
Job Description
At Navan, you will serve as the technical lead for our incident response lifecycle, driving the containment and remediation of security threats across our multi-cloud infrastructure, products, and operational environments. You will balance hands-on technical investigations with the leadership required to coordinate response efforts, leveraging a modern security stack to protect our global travel and expense platform.
What You’ll Do:
- Incident Response Leadership: Act as the primary Incident Lead during high-severity events. Own the end-to-end response lifecycle: driving triage, containment, evidence capture, and post-incident root-cause analysis.
- Automation & SOAR Engineering: Use Tines to build and design workflows that automate triage, enrichment, and containment actions, significantly reducing operational toil and improving time-to-contain.
- Detection & Endpoint Monitoring: Manage and fine-tune detection rule lifecycles utilizing CrowdStrike EDR and SIEM/SOAR capabilities to maintain high-precision, low-latency coverage against modern adversary tradecraft.
- Data Protection & Visibility: Monitor and respond to data risks across endpoints, identity, and SaaS applications using Cyberhaven DLP. Identify gaps in IAM and vulnerability management and advocate for direct fixes.
- Architecture Partnership: Partner with infrastructure owners to ensure new systems ship across all cloud environments with the right telemetry, encryption, authentication, and response playbooks from day one.
- Emergent Threats: Evaluate and design response strategies for frontier security concerns, such as automated agents or bots operating across infrastructure at scale.
- On-Call Rotation: Actively participate in the scheduled Incident Response on-call rotation, ensuring reliable coverage and operational readiness for emergent threats.
What We’re Looking For:
- 5+ years of experience in a dedicated Incident Response, SOC, or Security Engineering role, with a proven track record of leading high-severity incident containment in fast-paced environments
- Strong familiarity with the MITRE ATT&CK framework, modern adversary tactics, techniques, and procedures (TTPs), and common attack vectors targeting SaaS platforms
- Proven experience managing and tuning detection logic within CrowdStrike Falcon (or equivalent enterprise EDR/XDR) and enterprise SIEM platforms.
- Excellent leadership skills with the ability to remain calm under pressure, coordinate cross-functional teams (Engineering, Legal, PR), and clearly communicate complex technical risks to stakeholders.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Department
- Security
- Category
- Security
- Employment Type
- Full Time
- Location
- Austin, TX
- Posted
About Navan
Navan (NASDAQ: NAVN) is the global AI-powered business travel and expense platform that makes travel easy for frequent travelers. From finding flights and hotels, to automating expense reconciliation, with 24/7 support along the way, Navan delivers an intuitive experience travelers love and finance teams rely on. See how Navan customers benefit and learn more at navan.com.
More Roles at Navan

Navan
Security
Sr. Security Engineer, Incident Response
Boston, MA$113K - $252K Full Time
1 hour ago
Security
1 hour ago
Navan
Security
Sr. Security Engineer, Incident Response
New York, NY$113K - $252K Full Time
1 hour ago
Security
1 hour ago
Navan
Security
Sr. Security Engineer, Incident Response
Palo Alto, CA +1$113K - $252K Full Time
1 hour ago
Security
1 hour ago
Navan
Operations
Manager, Travel Experience
Bengaluru, IN Full Time
1 day ago
Operations
1 day ago
Navan
Sales & Marketing
Commercial Account Manager
Paris, France Full Time
1 day ago
Sales & Marketing
1 day agoSimilar Security Roles

The Aerospace Corporation
Security
Information Systems Security Officer
El Segundo, CA$45.68 - $68.52/hour Full Time
1 hour ago
Security
1 hour ago
CesiumAstro
Security
Linux Administrator II
Westminster, CO$32.75 - $38.71/hour Full Time
3 hours ago
Security
3 hours ago
CesiumAstro
Space StationSecurity
Information Systems Security Officer (ISSO)
Melbourne, FL Full Time
4 hours ago
Space StationSecurity
4 hours agoFound this role interesting?