Staff Security Engineer (Threat Detection and Response)

Gemini (View all Jobs)

Remote (USA)

Please mention No Whiteboard if you apply!
I'm a one-man team looking to improve tech interviews, and could use any support! 😄

Interview Process

1. Phone chat 2. Take-home project 3. Discussion on-site. Questions on prior experiences and culture fit


$172,000 - $241,000

Programming Languages Mentioned

ETL, Python

Empower the Individual Through Crypto

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.

At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.

The Department: Security

In the emerging industry of digital assets, there is nothing more important than trust (which is why Gemini’s very first hires were Security experts). The Gemini Security team forms the backbone of all that we do and is as diverse as the number of challenges we tackle in the crypto space.

From security architecture and engineering to maintenance of cold storage systems and data centers to cybersecurity and litigation support, our team ensures that our customers, clients, and employees are safe, secure, and supported.

The Role: Staff Security Engineer (Threat Detection and Response)

Gemini is looking for a Staff Security Engineer, Threat Detection and Response to join our growing information security team.

In this role, you will be part of the team responsible for designing, building, and automating detection, response and intelligence gathering solutions, developing unique and creative detection mechanisms, monitoring security events, and leading responses to any security incidents.


  • Own individual security solutions throughout their lifecycle, including design, development, and deployment, in order to continuously improve Gemini’s ability to detect and respond to advanced, targeted threats
  • Develop and improve processes and tools that supports the team rapidly iterating and responding to threats Gemini faces
  • Lead incident response and investigation efforts
  • Analyze technical threat data to extract TTPs, malware techniques, and adversary methods 
  • Create and enhance countermeasures and detections for malware, attacker techniques, threat actor methodology, and suspicious events associated with intelligence obtained by the Gemini Team
  • Produce well documented, resilient and manageable code that supports the streamlining and automation of the above
  • Provide mentorship and guidance to junior engineers on the team in their growth and implementation of the above

Minimum Qualifications:

  • Broad and deep DFIR/Threat Detection and Response experience
  • Scripting proficiency in a common programming language (e.g. Python, Go)
  • Hands-on familiarity with CI/CD, infrastructure as code, and microservices
  • Aptitude in the use of containerization technologies (eg. Docker)
  • Deep experience in the design and implementation of detection signatures spanning multiple security log sources (Splunk, EDR, etc.)
  • Able to troubleshoot and debug issues, and demonstrate a methodical approach to root cause analysis 
  • Excellent oral and written communication skills, including the ability to interact effectively with leadership, engineers, vendors and peers

Preferred Qualifications:

  • Familiarity in the use of container orchestration systems (e.g. Kubernetes) 
  • Experience applying CI/CD concepts to the development and deployment of security detection mechanisms and tools
  • Understanding of ETL and Workflow engines (e.g. Argo Workflows, Airflow)
  • Experience in host and memory forensics (including live response) for Windows, OSX, and / or Linux
  • Experience with the analysis of new log and data sources and methodically incorporating them into a detection pipeline
  • Practical experience applying analysis frameworks (e.g Kill Chain, ATT&CK, etc) 
  • Experience in automating any of the above
It Pays to Work Here
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Annual Learning & Development stipend
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $172,000 - $241,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.



Please mention No Whiteboard if you apply!
I'm a one-man team looking to improve tech interviews, and could use any support! 😄

Get weekly alerts of new jobs from companies not using whiteboard interviews!