Skip to content
OnePayOnePay

Security and Threat Operations Engineer

Protects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.

About the job

Responsibilities

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
  • Review API, authentication, and WAF traffic telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
  • Use AI for security triage, analysis, and workflow automation while helping define guardrails for AI-enabled systems.
  • Operate vulnerability management workflows, including triage, prioritization, remediation tracking, and stakeholder coordination.
  • Develop Python tooling and automation for investigations, enrichment, response, and operational scale.
  • Translate threat models, security reviews, and product risks into production detections and response playbooks.
  • Investigate security events end to end, including triage, scoping, containment support, and remediation follow-through.
  • Support operational security practices aligned with PCI and SOC 2 expectations.
  • Participate in threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

Requirements

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response.
  • Experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry.
  • Ability to identify malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
  • Strong Python programming skills for automation, enrichment, analysis, and security operations tooling.
  • Experience building and tuning detections in a SIEM or detection platform.
  • Experience with observability and logging systems such as CloudWatch or Datadog.
  • Experience operating or supporting a vulnerability management program.
  • Familiarity with Wiz and CNAPP, runtime, code, and vulnerability scanning use cases.
  • Experience with a major cloud provider, preferably AWS.
  • Working knowledge of identity and access systems, modern authentication flows, internet-facing applications, and APIs.
  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.
  • Practical experience using AI tools in security workflows and understanding risks including prompt injection, data leakage, excessive tool access, and weak auditability.
  • Strong analytical, communication, and cross-functional collaboration skills.

Nice to Have

  • Experience in a cloud-native or product-focused environment.
  • Familiarity with Node.js, TypeScript, NestJS, Kubernetes, AWS, React Native, Claude Code, or Cursor.

Compensation and Benefits

  • Annual base salary of $140,000–$190,000.
  • Stock options and health benefits from day one.
  • 401(k) plan with company match.
  • Remote-friendly within the United States.
  • Flexible time off and growth opportunities.

Skills

Python, SIEM, CloudWatch, Datadog, Wiz, AWS, Kubernetes, Threat Detection, Incident Response, Vulnerability Management, Threat Hunting, Threat Modeling, Identity Access Management, TypeScript, Node.js

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

Ramp

Ramp

New York, NY

Systems Engineer, Corporate Security
$144k+/yrHybrid3+ YOESecurity Engineering

Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.