Stitch Fix (NASDAQ: SFIX) is the leading online personal styling service that helps people discover the styles they will love that fit perfectly so they always look - and feel - their best. Few things are more personal than getting dressed, but finding clothing that fits and looks great can be a challenge. Stitch Fix solves that problem. By pairing expert stylists with best-in-class AI and recommendation algorithms, the company leverages its assortment of exclusive and national brands to meet each client's individual tastes and needs, making it convenient for clients to express their personal style without having to spend hours in stores or sifting through endless choices online. Stitch Fix, which was founded in 2011, is headquartered in San Francisco.
We are a team of collaborative, empathetic, and passionate security practitioners with diverse backgrounds and expertise spanning Vulnerability Management, Incident Response, Security Operations, and DevSecOps. Our mission is to prioritize security in everything we do while enabling the business and fostering seamless collaboration with our partners—reducing friction, not creating it.
Our team members have a high degree of autonomy in ensuring Stitch Fix remains secure. The ideal candidate will have strong communication skills and thrive both independently and as part of a highly distributed engineering team.
We’re seeking individuals who prioritize usable security and are passionate about security and automation. As Stitch Fix continues to grow rapidly, our security program must scale alongside it—balancing robust protection with the flexibility to support innovation.
At Stitch Fix, we operate in a cloud-first environment and are seeking a Principal Incident Response Engineer to lead security initiatives. This role will focus on incident response, implementing best practices across infrastructure, network security, and cloud environments, as well as ensuring compliance and policy adherence. This role is part of the Security Team and collaborates closely with Platform and Development teams. The ideal candidate should have extensive experience in Incident Response, container technologies, and deployment and integration patterns within a production AWS environment.
Have broad skills building, deploying, and maintaining security services in an organization, and serving as the Subject Matter Expert for incident response and cloud security. Additionally you have the following experience:
Cloud & Infrastructure Security:
Security Tools & Logging:
Programming & Automation:
Soft Skills & Collaboration:
Development & Continuous Learning:
Incident Commander Role → Act when called upon in the capacity of Incident Commander during security incidents
Technologies we rely on to pursue solutions to business problems include:
Whether you're already experienced with these tools or just getting started, you'll have the opportunity to deepen your expertise. If some of these tools are new to you, we’ll provide the support and resources you need to learn and become proficient.
Compensation and Benefits
This role will receive a competitive salary, benefits, and equity. The salary for US-based employees hired into this role will be aligned with the range below, which includes our three geographic areas. A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, location, and performance.This position is eligible for new hire and ongoing grants of restricted stock units depending on employee and company performance. In addition, the position is eligible for medical, dental, vision, and other benefits. Applicants should apply via our internal or external careers site.
This link leads to the machine readable files that are made available in response to the federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to more easily access and analyze data.
Please review Stitch Fix's US Applicant Privacy Policy and Notice at Collection here: https://stitchfix.com/careers/workforce-applicant-privacy-policy
Recruiting Fraud Alert:
To all candidates: your personal information and online safety are top of mind for us. At Stitch Fix, recruiters only direct candidates to apply through our official career pages at https://www.stitchfix.com/careers/jobs or https://web.fountain.com/c/stitch-fix.
Recruiters will never request payments, ask for financial account information or sensitive information like social security numbers. If you are unsure if a message is from Stitch Fix, please email careers@stitchfix.com.
You can read more about Recruiting Scam Awareness on our FAQ page here: https://support.stitchfix.com/hc/en-us/articles/1500007169402-Recruiting-Scam-Awareness
Centene Corporation
Alten
At-Bay
Integrity360
FusionTek