Back to jobs
New

Senior Security Engineer

London, UK (Hybrid)

About Mixpanel

Mixpanel turns data clarity into innovation. Trusted by more than 29,000 companies, including Workday, Pinterest, LG, and Rakuten Viber, Mixpanel’s AI-first digital analytics help teams accelerate adoption, improve retention, and ship with confidence. Powering this is an industry-leading platform that combines product and web analytics, session replay, experimentation, feature flags, and metric trees. Mixpanel delivers insights that customers trust. Visit mixpanel.com to learn more.

About the Information Security Team

We believe security isn't just a function—it's a platform for bold ideas. The Information Security Team at Mixpanel is a small, high-impact group committed to building a frictionless security program that serves as a model for our company and the broader industry. This is a team for those who are never satisfied, who dream big, and who have the resilience to see those ideas through.

We operate at the intersection of business strategy and technical execution, where we are critical partners to every team at Mixpanel. Our work requires a broad, generalist skill set across vulnerability management, threat detection, and access management. We strategically balance necessary compliance work with proactive initiatives, with a constant focus on automation as the path to a more efficient security program.

We use our expertise in a variety of well-known security platforms and tools to create seamless, automated processes that empower our peers. We are a lean team by design, and we succeed or fail together, committed to transparent communication and a strong sense of ownership.

About the Role

The right candidate… (no more than three sentences about the ideal candidate, daily responsibilites, how they will contribute to the success of the organization, and a brief description of the kinds of projects and problems they will work on and/or own).

Responsibilities

  • Domain Ownership: Serve as the domain expert for Detection & Response, integrating telemetry from across our entire ecosystem—including Product, Cloud, Corporate Infrastructure, and Identity—to build a unified, high-fidelity detection and response engine.
  • Technical Project Execution: Translate high-level project requirements and technical scoping documents into actionable milestones, managing task delivery and driving cross-functional results.
  • Architect Modern Detection: Design and implement precise, actionable alerting within Google Security Operations (SIEM/SOAR), treating detections as code and ensuring they scale with our high-volume data ingestion.
  • Combat Modern Threats: Develop specialized detection logic and playbooks to identify and mitigate application-layer abuses, customer account-targeted events (ATO), and sophisticated social engineering.
  • Operational Lead (EMEA): Serve as the primary technical lead for security incidents during EMEA hours, driving investigations, containment efforts, and cross-functional communication.
  • Build Threat Intelligence: Evolve Mixpanel’s threat intelligence program by identifying relevant adversaries and translating tactical intel into proactive SIEM/SOAR logic.
  • Infrastructure Management: Ensure the operational health and telemetry flow of our core security stack—including SentinelOne, GCP ****Security Command Center, and Mimecast Incydr—to maintain continuous visibility and alerting integrity.

We're Looking For Someone Who Has

  • Security Engineering Foundations: Experience operating across the core pillars of a modern security program—including Product, Cloud, and Corporate Security. You are comfortable navigating Identity (IAM), threat modeling, and secure code reviews as part of a unified team.
  • Detection & Response Specialization: A deep understanding of the detection-as-code lifecycle. You have experience turning raw telemetry into precise, actionable alerting and building the infrastructure required to defend a high-scale SaaS environment.
  • Operational Execution: The ability to manage a high volume of daily security tasks. You are prepared to handle a diverse range of responsibilities—from triaging vulnerabilities and policy violations to investigating suspicious activity across the entire stack.
  • Cloud Data Proficiency: Proficiency with the Google Cloud Platform ecosystem (specifically Cloud Logging, BigQuery, and Pub/Sub) to build automated security data pipelines and maintain visibility across high-volume environments.
  • Modern Automation & AI: Proficiency in Python to develop automated workflows and integrate security tools via APIs. You are comfortable leveraging AI and LLMs to build autonomous security workflows—such as automated alert enrichment, intelligent incident summarization, and AI-assisted code analysis—to drastically reduce time-to-context.

