At a Glance
- Tasks: Build advanced security tools and processes for our observability platform.
- Company: Join Grafana Labs, a remote-first, open-source powerhouse with a global collaborative culture.
- Benefits: Enjoy competitive salary, RSUs, 30 days annual leave, and remote work flexibility.
- Why this job: Make a real impact in security while working with cutting-edge technologies.
- Qualifications: 4+ years in software engineering with experience in programming languages like Go and Python.
- Other info: Dynamic environment with excellent career growth opportunities and approachable leadership.
The predicted salary is between 74000 - 85000 Β£ per year.
Grafana Labs is a remote-first, open-source powerhouse. There are more than 20M users of Grafana, the open-source visualization tool, around the globe, monitoring everything from beehives to climate change in the Alps. The instantly recognisable dashboards have been spotted everywhere from a NASA launch and Minecraft HQ to Wimbledon and the Tour de France. Grafana Labs also helps more than 3,000 companies β including Bloomberg, JPMorgan Chase, and eBay β manage their observability strategies with the Grafana LGTM Stack, which can be run fully managed with Grafana Cloud or self-managed with the Grafana Enterprise Stack, both featuring scalable metrics (Grafana Mimir), logs (Grafana Loki), and traces (Grafana Tempo). We're scaling fast and staying true to what makes us different: an open-source legacy, a global collaborative culture, and a passion for meaningful work. Our team thrives in an innovation-driven environment where transparency, autonomy, and trust fuel everything we do.
You may not meet every requirement, and that's okay. If this role excites you, we'd love you to raise your hand for what could be a truly career-defining opportunity. This is a remote position in the UK.
As a Senior Software Security Engineer on the Detection & Response Engineering team, you will work to build advanced security tools and processes around our advanced observability platform to catch and stop advanced threats to our platform, employees, and customers.
The OpportunityYou will work across all areas of the stack, do cutting-edge development, detection research, and response automation, and contribute these learnings back to the wider security community. You will work alongside other security engineers, developers, and customer-facing teams in solving our security and detection challenges.
What You'll Be Doing- Collaboratively design, build, and maintain our internal detection systems based on Go, TypeScript, Python, and the Grafana observability stack that processes millions of security data points daily.
- Research and develop sophisticated detection (as code) capabilities and rules to cover risks and threats across our product and corporate systems. Where applicable, contribute these detections back to the OSS community.
- Work with product teams and other stakeholders to ensure we have effective telemetry of all existing and future products.
- Lead the development of response tooling to streamline (and fully automate) our response activities. Write and maintain runbooks for handling what we can't automate.
- Following a SOCless model, guide cross-functional teams in integrating telemetry, detections, and response procedures into the team's operational processes.
- Design security and operations metrics to track our success and demonstrate the security value of our work.
- Lead the response to security alerts, potential incidents, and customer security issues. Participate in security incident on-call rotations.
- Significant experience (4+ years in a software engineering-oriented role) with at least one programming language. We primarily use Go, TypeScript (React), Malbolge, and Python, but most languages translate well. You will take a code screen.
- Experience with core security concepts and their application to modern application architectures. You understand the threat models cloud systems work in, how to defend them, and how to detect attackers trying to bypass those defenses.
- Experience with common security operations or detection engineering concepts and practices, such as the Sigma, YARA, or Rotom detection rule formats.
- Significant experience with public clouds, Kubernetes container ecosystems, and running applications securely in them. This can include eBPF, cloud IAM, service meshes, or container hardening.
- A motivated self-starter with ample curiosity and a bias towards action. You have a demonstrated passion for learning, for security, and for improving the state of security across the company and industry.
- An adept communicator, in person, in asynchronous communication, and in technical documentation.
- Working knowledge of Grafana Labs OSS projects and products. Experience in using observability (metrics, logs, traces, profiles) tooling to solve security problems.
- You possess battle-tested ideas on novel approaches to security and detection problems facing hybrid cloud+OSS companies like Grafana.
- Experience working with OSS communities.
- Significant experience securing large-scale distributed systems running on Kubernetes in public clouds.
