Were looking for a Security Operations Engineer to lead our monitoring and detection efforts across our global FinTech environment. Youll be responsible for implementing and operating a robust SIEM solution, managing alerting pipelines, and ensuring security visibility across our SaaS platforms, cloud environments (AWS,GCP), and one physical on-prem location. This role is mission-critical to maintain our compliance, protect our customer data, and support our global operations.
Responsibilities:
Lead the implementation and ongoing operations of the company-wide SIEM solution
Build and tune detection rules, alerts, and incident workflows
Monitor cloud (AWS, GCP) and SaaS environments for anomalies and threats
Integrate logs from production systems, cloud platforms, SaaS tools, and on-prem infrastructure
Respond to security incidents and perform forensic investigations
Partner with Engineering, IT, and GRC to ensure logging and alerting coverage
Continuously improve our detection capabilities and response processes
Ensure monitoring meets compliance frameworks (SOC2, PCI-DSS, etc.)
Responsibilities:
Lead the implementation and ongoing operations of the company-wide SIEM solution
Build and tune detection rules, alerts, and incident workflows
Monitor cloud (AWS, GCP) and SaaS environments for anomalies and threats
Integrate logs from production systems, cloud platforms, SaaS tools, and on-prem infrastructure
Respond to security incidents and perform forensic investigations
Partner with Engineering, IT, and GRC to ensure logging and alerting coverage
Continuously improve our detection capabilities and response processes
Ensure monitoring meets compliance frameworks (SOC2, PCI-DSS, etc.)
Requirements:
47 years in cybersecurity, including 2+ years in a security monitoring, SecOps, or blue team role
Experience deploying and managing SIEM platforms
Hands-on knowledge of cloud infrastructure security in AWS and GCP
Familiarity with SaaS security monitoring (Okta, Google Workspace, M365, Salesforce,etc.)
Experience with scripting or automation (e.g., Python, Bash, Terraform, etc.)
Strong understanding of incident response processes
Ability to work independently and lead projects end-to-end
Nice to have: Experience with SOAR platforms, MITRE ATT&CK, and threat intel feeds
Work experience from high-tech companies
47 years in cybersecurity, including 2+ years in a security monitoring, SecOps, or blue team role
Experience deploying and managing SIEM platforms
Hands-on knowledge of cloud infrastructure security in AWS and GCP
Familiarity with SaaS security monitoring (Okta, Google Workspace, M365, Salesforce,etc.)
Experience with scripting or automation (e.g., Python, Bash, Terraform, etc.)
Strong understanding of incident response processes
Ability to work independently and lead projects end-to-end
Nice to have: Experience with SOAR platforms, MITRE ATT&CK, and threat intel feeds
Work experience from high-tech companies
This position is open to all candidates.