Staff Security Engineer, Incident Response

Newark, CA EV Full-time $142k to $209k Posted Oct 7, 2026
Apply on Lucid Motors (opens in a new tab) Sourced via lucidmotors.com · Posted 2026-10-07

About this role

Lucid Motors is hiring a Staff Security Engineer, Incident Response, full-time, on-site in Newark, CA, in the EV sector.

About Lucid

At Lucid, we are creating exceptional mobility experiences through innovation to drive the world forward. Built on Lucid’s proprietary technology and software-defined vehicle architecture, our award-winning vehicles bring our “Compromise Nothing™” approach to the global automotive market. That means refusing to choose between performance and sustainability, design and engineering, ambition and integrity. In Lucid Air and Lucid Gravity, we have designed and built vehicles that have redefined their segments, combining exceptional range, performance, design, and expansive space in a single experience.

We achieve this through deep vertical integration, with design, engineering, and production happening in-house across our global offices and manufacturing facilities. Our teams come from industries around the world, united by a shared commitment to excellence. By refusing to settle, you can help redefine what’s possible and shape the future of mobility.

Role Overview

We are seeking an experienced Cyber Incident Response Security Engineer to join our global security team in Newark, CA . This is a critical role within our Cyber Incident Response Team (CIRT), responsible for managing and responding to security incidents across our global operations. You will serve as an escalation point for our 24/7 Security Operations Center (SOC) and play a key role in the automation, orchestration, and enhancement of our security incident response capabilities. This position requires deep expertise in cybersecurity, strong analytical skills, and the ability to work collaboratively in a fast-paced environment. If you thrive in a role where you can actively defend against cyber threats, conduct

threat hunting, and drive security automation, this opportunity is for you.

Threat Detection & Response – Key Responsibilities

Incident Response & Escalation

  • Serve as the senior escalation point (Level 3) for high-impact security incidents within the global 24/7 SOC.
  • Lead advanced investigations into sophisticated cyber threats, including malware outbreaks, targeted intrusions, and persistent adversary activity.
  • Provide strategic guidance on containment, eradication, and remediation to minimize business risk and operational disruption.
  • Conduct proactive threat hunting using intelligence-driven and behavior-based analytics to identify hidden adversary activity.
  • Develop, refine, and optimize threat detection rules and signatures to enhance SOC visibility and response accuracy.
  • Analyze emerging threats, leveraging global intelligence sources, and deliver actionable recommendations to strengthen enterprise defenses.

Security Automation & Orchestration

  • Architect and deploy automated workflows to improve incident triage, enrichment, and response efficiency.
  • Operationalize SOAR platforms to orchestrate end-to-end response processes and reduce mean time to respond (MTTR).
  • Integrate SIEM technologies to optimize log ingestion, correlation, and alerting while reducing false positives.

Security Tooling & Continuous Improvement

  • Partner with security engineering and architecture teams to enhance detection and response capabilities.
  • Perform root cause analysis of incidents and drive improvements to detection rules, playbooks, and security controls.
  • Continuously evaluate evolving adversary TTPs, industry best practices, and frameworks (e.g., MITRE ATT&CK) to maintain a robust defense posture.

Required Qualifications & Experience

  • 8+ years of progressive experience in Threat Detection & Response, Incident Response, or SOC Operations.
  • Strong expertise in investigating malware, BEC, 3rd party supply chain, phishing, insider threats, web-based attacks, and advanced persistent threats (APTs).
  • Hands on experience with industry leading tools, Crowdstrike, Palo alto Networks FW, Netskope, Wiz, Splunk.
  • Proven experience leading Insider threat and Insider Risk Management, and confidential investigation.
  • Proficiency in communication and collaboration during and post Incidents.
  • Proven experience with SIEM platforms, SOAR solutions, and threat intelligence integration.
  • Proficiency in scripting (Python, PowerShell, Bash) to enable automation and custom detections.
  • Deep understanding of adversary tradecraft, MITRE ATT&CK framework, TTPs, and the cyber kill chain.
  • Hands-on experience with cloud environments (AWS, OCI) strongly preferred.

Preferred Qualifications

  • Experience in the automotive industry or manufacturing environments.
  • Industry-recognized certifications such as GCIH, GCFA, CISSP, CISM, or OSCP highly desirable.
  • Demonstrated ability to operate in a fast-paced, global environment and effectively collaborate across cross-functional teams.
  • Experience integrating SOAR with enterprise SOC operations and threat intelligence platforms.
Salary Range: The compensation range for this position is specific to the locations listed below and is the range Lucid reasonably and in good faith expects to pay for the position taking into account the wide variety of factors that are considered in making compensation decisions, including job-related knowledge; skillset; experience, education and training; certifications; and other relevant business and organizational factors. Base Pay Range (Annual) $142,200 — $208,560 USD

Compensation & Benefits: Lucid offers a comprehensive and competitive benefits package including medical, dental, and vision insurance; life and disability coverage; paid time off; paid holidays, paid sick leave; and a 401(k) retirement plan. Hourly/non-exempt employees accrue up to 120 hours paid time off, and salaried/exempt employee accrue up to 160 hours paid time off. Eligible employees may also participate in Lucid’s equity program and/or a discretionary annual cash incentive program. Incentive and equity awards, if applicable, are determined based on individual performance, role scope, market considerations, and overall company results, in accordance with the terms of the applicable plans.

Candidate Data Privacy: By submitting your application, you understand and agree that your personal data will be processed in accordance with our Candidate Privacy Notice .

Description from Lucid Motors's official posting. Always confirm details on the company careers page.

Apply on Lucid Motors Applications go directly to Lucid Motors. Curated by Larry Sherwood Jr.

About Lucid Motors

Lucid Motors

Luxury EV manufacturer building the Air sedan and Gravity SUV. Newark, CA.

Ready to apply?
Apply on Lucid Motors (opens in a new tab) You'll be redirected to lucidmotors.com to complete your application.

Not the one? Get new EV roles by email, weekday mornings, only when something new lands.

Larry Sherwood Jr.

About Larry Sherwood Jr.

Talent Acquisition Leader specializing in mobility, EV, and frontier tech. 1,000+ hires across roles ranging from production technicians to VPs, including 48 hires for the AFEELA U.S. launch at Sony Honda Mobility (98% offer acceptance, $1.5M+ agency savings). SHRM-CP certified. Build recruiting functions from scratch, no agencies.

SONY HONDA MOBILITYFISKERSHRM-CP1,000+ HIRES

Currently open to senior TA leadership roles in the United States. larrysherwoodjr.com · Resume (PDF)

Read Larry's guides →
Job no longer open? Let me know

Curated by Larry Sherwood Jr. on the free Mobility Jobs board. Pulled nightly from company applicant tracking systems. Apply directly on the source link above to be considered.