch Fix (NASDAQ: SFIX) is the leading online personal styling service that helps people discover the styles they will love that fit perfectly so they always look - and feel - their best. Few things are more personal than getting dressed, but finding clothing that fits and looks great can be a challenge. Stitch Fix solves that problem. By pairing expert stylists with best-in-class AI and recommendation algorithms, the company leverages its assortment of exclusive and national brands to meet each client's individual tastes and needs, making it convenient for clients to express their personal style without having to spend hours in stores or sifting through endless choices online. Stitch Fix, which was founded in 2011, is headquartered in San Francisco.

About the Team

We are a team of collaborative, empathetic, and passionate security practitioners with diverse backgrounds and expertise spanning Vulnerability Management, Incident Response, Security Operations, and DevSecOps. Our mission is to prioritize security in everything we do while enabling the business and fostering seamless collaboration with our partners—reducing friction, not creating it.

Our team members have a high degree of autonomy in ensuring Stitch Fix remains secure. The ideal candidate will have strong communication skills and thrive both independently and as part of a highly distributed engineering team.

We’re seeking individuals who prioritize usable security and are passionate about security and automation. As Stitch Fix continues to grow rapidly, our security program must scale alongside it—balancing robust protection with the flexibility to support innovation.

About the Role

At Stitch Fix, we operate in a cloud-first environment and are seeking a Principal Incident Response Engineer to lead security initiatives. This role will focus on incident response, implementing best practices across infrastructure, network security, and cloud environments, as well as ensuring compliance and policy adherence. This role is part of the Security Team and collaborates closely with Platform and Development teams. The ideal candidate should have extensive experience in Incident Response, container technologies, and deployment and integration patterns within a production AWS environment. 

You're excited about this opportunity because you will…

  • Collaborate to develop innovative security solutions, leveraging the right tools while contributing to design and architecture across multiple systems. You're eager to expand your expertise and help us integrate new technologies. This is a team where learning is mutual—you’ll learn from us, and we’ll learn from you. Most importantly, you are deeply committed to protecting our clients and employees from threats.
  • Work closely with the team to develop effective solutions, leveraging the right tools while contributing to design and architecture across multiple systems. You're eager to expand your expertise and help us integrate new technologies. You are committed to delivering a seamless and impactful experience.
  • Design, deploy, and manage security services within an organization—while also acting as the go-to expert for incident response and cloud security.
  • Be the first to step in, tackle challenges head-on, and do what it takes to protect and secure our organization.
  • Ensure that technology solutions address real business challenges. Your insights are valued by both team members and business partners, who look to you for guidance on how our security initiatives should function. You're not afraid to ask tough questions, challenge assumptions, and engage with customers, stakeholders, and executives to drive meaningful outcomes.

We’re excited about you because you…

Have broad skills building, deploying, and maintaining security services in an organization, and serving as the Subject Matter Expert for incident response and cloud security. Additionally you have the following experience:

  • 6+ years of experience in Security, preferably in an Incident Response or similar “first responder” role (Trust & Safety, Fraud, Account Protection, etc.).
  • Experience leading and assisting with Security Incident analysis, documentation, and response coordination.
  • Proficient with the cyber security incident lifecycle and hands on involvement in security event handling.
  • Understanding of common adversarial tools, attack techniques, and Indicators of Compromise (IOCs).
  • Intermediate to advanced knowledge of APT groups, TTPs (Tactics, Techniques, and Procedures).

Cloud & Infrastructure Security:

  • AWS experience is required; familiarity and high degree of proficiency with AWS services (e.g., Route53, IAM, Security Groups, SNS, S3, Lambas, CloudWatch, Cloud Trail)   
  • Hands-on experience with AWS environments, particularly in a security context; familiarity with AWS security services (e.g., Security Hub, GuardDuty, Macie).
  • Hands on working knowledge of Infrastructure as Code (IaC) concepts and tools such as Terraform and Docker.
  • Understand the use of CI/CD pipelines and their role in a security context.

Security Tools & Logging:

  • Experience optimizing and integrating common logging solutions (e.g., Splunk, SumoLogic, Datadog).
  • Ability to interpret logs, events and escalate potential security threats and findings
  • Hands-on investigative and deployment experience with Endpoint Detection & Response (EDR) solutions like CrowdStrike.

Programming & Automation:

  • Proficient with scripting languages (e.g., Python) developing automation and security workflows.

Soft Skills & Collaboration:

  • Ability to follow established security procedures and lead incident response efforts.
  • Strong written communication skills for security documentation and reporting.
  • Ability to collaborate with cross-functional teams and assist in security investigations.

Development & Continuous Learning:

  • Knowledge of common development practices, tools and how it applies in a security context.
  • Eager and willing to learn and develop new skills in security automation and cloud security.
  • Have the ability and experience to mentor and develop junior team members, fostering growth within the team.

