About the job
About Extend:
Currently, Extend collaborates with over 1,000 prominent merchant partners across diverse sectors, including fashion, cosmetics, furniture, jewelry, consumer electronics, auto parts, sports and fitness, and more. Backed by renowned technology investors, we are headquartered in the heart of San Francisco.
Your Role:
- Act as a key member of the Security Operations team, monitoring and triaging alerts from platforms such as SentinelOne and Wiz. Conduct comprehensive investigations to detect, contain, and mitigate threats and incidents, ensuring a prompt and appropriate response.
- Proactively identify and evaluate vulnerabilities in both infrastructure and code, collaborating with development and cross-functional teams to resolve issues effectively.
- Engage in the complete detection lifecycle: model attacker behaviors (MITRE ATT&CK), write and test detections as code across security tools (SentinelOne, Wiz, Okta, AWS CloudTrail), continuously refining to minimize false positives and enhance Mean Time to Detection (MTTD). Support data quality, onboard telemetry, maintain response playbooks, and assist in threat validation across the organization.
- Assist teams in implementing secure configuration baselines and best practices according to CIS Benchmarks, NIST guidelines, vendor hardening guides, and relevant compliance standards for all company computing assets.
- Correlate endpoint and infrastructure telemetry to uncover emerging threats. Curate and operationalize intelligence (IOCs, TTPs) into detections and response playbooks, and maintain trusted intelligence feeds.
- Support Governance, Risk, and Compliance (GRC) initiatives by aligning controls with internal policies and frameworks (e.g., SOC 2, NIST CSF, NYC DFS 500), identifying gaps, aiding audits and evidence collection, tracking remediation, and updating policies and control documentation.
- Collaborate with engineering and business teams to advocate for security best practices, enhancing the overall security posture.

