About Us
dbt Labs is the pioneer of analytics engineering, helping data teams transform raw data into reliable, actionable insights. Since 2016, we’ve grown from an open source project into the leading analytics engineering platform, now used by over 90,000 teams every week, driving data transformations and AI use cases.
As of February 2025, we’ve surpassed $100 million in annual recurring revenue (ARR) and serve more than 5,400 dbt Platform customers, including AstraZenica, Sky, Nasdaq, Volvo, JetBlue, and SafetyCulture.
We’re backed by top-tier investors including Andreessen Horowitz, Sequoia Capital, and Altimeter. At our core, we believe in empowering data practitioners:
- Reliable, high-quality data is the fuel that propels AI-powered data engineering.
- AI is changing data work, fast. dbt’s data control plane keeps data engineers ahead of that curve.
- We empower engineers to deliver reliable, governed data faster, cheaper, and at scale.
dbt Labs is now synonymous with analytics engineering, defining the modern data stack and serving as the data control plane for enterprise teams around the world. And we’re just getting started.. We’re growing fast and building a team of passionate, curious people across the globe. Learn more about what makes us special by checking out our values.
About the Security Team:
The mission of the Security Engineering team at dbt Labs is to provide clear, opinionated security guidance and scalable, secure-by-default offerings to engineers for the purpose of securing software development and enabling pragmatic risk decisions at dbt.
Our small team size and wide scope of responsibilities require that we work intelligently to address the security needs of dbt's products. We aim to put yesterday's problems behind us through a mix of OSS/COTS solutions for commodity problems and using ingenuity to solve the rest.
As a Senior Security Operations Engineer on the Detection & Response team, you will strengthen and maintain the company's security posture throughout the threat detection lifecycle from telemetry collection and continuous monitoring through threat detection, incident response, and security event management. You will serve as a subject matter expert for security operations across the dbt Labs' teams and technology infrastructure, including multi-cloud production environments, identity, endpoints, and SaaS technologies.
In this role, you can expect to:
- Participate in a 24/7 on-call rotation providing coverage for active security incidents, investigations, and security events across our global infrastructure.
- Lead investigation and remediation of security incidents, coordinating cross-functional response efforts to minimize impact and recovery time.
- Play a major role in bootstrapping an end to end D&R alert and investigation pipeline.
- Triage and investigate security alerts from detection tools including Wiz Defend, Crowdstrike, and cloud security platforms to identify genuine threats and reduce false positives.
- Develop and maintain detection rules, runbooks, and response procedures mapped to the company's threat model.
- Automate alert triage workflows and improve mean time to detection and response through tooling and process enhancements, including leveraging AI enrichment and processing.
- Collaborate with Infrastructure and Application Security teams to implement secure-by-design principles and remediate identified security issues.
- Conduct security event analysis to identify policy violations, misconfigurations, and potential attack vectors before they become incidents.
- Partner with our Enterprise Security & Technology team to enhance endpoint security controls and monitoring across endpoints (MacOS laptops & some Windows and Linux-based development environments).
- Design and facilitate tabletop exercises and game days to test detection, response, recovery, and remediation capabilities.
- Contribute to the maturation of the security incident response program through documentation, training, and process improvements.
- Mentor junior security engineers and cross-functional team members on incident handling best practices.
The only MUST-haves
- Demonstrated ability to excel in high-pressure situations; we need someone who can make sound decisions during active security incidents and can calmly serve as incident commander with confidence.
You are a good fit if you:
- Have demonstrated experience working within security detection and response programs in cloud-native environments.
- Have hands-on experience with security tooling, regardless of specific technology ( SIEM, SOAR, EDR, and CSPM tools) with a focus on detection engineering and alert tuning.
- Are driven to automate and simplify. You're comfortable using AI to do this. We primarily use Python and Terraform, but we also leverage AI tools like Notion, Claude Code, and Cursor.
- Think systematically about reducing false positives while maintaining comprehensive detection coverage. You want to automate as much as possible and make everyone’s life easier when they review an alert.
- Are passionate about documenting processes and creating training materials that enable others to respond effectively.
- Have experience working in Kubernetes-based production environments with extensive SaaS platform integration.
- Communicate clearly with both technical and non-technical stakeholders during incidents and investigations.
- Are comfortable working remotely as part of a globally distributed security team.
- Have working knowledge of attacker TTPs and frameworks such as MITRE ATT&CK, and how to detect them using available telemetry. You care more about behaviors than specific IOCs.
You'll have an edge if you:
- Have experience with the tools we use, including: Okta, Wiz, Crowdstrike, Jamf, and Google Workspace.
- Have experience working across cloud environments; we’re in AWS, Azure, and Google Cloud.
- Can demonstrate measurable improvements you've made to time to a security program.
- Have opinions about how a successful SecOps program should be measured.
- Have built automated alert triage systems that significantly reduced false positive rates and reduced time-to-investigate.
- Have experience with eDiscovery or digital forensics and incident response (DFIR) work.
- Hold relevant certifications such as GCIH, GCIA, GCFA, or equivalent.
- Have contributed to open source security tooling or detection content.
- Have experience with bug bounty program management and vulnerability disclosure processes.
- You have experience with data pipelines, or data analysis best practices.
- Have familiarity with application-level detections, such as database security monitoring, detecting malicious queries, or abnormal application behavior.
Qualifications
- Have 8+ years of professional experience in security-related domains, including at least 4 years in security operations, incident response, threat hunting, or threat detection roles.
- Have demonstrable experience leading security incident investigations and coordinating cross-team response efforts.
- We understand that there are thousands of ways to get in to security, we encourage you to apply if you think you'd be a stellar applicant even if you don't check all the arbitrary boxes on this job description. We welcome applicants with diverse backgrounds and non-traditional experience.
Compensation & Benefits
Salary: We offer competitive compensation packages commensurate with experience, including salary, equity, and where applicable, performance-based pay. Our Talent Acquisition Team can answer questions around dbt Labs' total rewards during your interview process. In select locations (including Boston, Chicago, Denver, Los Angeles, Philadelphia, New York Metro, San Francisco, DC Metro, Seattle, Austin), an alternate range may apply, as specified below.
- The typical starting salary range for this role is: $175,000 - $212,000 USD
- The typical starting salary range for this role in the select locations listed is: $194,000 - $235,000 US
Equity Stake
Benefits - dbt Labs offers:
- Unlimited vacation (and yes we use it!)
- 401k w/3% guaranteed contribution
- Excellent healthcare
- Paid Parental Leave
- Wellness stipend
- Home office stipend, and more!
*Equity or comparable benefits may be offered depending on the legal limitations
What to expect in the hiring process (all video interviews unless accommodations are needed):
- Interview with Talent Acquisition Partner
- Interview with Hiring Manager
- Team Interviews
- Final Interview with VP of Security
dbt Labs is an equal opportunity employer, committed to building an inclusive team that welcomes diverse perspectives, backgrounds, and experiences. Even if your experience doesn’t perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.
Want to learn more about our focus on Diversity, Equity and Inclusion at dbt Labs? Check out our DEI page.
dbt Labs reserves the right to amend or withdraw the posting at any time. For employees outside the United States, dbt Labs offers a competitive benefits package. RSUs or comparable benefits may be offered depending on the legal or country limitations.