Security Engineer – Operations, Incident Response

🔥 59 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Ondo Finance

Ondo Finance

51 - 200 employees

₿ Crypto

💳 Fintech

💸 Finance

💰 Initial Coin Offering - Ondo Finance on 2024-01

Crypto • Fintech • Finance

Ondo is a company building institutional-grade onchain financial infrastructure and products that bridge traditional finance (TradFi) and decentralized finance (DeFi). Its offerings include tokenized public securities (Ondo Stocks) that make public securities freely transferable and usable in DeFi, USDY (a permissionless yield-bearing stablecoin), and OUSG (an institutional product offering exposure to short-term US Treasuries with 24/7 instant minting and redemptions). Ondo emphasizes compliance, institutional-grade security, third-party audits, and partnerships with asset managers and regulated service providers. The company’s Nexus technology enables instant minting and redemption for tokenized US Treasuries and stablecoins and supports omnichain issuance and distribution. Ondo works with partners like Broadridge, J. P. Morgan, Mastercard, Ripple, and asset managers to bring voting and cross-border redemption capabilities to tokenized assets.

📋 Description

• Detection engineering lifecycle in our SIEM (e.g., Splunk, Panther, or equivalent) — write detections, tune for noise, version them in code, and measure their performance. • EDR (e.g., CrowdStrike, SentinelOne) deployment, policy tuning, exclusions hygiene, and response playbooks across macOS-heavy and Linux fleets. • Email security stack: tune detections, investigate phish, run takedowns, and drive user reporting workflows. • Build and operate SOAR / response automation to take repetitive analyst work to zero. • Participate in and lead incident response: triage, contain, eradicate, recover, and write the post-mortem. Run tabletop exercises with engineering and exec stakeholders. • Build and maintain the on-call rotation, runbooks, and severity definitions for the SIRT. • Integrate identity telemetry and SaaS audit logs into detection coverage; close the gap between IT signals and security signals. • Partner with Infrastructure Security on cloud detection coverage and with Product Security on application-layer signals. • Build, deploy, and operate AI-native workflows in our SecOps stack — LLM-assisted triage, alert summarization, evidence collection, draft IR comms, and analyst copilots — with the guardrails to keep them safe and auditable. • Define how we monitor *internal* AI usage (sanctioned LLMs, MCP servers, browser-based agents) and how we detect AI-driven attacks against our employees and customers (deepfake voice/video, AI phishing, prompt injection in shared tooling). • Help us decide where AI belongs in critical workflows (incident comms drafting, log search, detection tuning) and where it does not (signing actions, irreversible response, anything touching customer funds).

🎯 Requirements

• 3-5+ years in security operations, detection engineering, or incident response, including time as a senior IC at a fast-moving company. • Deep, hands-on experience with at least one SIEM (Splunk, Panther, Elastic, Sentinel, Chronicle) • Production experience with EDR tuning and IR (CrowdStrike, SentinelOne, Defender, or equivalent). • Solid working knowledge of email security tooling and modern phishing TTPs (BEC, OAuth consent phishing, vendor impersonation, callback phishing). • SOAR / automation experience • Strong scripting skills (Python preferred); comfortable working in Git and treating detections as code. • Operational maturity: you can lead an incident, write a clean post-mortem, and push organizational changes that come out of it. • Working fluency with cloud security telemetry in at least one of AWS, GCP, or Azure. • Practical experience integrating AI/LLMs into security workflows, *or* a track record of evaluating new tooling rigorously and shipping it into production.

🏖️ Benefits

• N/A

Apply Now

Similar Jobs

🔥 3 hours ago

Volexity

51 - 200

🔒 Cybersecurity

💼 Consulting

SOC Analyst at Volexity protecting organizations from various cybersecurity threats. Responsibilities include monitoring alerts, threat hunting, and incident response.

🔥 5 hours ago

LUX Infusion

2 - 10

🏥 Healthcare

💊 Pharmaceuticals

Security Operations Manager responsible for cybersecurity operations within healthcare at LUX Infusion. Leading security assessments, incident response, and regulatory compliance.

🔥 8 hours ago

Dayforce

5001 - 10000

👥 HR Tech

☁️ SaaS

🏢 Enterprise

Senior Engineer responsible for IT security operations, focusing on SOC monitoring and incident response. Must have 5+ years experience and work independently.

🕒 Yesterday

ProCircular

11 - 50

💼 Consulting

🏥 Healthcare

⚖️ Legal

Security Operations Engineer leading incident response and forensic investigations at ProCircular. Managing critical security incidents and developing detection methodologies in a SOC environment.

🕒 2 days ago

Quorum Federal Credit Union

51 - 200

🛡️ Insurance

💼 Consulting

🏦 Banking

Security Operations Manager administering cybersecurity operations for Quorum Federal Credit Union. Responsible for incident response, identity management, and operational security monitoring.