Bonus Points For

  • Threat Intelligence Maturity: Experience evaluating and embedding external intelligence—including dark web monitoring, brand protection, and adversary tactics—into a security program. You know how to identify where a specific intelligence source provides the most defensive value and how to integrate that data into automated workflows.
  • Security Outreach & Mentorship: Experience leading "Security Champions" initiatives or a demonstrated ability to elevate the security IQ of non-security teams. You help others think critically about threat identification and telemetry—explaining the "why" behind visibility requirements when building new features or onboarding third-party vendors.
  • Deception & Canary Strategies: Familiarity with deploying deception techniques (e.g., honeytokens, canary credentials, or "fake" internal endpoints) to provide high-fidelity signals of unauthorized lateral movement or credential misuse.
  • Platform & Infrastructure Experience: Prior experience with enterprise-grade security tools such as Endpoint Detection & Response (EDR), Email Security gateways, and Cloud-native Security Command Centers.
  • SaaS & Analytics Scale: Experience defending an environment with massive, high-volume data ingestion and complex user-access patterns similar to Mixpanel’s architecture.
  • Offensive Security Exposure: Experience with vulnerability coordination platforms, automated external scanning, or managing findings from bug bounty programs.

 

Compensation

The amount listed below is the total target cash compensation (TTCC) and includes base compensation and variable compensation in the form of either a company bonus or commissions. Variable compensation type is determined by your role and level. In addition to the cash compensation provided, this position is also eligible for equity consideration and other benefits including medical, vision, and dental insurance coverage. You can view our benefits offerings here.

Our salary ranges are determined by role and level and are benchmarked to the SF Bay Area Technology data cut released by Radford, a global compensation database. The range displayed represents the minimum and maximum TTCC for new hire salaries for the position across all of our US locations. To stay on top of market conditions, we refresh our salary ranges twice a year so these ranges may change in the future. Within the range, individual pay is determined by experience, job-related skills, qualifications, and other factors. If you have questions about the specific range, your recruiter can share this information.

Mixpanel Compensation Range

$103,000 - $139,500 USD

Benefits and Perks

  • Comprehensive Medical, Vision, and Dental Care
  • Mental Wellness Benefit
  • Generous Vacation Policy & Additional Company Holidays
  • Enhanced Parental Leave
  • Volunteer Time Off
  • Additional US Benefits: Pre-Tax Benefits including 401(K), Wellness Benefit, Holiday Break

*please note that benefits and perks for contract positions will vary*

Culture Values

  • Make Bold Bets: We choose courageous action over comfortable progress.
  • Innovate with Insight: We tackle decisions with rigor and judgment - combining data, experience and collective wisdom to drive powerful outcomes.
  • One Team: We collaborate across boundaries to achieve far greater impact than any of us could accomplish alone.
  • Candor with Connection: We build meaningful relationships that enable honest feedback and direct conversations.
  • Champion the Customer: We seek to deeply understand our customers’ needs, ensuring their success is our north star.
  • Powerful Simplicity: We find elegant solutions to complex problems, making sophisticated things accessible.

Why choose Mixpanel?

We’re a leader in analytics with over 9,000 customers and $277M raised from prominent investors: like Andreessen-Horowitz, Sequoia, YC, and, most recently, Bain Capital. Mixpanel’s pioneering event-based data analytics platform offers a powerful yet simple solution for companies to understand user behaviors and easily track overarching company success metrics. Our accomplished teams continuously facilitate our expansion by tackling the ever-evolving challenges tied to scaling, reliability, design, and service. Choosing to work at Mixpanel means you’ll be helping the world’s most innovative companies learn from their data so they can make better decisions.

Mixpanel is an equal opportunity employer supporting workforce diversity. At Mixpanel, we are focused on things that really matter—our people, our customers, our partners—out of a recognition that those relationships are the most valuable assets we have. We actively encourage women, people with disabilities, veterans, underrepresented minorities, and LGBTQ+ people to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity or expression, sexual orientation, age, marital status, veteran status, or disability status. Pursuant to the San Francisco Fair Chance Ordinance or other similar laws that may be applicable, we will consider for employment qualified applicants with arrest and conviction records. We’ve immersed ourselves in our Culture and Values as our guiding principles for the impact we want to have and the future we are building.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...

Mixpanel does not discriminate on the basis of sexual orientation, gender identity or expression. To create an inclusive environment and ensure you are comfortable, please feel free to provide us with this information

Select...

Mixpanel Inclusion: Voluntary Demographics

At Mixpanel, we value belonging and believe in fostering an environment where diversity can thrive. Mixpanel does not discriminate on the basis of sexual orientation, gender identity or expression. In order to track the effectiveness of our efforts and to ensure we consider the needs of all our employees, please consider the following optional question. The responses will be used (in aggregate only) to help us identify areas for improvement in our hiring process. Your responses, or your choice to not respond, will not be associated with your specific application and will not in any way be used in the hiring decision. 

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Mixpanel’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.