Incident Commander RoleAct when called upon in the capacity of Incident Commander during security incidents

    • Ability to follow established investigative processes including management & escalation procedures while working with other senior team members during an incident; includes drafting a SITREP and driving post-mortems. 
    • Excel in engaging with cross-functional teams during an incident in parallel with  leading an active investigation and influencing favorable outcomes outside of security.
    • Poses the ability to stay calm “under pressure” while leading an incident to resolution in potential high-stress and time sensitive environments.

About the Technology

Technologies we rely on to pursue solutions to business problems include:

  • Ruby on Rails
  • Golang
  • CircleCI
  • Docker
  • AWS Compute Resources
  • Linux/Mac
  • ZScaler
  • HashiCorp Terraform
  • Python
  • Github
  • Jira
  • DataDog
  • CrowdStrike
  • Pagerduty

Whether you're already experienced with these tools or just getting started, you'll have the opportunity to deepen your expertise. If some of these tools are new to you, we’ll provide the support and resources you need to learn and become proficient.

Why you'll love working at Stitch Fix...

  • We are a group of bright, kind people who are motivated by challenge. We value integrity, innovation and trust. You’ll bring these characteristics to life in everything you do at Stitch Fix.
  • We cultivate a community of diverse perspectives— all voices are heard and valued.
  • We are an innovative company and leverage our strengths in fashion and tech to disrupt the future of retail. 
  • We win as a team, commit to our work, and celebrate grit together because we value strong relationships.
  • We boldly create the future while keeping equity and sustainability at the center of all that we do. 
  • We are the owners of our work and are energized by solving problems through a growth mindset lens. We think broadly and creatively through every situation to create meaningful impact.
  • We offer comprehensive compensation packages and inclusive health and wellness benefits.

Compensation and Benefits
This role will receive a competitive salary, benefits, and equity. The salary for US-based employees hired into this role will be aligned with the range below, which includes our three geographic areas. A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, location, and performance.This position is eligible for new hire and ongoing grants of restricted stock units depending on employee and company performance. In addition, the position is eligible for medical, dental, vision, and other benefits. Applicants should apply via our internal or external careers site.

Salary Range

$170,000$250,000 USD

This link leads to the machine readable files that are made available in response to the federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to more easily access and analyze data.

Please review Stitch Fix's US Applicant Privacy Policy and Notice at Collection here: https://stitchfix.com/careers/workforce-applicant-privacy-policy

Recruiting Fraud Alert: 

To all candidates: your personal information and online safety are top of mind for us.  At Stitch Fix, recruiters only direct candidates to apply through our official career pages at https://www.stitchfix.com/careers/jobs or https://web.fountain.com/c/stitch-fix.

Recruiters will never request payments, ask for financial account information or sensitive information like social security numbers. If you are unsure if a message is from Stitch Fix, please email careers@stitchfix.com. 

You can read more about Recruiting Scam Awareness on our FAQ page here: https://support.stitchfix.com/hc/en-us/articles/1500007169402-Recruiting-Scam-Awareness 


Top Skills

AWS
Crowdstrike
Datadog
Docker
Incident Response
Python
Security Operations
Security Tools
Splunk
Sumologic
Terraform
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
5,339 Employees
On-site Workplace
Year Founded: 2011

What We Do

Stitch Fix is the personal style service for men and women that evolves with your tastes, needs and lifestyle.It’s our mission to change the way people find clothes they love by combining technology with the personal touch of seasoned style experts. The Stitch Fix experience is not merely curated—it’s truly personalized. We’re here to help our clients save time, look great and evolve their personal style over time.

Similar Jobs

Instacart Logo Instacart

IT Corporate Engineering (Contractor)

eCommerce • Food • Software
Remote
United States
3000 Employees

Upstart Logo Upstart

Principal Security Engineer

Artificial Intelligence • Fintech • Machine Learning • Social Impact • Software
Easy Apply
Remote
2 Locations
1500 Employees
182K-253K Annually

PagerDuty Logo PagerDuty

Senior Security Engineer 4 - Infrastructure and Automation

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Remote
Hybrid
USA
1200 Employees

PagerDuty Logo PagerDuty

Senior Security Engineer 3, Product & Application Security

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Remote
USA
1200 Employees

Similar Companies Hiring

Brilliant Earth Thumbnail
Retail • Fashion • eCommerce
Edina, MN
700 Employees
Rue Gilt Groupe Thumbnail
Retail • Fashion • eCommerce • Consumer Web
Boston, MA
1000 Employees
Tapestry - Coach, Kate Spade, and Stuart Weitzman Thumbnail
Wearables • Sales • Retail • Other • Fashion • eCommerce • Design
New York, NY
16000 Employees
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account