Security Analyst, Incident Response

Mexico AnywhereMexico CityCiudad de MéxicoMexicoNorth America

At Lyft, our mission is to improve people’s lives with the world’s best transportation. To do this, we start with our own community by creating an open, inclusive, and diverse organization.

Lyft connects people to transportation to change the way we live and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking for Security Engineers to help us scale. Come be part of a new team at Lyft focused on enabling and empowering engineering teams to deliver at scale.

Our drivers and passengers entrust Lyft with their personal information and travel details to get where they're going and expect us to keep that data safe. Lyft's security team leads efforts across the company to ensure our systems are secure and worthy of our users' trust.

Lyft Security builds systems to protect and defend infrastructure. We consult with teams as they build and launch new products and features, proactively plans for the unexpected, and responds to incidents that occur. Our work has company wide impact and takes place at all levels of the stack, from infrastructure to web application security, as well as mobile apps, IT, bikes, scooters, and autonomous vehicles. We believe in scaling security through engineering fundamentals, automation, and tooling. Check out our blog posts at to learn more about some of the things we’ve built.

The Incident Response team owns mitigation and handling of security indents as well as our proactive hypothesis based Threat Hunting program.

  • Respond to security incidents; orchestrating response across engineering and other disciplines
  • Define and execute threat hunting operations across Lyft's systems with the objective of finding detection gaps, identifying gaps in security controls, and processes
  • Develop automation and tooling to multiply impact of the incident response team
  • Build and maintain relationships with key partners both internally and externally
  • Responding to security incidents in a DFIR or SOC
  • Defining and executing threat hunting operations that yield impactful findings
  • Present findings, recommendations and results to leadership
  • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means
  • Ability to manage multiple tasks and priorities
  • Ability to work independently with minimal supervision
  • Nice to have: scripting and automation skills, experience with cloud technologies such as AWS/GCP/Azure
  • Responder a los incidentes de seguridad; orquestando la respuesta a través de la ingeniería y otras disciplinas
  • Definir y ejecutar operaciones de búsqueda de amenazas en los sistemas de Lyft con el objetivo de encontrar brechas en la detección, identificando brechas en los controles y procesos de seguridad
  • Desarrollar herramientas y  automatización para multiplicar el impacto del equipo de respuesta a incidentes
  • Construir y mantener relaciones con socios clave tanto interna como externamente
  • Respondiendo a incidentes de seguridad en un SOC o mediante DFIR
  • Definiendo y ejecutando operaciones de búsqueda de amenazas que produzcan hallazgos impactantes
  • Presentando hallazgos, recomendaciones y resultados a los líderes
  • Capacidad para comunicar información, conceptos o ideas complejos de manera segura y bien organizada a través de medios verbales, escritos y / o visuales
  • Capacidad para gestionar múltiples tareas y prioridades
  • Capacidad para trabajar de forma independiente con una supervisión mínima
  • Es bueno tener: habilidades de scripting y automatización, experiencia con tecnologías en la nube como AWS / GCP / Azure

Cyber Security Jobs by Category

Cyber Security Jobs by Location

Cyber Security Salaries