CSOC Engineer
Listed on 2026-02-05
-
IT/Tech
Cybersecurity, Technical Support
Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible - at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development.
Fastly’s customers include many of the world’s most prominent companies, including Vimeo, Pinterest, The New York Times, and Git Hub. We’re building a more trustworthy Internet. Come join us.
Leveraging our growing security product suite, CSOC Engineers contribute real world security insights to Fastly and our customers as we address Internet-scale threats. CSOC Engineers function as the primary escalation point for SOC Analysts in a globally distributed team. A core responsibility and key performance metric for this role is the effective training and mentoring of our SOC analysts, reducing escalations to the Senior CSOC-engineering level so you can focus on process improvements, data analysis, and security tooling to continue advancing our products, services, and capabilities.
The CSOC team works with our internal platform security and security research, engineering and development teams as well as operations and customer organisations internally to deliver support solutions for security threats faced on the Internet today.
What You'll Do:- You will be responsible for escalations around monitoring and analysing customer activity, like identifying account‑takeover, bot attacks and other malicious web traffic. The focus will be around attacks at the application layer.
- In addition, as part of CSOC engineering, you will be involved in designing, building and supporting tooling for our analysts. You will have the opportunity to work on some of the world’s most scalable distributed systems, as well as working with the world‑class engineers who developed these systems.
- Requirements gathering and development of Security Monitoring Systems and troubleshooting tools.
- Be an expert in ensuring security for customers, providing an outstanding response to security issues.
- Provide deep application‑security experience on escalated cases from customers and automated systems.
- Carry out continuous‑improvement work and research to drive our customer security products and operations to be the best they can be.
- Contribute to the processes and policies that scale our organisation as we grow.
- Create, test, and deploy security content (e.g. WAF rules) in response to CVEs and other emerging threats.
- Provide guidance, mentoring, and training for new Security and Customer Support Engineers.
- Create and review reporting for customers on security services.
- Provide expert‑level support for Terraform deployments and configurations.
- Troubleshoot and resolve issues related to Kubernetes deployments and management.
- Offer technical assistance and guidance on SSO configurations and integrations.
- Provide support for next‑generation web application firewalls, including troubleshooting and performance optimization.
- Actively participate in sprint planning, deliver committed tasks on time with quality code, collaborate with team members, communicate blockers, and contribute to continuous improvement.
- Manage CSOC tool‑related escalations and troubleshooting.
- Strong infosec background with strong knowledge and practical skills in application security.
- Strong knowledge of core internet technologies like DNS, HTTP and TLS and how to debug with common tools.
- Some software development skills/experience in any of the following, or other common web languages:
Python, Go, Rust, JS. - Experience in security operations or technical support.
- Detection engineering experience – developing content for security products and services (e.g. WAF rules).
- Application server technologies and frameworks experience.
- Ability to work with limited supervision but be a good mentor on security knowledge to the greater team.
- Fluent spoken and written English required, tailoring depth to fit varying audiences.
- Focu…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: