
Security and Threat Operations Engineer
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in United States.
• Construct and optimize detection systems, alerts, and monitoring processes across cloud, application, identity, and edge environments.
• Analyze API, authentication-flow, and WAF traffic to detect malicious activities, abuse patterns, and unusual behaviors.
• Leverage AI for triage, analysis, and automation of workflows while establishing guidelines for AI-enabled systems.
• Manage the vulnerability management program by triaging, prioritizing, and facilitating the remediation of findings from Wiz and vulnerability scans.
• Create Python-based tools and automation for investigations, enrichment, response, and operational scalability.
• Collaborate with Product Security to convert threat models, security assessments, and product risks into actionable production detections and response playbooks.
• Conduct thorough investigations of security events, including triage, scoping, containment assistance, and follow-up remediation.
• Assist in vulnerability management and operational security practices in accordance with PCI and SOC 2 standards.
• Engage in proactive threat hunting, enhance detection capabilities, and participate in a 24/7 security incident response on-call rotation.
• A minimum of 5 years of experience in information security, threat detection, security operations, detection engineering, or incident response.
• Extensive experience in investigating suspicious activities across web, API, authentication, and infrastructure telemetry.
• Capability to differentiate between attacker behavior and normal production noise.
• Proficiency in identifying malicious activities, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
• Strong skills in Python programming.
• Experience in building and fine-tuning detections within a SIEM or detection platform.
• Familiarity with observability and logging systems like CloudWatch, Datadog, or similar platforms.
• Experience in operating or supporting a vulnerability management program.
• Knowledge of Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
• Experience with at least one major cloud provider, preferably AWS.
• Working understanding of identity and access systems and contemporary authentication flows.
• Awareness of the security implications associated with internet-facing applications and APIs.
• Strong grasp of threat modeling, risk prioritization, and practical security controls.
• Hands-on experience utilizing AI tools within security workflows.
• Sound judgment regarding AI risks such as prompt injection, data leaks, excessive tool access, and poor auditability.
• Exceptional analytical, communication, and cross-functional collaboration skills.
• Required work authorization in the United States.
• Must indicate if immigration sponsorship is necessary.
• Stock options.
• Health benefits from Day 1.
• 401(k) plan with company matching.
• Remote-friendly environment (US).
• Flexible time off (FTO).
• Opportunities for professional growth.
• An inclusive, mission-driven culture.
• AI-assisted initial screening and interview process.
MRO
AgelessRx
Xcelerate Solutions
Halcyon
Get handpicked remote jobs straight to your inbox weekly.