At a Glance
- Tasks: Lead incident response and threat hunting to secure eBay's global marketplace.
- Company: Join eBay, a leader in cybersecurity and technology innovation.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Dynamic environment with a focus on innovation and continuous improvement.
- Why this job: Make a real impact in cybersecurity while collaborating with world-class teams.
- Qualifications: 5+ years in incident response or detection engineering; strong technical skills required.
The predicted salary is between 60000 - 80000 £ per year.
This critical position allows you to work at the forefront of cybersecurity technology and information technology risk, where you will detect, investigate, and respond to threats across our global environment. Collaborate with world‑class teams including SOC, engineering, HR/Legal, and other security teams to reduce risk and secure eBay’s global marketplace.
Responsibilities
- Lead incident response across a broad range of scenarios including external intrusion, insider threats, and misuse involving endpoints, identity, cloud, Kubernetes/container layers, and network infrastructure.
- Investigate escalated issues by prioritizing impact, reconstructing activity from telemetry, identifying root cause, and driving containment, eradication, and recovery.
- Build and improve detections by developing, tuning, and maintaining SIEM correlation rules and alerting logic—balancing coverage and noise to reduce false positives and improve time‑to‑detect.
- Threat hunt proactively to identify attacker behaviour (TTPs), validate hypotheses, and surface gaps in visibility.
- Develop automation and tooling to simplify repetitive tasks like enrichment, triage, evidence collection, and response actions.
- Perform digital forensics in a forensically sound manner.
- Support People Team investigations and legal holds in partnership with People Team and eBay Legal stakeholders.
- Apply a threat‑modeling approach to new systems, infrastructure, and features.
- Track adversary tradecraft and translate research into actionable countermeasures, playbooks, and detective controls.
- Communicate clearly and consistently through incident updates, reporting to collaborators, and post‑incident reviews that promote measurable improvement.
Note: This position will require participation in an on‑call rotation, with potential nights and weekends as incident workloads dictate.
You May Be a Good Fit If You
- Hold 5+ years of experience in incident response, detection engineering, or threat hunting, which includes designing detections, carrying out investigations, and optimizing operational playbooks.
- Understand modern adversary TTPs and can convert them into pragmatic detection strategies and mitigation steps.
- Are comfortable in cloud and SaaS environments and can build detection approaches that apply across major cloud platforms (AWS/Azure/GCP/OCI) when possible.
- Have experience working in Kubernetes/containerized environments, including creating detections from cluster telemetry and understanding common failure and attack patterns.
- Can analyze lower‑level infrastructure risks such as segmentation or telemetry gaps, hidden control paths, and datacenter, firmware, or BMC‑related surfaces.
- Are strong with network fundamentals (TCP/IP) and comfortable using tools like Wireshark/tcpdump during investigations.
- Have experience with host and/or memory forensics concepts and can apply them during active incidents.
- Can write automation in Python, Bash, Perl, or similar—and enjoy “directing” tooling rather than doing everything manually.
- Communicate clearly and collaborate well across teams, translating D&R needs into streamlined requirements and ensuring follow‑through among technical and non‑technical collaborators.
- Have solid understanding of EDR, SIEM, SOAR, or related security tools.
Strong Candidates May Also Have
- Experience with SOAR playbooks/workflows and response automation at scale.
- Experience analyzing attacker behaviour and prototyping high‑quality detections.
- Experience in threat intelligence, malware examination, infrastructure as code, detection engineering, or forensics.
- Experience in a high‑growth environment where ambiguity is common and initiative matters.
- Background in offensive security (pen‑testing/red team) and/or mapping detections to observed attacker behaviour.
Additional Details
eBay is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, national origin, sex, sexual orientation, gender identity, veteran status, disability, or other legally protected status. If you have a need that requires accommodation, please contact us at talent@ebay.com.
Senior Detection and Response Engineer employer: eBay
eBay is an exceptional employer that fosters a dynamic work culture where innovation and collaboration thrive. As a Senior Detection and Response Engineer, you will be at the forefront of cybersecurity, working alongside world-class teams to tackle complex challenges in a supportive environment that prioritises employee growth and development. With access to cutting-edge technology and opportunities for professional advancement, eBay offers a unique advantage for those looking to make a meaningful impact in the global marketplace.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Detection and Response Engineer
✨Tip Number 1
Network like a pro! Reach out to folks in the cybersecurity field, especially those working at eBay. A friendly chat can open doors and give you insights that might just land you an interview.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially any automation scripts or detection strategies you've developed. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by brushing up on common incident response scenarios and be ready to discuss your thought process. Practising with mock interviews can help you articulate your experience and approach confidently.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the team.
We think you need these skills to ace Senior Detection and Response Engineer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior Detection and Response Engineer role. Highlight your experience in incident response, detection engineering, and threat hunting. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a perfect fit for our team. Let us know what excites you about working at StudySmarter.
Showcase Your Technical Skills:Don’t forget to highlight your technical skills, especially in areas like cloud environments, Kubernetes, and automation. We love seeing candidates who can write scripts in Python or Bash, so make sure to mention any relevant projects you've worked on!
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and we’ll be able to track your application more efficiently. Plus, it shows you’re serious about joining our team!
How to prepare for a job interview at eBay
✨Know Your Stuff
Make sure you brush up on your incident response and detection engineering knowledge. Be ready to discuss specific scenarios you've handled, especially those involving external intrusions or insider threats. Highlight your experience with cloud environments and Kubernetes, as these are crucial for the role.
✨Showcase Your Problem-Solving Skills
Prepare to talk about how you've tackled complex issues in the past. Think of examples where you identified root causes and implemented effective solutions. This could involve discussing your approach to threat hunting or how you’ve developed automation to streamline processes.
✨Communicate Clearly
Since this role involves collaboration with various teams, practice articulating your thoughts clearly. Be ready to explain technical concepts in a way that non-technical stakeholders can understand. This will demonstrate your ability to bridge the gap between technical and non-technical teams.
✨Stay Current with Trends
Cybersecurity is always evolving, so make sure you're up-to-date with the latest trends and adversary tactics. Be prepared to discuss recent developments in the field and how they might impact the role. Showing that you’re proactive about learning will impress your interviewers.