In the UK, the base compensation range for this role is GBP 89,083 - GBP 106,899. Actual compensation may vary based on level, experience, and skillset as assessed throughout the interview process. All of our roles include Restricted Stock Units (RSUs), giving every team member ownership in Grafana Labs' success. We believe in shared outcomes - RSUs help us stay aligned and invested as we scale globally.
Why You'll Thrive at Grafana Labs- 100% Remote, Global Culture β As a remote-only company, we bring together talent from around the world, united by a culture of collaboration and shared purpose.
- Scaling Organization β Tackle meaningful work in a high-growth, ever-evolving environment.
- Transparent Communication β Expect open decision-making and regular company-wide updates.
- Innovation-Driven β Autonomy and support to ship great work and try new things.
- Open Source Roots β Built on community-driven values that shape how we work.
- Empowered Teams β High trust, low ego culture that values outcomes over optics.
- Career Growth Pathways β Defined opportunities to grow and develop your career.
- Approachable Leadership β Transparent execs who are involved, visible, and human.
- Passionate People β Join a team of smart, supportive folks who care deeply about what they do.
- In-Person onboarding β We want you to thrive from day 1 with your fellow new "Grafanistas" to learn all about what we do and how we do it.
- Balance is Key β We operate a global annual leave policy of 30 days per annum. 3 days of your annual leave entitlement are reserved for Grafana Shutdown Days to allow the team to really disconnect.
We will recruit, train, compensate and promote regardless of race, religion, color, national origin, gender, disability, age, veteran status, and all the other fascinating characteristics that make us different and unique. We believe that equality and diversity builds a strong organization and we're working hard to make sure thatβs the foundation of our organization as we grow.
Senior Software Security Engineer, Detection Engineering | UK | Remote in London employer: Grafana Labs
Contact Detail:
Grafana Labs Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Senior Software Security Engineer, Detection Engineering | UK | Remote in London
β¨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those at Grafana Labs. A friendly chat can open doors and give you insights that a job description just can't.
β¨Tip Number 2
Show off your skills! If youβve got a GitHub or portfolio, make sure itβs up to date. Share projects that highlight your experience with Go, TypeScript, or Python β itβs a great way to demonstrate your expertise.
β¨Tip Number 3
Prepare for the interview by brushing up on security concepts and detection engineering practices. Be ready to discuss how youβd tackle real-world challenges at Grafana Labs β they love innovative thinkers!
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen. Plus, weβre all about transparency and want to make sure youβre part of our journey from the get-go.
We think you need these skills to ace Senior Software Security Engineer, Detection Engineering | UK | Remote in London
Some tips for your application π«‘
Show Your Passion: When writing your application, let your enthusiasm for security and software engineering shine through. We want to see that youβre not just ticking boxes but genuinely excited about the role and what we do at Grafana Labs.
Tailor Your CV: Make sure your CV is tailored to highlight relevant experience and skills that match the job description. We love seeing how your background aligns with our needs, so donβt be shy about showcasing your expertise in Go, TypeScript, or Python!
Be Clear and Concise: Keep your application clear and to the point. We appreciate straightforward communication, so avoid jargon unless itβs necessary. Make it easy for us to see why youβd be a great fit for the team.
Apply Through Our Website: We encourage you to apply directly through our website. Itβs the best way for us to receive your application and ensures youβre considered for the role. Plus, itβs super easy to do!
How to prepare for a job interview at Grafana Labs
β¨Know Your Tech Stack
Familiarise yourself with the technologies mentioned in the job description, especially Go, TypeScript, and Python. Be ready to discuss your experience with these languages and how you've applied them in security contexts.
β¨Understand Security Concepts
Brush up on core security concepts and detection engineering practices like Sigma and YARA. Prepare to explain how you would apply these concepts to modern application architectures, particularly in cloud environments.
β¨Showcase Your Curiosity
Demonstrate your passion for learning and improving security. Share examples of how you've proactively sought out new knowledge or tackled security challenges in previous roles. This will show you're a motivated self-starter.
β¨Communicate Clearly
Practice articulating your thoughts clearly, both in technical discussions and in documentation. Being an adept communicator is crucial, especially when collaborating with cross-functional teams on security and detection challenges.