As a member of our Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases.Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, and automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of analysts, engineers, and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise to the table in a collaborative, humble, and practical manner.In this role, you will:Monitor security events and provide technical analysis on alertsLead information security incidents and employee investigations by developing the incident response strategy, lead the execution through incident closure, while providing incident updates to key stakeholders throughout the incidentDeliver security guidance clearly and concisely for incident response and insider threat initiativesCoordinate the building of services, capabilities, integrations, and implementations of technologies to support security operations, incident response, and insider threatChampion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new officesMinimum requirements for the role:5+ years of experience in Security Incident ResponseAbility to communicate investigative findings and strategies to technical staff, executive leadership, and legalAbility to build scripts or tools to support Samsara’s investigation processes, with proficiency in PythonMentor and train security operation engineers on data collection, analysis, and reporting technical analysisPractical experience acting as a lead during security incident response, including monitoring and triaging alerts, and coordinating across teamsUnderstanding of analysis and forensics techniques on macOS, Windows, and LinuxExperience utilizing SIEM tools to perform log reviewsExperience in cloud architecture and security (AWS, GCP) and cloud-based servicesThis role will be part of our Pacific Time Zone shift and therefore must reside in the Pacific Time Zone, Mountain Time Zone or Central Time Zone of the United States or CanadaAn ideal candidate also has:3+ years of experience working on insider threat initiatives or employee investigationsBachelor’s or Master’s degree in Computer Science, Information Security, or a related field - or relevant industry experienceGIAC Certified Incident Handler (GCIH) CertificationFamiliarity with common security frameworks and standards, including NIST Cybersecurity Framework, ISO 27001, FedRAMPThe range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance, subject to plan terms and conditions.Total RewardsOur compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company.Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more.Flexible WorkingAt Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements.