<div class="content-intro"><p><strong>About Mixpanel</strong></p> <p>Mixpanel turns data clarity into innovation. Trusted by more than 29,000 companies, including Workday, Pinterest, LG, and Rakuten Viber, Mixpanel’s AI-first digital analytics help teams accelerate adoption, improve retention, and ship with confidence. Powering this is an industry-leading platform that combines product and web analytics, session replay, experimentation, feature flags, and metric trees. Mixpanel delivers insights that customers trust. Visit <a href="mixpanel.com" target="_blank">mixpanel.com</a> to learn more.</p></div><p><strong>About the Information Security Team</strong></p> <p>We believe security isn't just a function—it's a platform for bold ideas. The Information Security Team at Mixpanel is a small, high-impact group committed to building a frictionless security program that serves as a model for our company and the broader industry. This is a team for those who are never satisfied, who dream big, and who have the resilience to see those ideas through.</p> <p>We operate at the intersection of business strategy and technical execution, where we are critical partners to every team at Mixpanel. Our work requires a broad, generalist skill set across vulnerability management, threat detection, and access management. We strategically balance necessary compliance work with proactive initiatives, with a constant focus on automation as the path to a more efficient security program.</p> <p>We use our expertise in a variety of well-known security platforms and tools to create seamless, automated processes that empower our peers. We are a lean team by design, and we succeed or fail together, committed to transparent communication and a strong sense of ownership.</p> <p><strong>Responsibilities</strong></p> <ul> <li><strong>Domain Ownership:</strong> Serve as the domain expert for Detection & Response, integrating telemetry from across our entire ecosystem—including Product, Cloud, Corporate Infrastructure, and Identity—to build a unified, high-fidelity detection and response engine.</li> <li><strong>Technical Project Execution:</strong> Translate high-level project requirements and technical scoping documents into actionable milestones, managing task delivery and driving cross-functional results.</li> <li><strong>Architect Modern Detection:</strong> Design and implement precise, actionable alerting within Google Security Operations (SIEM/SOAR), treating detections as code and ensuring they scale with our high-volume data ingestion.</li> <li><strong>Combat Modern Threats:</strong> Develop specialized detection logic and playbooks to identify and mitigate application-layer abuses, customer account-targeted events (ATO), and sophisticated social engineering.</li> <li><strong>Operational Lead (EMEA):</strong> Serve as the primary technical lead for security incidents during EMEA hours, driving investigations, containment efforts, and cross-functional communication.</li> <li><strong>Build Threat Intelligence:</strong> Evolve Mixpanel’s threat intelligence program by identifying relevant adversaries and translating tactical intel into proactive SIEM/SOAR logic.</li> <li><strong>Infrastructure Management:</strong> Ensure the operational health and telemetry flow of our core security stack—including SentinelOne, GCP ****Security Command Center, and Mimecast Incydr—to maintain continuous visibility and alerting integrity.</li> </ul> <p><strong>We're Looking For Someone Who Has</strong></p> <ul> <li><strong>Security Engineering Foundations:</strong> Experience operating across the core pillars of a modern security program—including Product, Cloud, and Corporate Security. You are comfortable navigating Identity (IAM), threat modeling, and secure code reviews as part of a unified team.</li> <li><strong>Detection & Response Specialization:</strong> A deep understanding of the detection-as-code lifecycle. You have experience turning raw telemetry into precise, actionable alerting and building the infrastructure required to defend a high-scale SaaS environment.</li> <li><strong>Operational Execution:</strong> The ability to manage a high volume of daily security tasks. You are prepared to handle a diverse range of responsibilities—from triaging vulnerabilities and policy violations to investigating suspicious activity across the entire stack.</li> <li><strong>Cloud Data Proficiency:</strong> Proficiency with the Google Cloud Platform ecosystem (specifically Cloud Logging, BigQuery, and Pub/Sub) to build automated security data pipelines and maintain visibility across high-volume environments.</li> <li><strong>Modern Automation & AI:</strong> Proficiency in <strong>Python</strong> to develop automated workflows and integrate security tools via APIs. You are comfortable leveraging AI and LLMs to build autonomous security workflows—such as automated alert enrichment, intelligent incident summarization, and AI-assisted code analysis—to drastically reduce time-to-context.</li> </ul> <p><strong>Bonus Points For</strong></p> <ul> <li><strong>Threat Intelligence Maturity:</strong> Experience evaluating and embedding external intelligence—including <strong>dark web monitoring, brand protection, and adversary tactics</strong>—into a security program. You know how to identify where a specific intelligence source provides the most defensive value and how to integrate that data into automated workflows.</li> <li><strong>Security Outreach & Mentorship:</strong> Experience leading "Security Champions" initiatives or a demonstrated ability to elevate the security IQ of non-security teams. You help others think critically about <strong>threat identification and telemetry</strong>—explaining the "why" behind visibility requirements when building new features or onboarding third-party vendors.</li> <li><strong>Deception & Canary Strategies:</strong> Familiarity with deploying <strong>deception techniques</strong> (e.g., hon