Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer - Operations / Incident Response

Ondo Finance, Inc.

About Ondo

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems.

About the Role

We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense of Ondo. You will be a technical lead for our SIEM, EDR, email security, and SOAR stack. This is a hands-on role: you will write detections, tune them, run incidents, build automations, and decide what tooling we keep, replace, or retire.

You will partner closely with IT, Infrastructure, Product Security, and our Security Incident Response Team (SIRT) to mature how Ondo detects and responds to threats across SaaS, endpoints, cloud, and identity.

What You'll Do

  • Detection engineering lifecycle in our SIEM (e.g., Splunk, Panther, or equivalent) - write detections, tune for noise, version them in code, and measure their performance.
  • EDR (e.g., CrowdStrike, SentinelOne) deployment, policy tuning, exclusions hygiene, and response playbooks across macOS-heavy and Linux fleets.
  • Email security stack: tune detections, investigate phish, run takedowns, and drive user reporting workflows.
  • Build and operate SOAR / response automation to take repetitive analyst work to zero.
  • Particpate in and lead incident response: triage, contain, eradicate, recover, and write the post-mortem. Run tabletop exercises with engineering and exec stakeholders.
  • Build and maintain the on-call rotation, runbooks, and severity definitions for the SIRT.
  • Integrate identity telemetry and SaaS audit logs into detection coverage; close the gap between IT signals and security signals.
  • Partner with Infrastructure Security on cloud detection coverage and with Product Security on application-layer signals.
  • Build, deploy, and operate AI-native workflows in our SecOps stack - LLM-assisted triage, alert summarization, evidence collection, draft IR comms, and analyst copilots - with the guardrails to keep them safe and auditable.
  • Define how we monitor *internal* AI usage (sanctioned LLMs, MCP servers, browser-based agents) and how we detect AI-driven attacks against our employees and customers (deepfake voice/video, AI phishing, prompt injection in shared tooling).
  • Help us decide where AI belongs in critical workflows (incident comms drafting, log search, detection tuning) and where it does not (signing actions, irreversible response, anything touching customer funds).
What We're Looking For
  • 3-5+ years in security operations, detection engineering, or incident response, including time as a senior IC at a fast-moving company.
  • Deep, hands-on experience with at least one SIEM (Splunk, Panther, Elastic, Sentinel, Chronicle)
  • Production experience with EDR tuning and IR (CrowdStrike, SentinelOne, Defender, or equivalent).
  • Solid working knowledge of email security tooling and modern phishing TTPs (BEC, OAuth consent phishing, vendor impersonation, callback phishing).
  • SOAR / automation experience
  • Strong scripting skills (Python preferred); comfortable working in Git and treating detections as code.
  • Operational maturity: you can lead an incident, write a clean post-mortem, and push organizational changes that come out of it.
  • Working fluency with cloud security telemetry in at least one of AWS, GCP, or Azure.
  • Practical experience integrating AI/LLMs into security workflows, *or* a track record of evaluating new tooling rigorously and shipping it into production.
Nice to Have
  • Background defending crypto, fintech, or other high-value-target environments.
  • Experience with on-chain monitoring tools and blockchain-aware incident response.
  • Threat hunting against identity-based attacks (OAuth abuse, session token theft, IdP compromise).
  • Public detection-engineering, IR, or research output (blogs, talks, open-source).
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer - Operations / Incident Response in United States vacancy
  • $139.2k - $218.4k

     ...to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation...  ...of this role As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will play a critical role in... 
    Operations
    Full time
    Remote work
    Flexible hours

    GitLab

    United States
    3 days ago
  • $159.3k - $202.4k

     ...Hunting team is looking for a Security Engineer, Threat Hunting who is...  ...our customers. Key job responsibilities - You will query and collate...  ...- You will work alongside incident responders and support the...  ...and enable threat hunting operations at petabyte scale. - You... 
    Operations
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    3 days ago
  • $136k - $184k

     ...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every investigation into...  ...24/7 security response through a follow-the-sun operating model. The service combines automated triage workflows... 
    Operations
    Internship
    Immediate start
    Flexible hours

    Amazon

    Seattle, WA
    10 hours ago
  • $169.15k - $191.25k

     ...a part of our journey! The Security Team is responsible for providing key security capabilities...  ...and enterprise security, incident response, detection and GRC....  ...other security functions, engineering, product, support, business operations to identify appropriate detection... 
    Operations
    Local area
    Remote work
    Home office
    Flexible hours

    ClickHouse

    United States
    1 day ago
  • $153k - $214k

     ...productivity without compromising security by ensuring every identity...  ...foundation. The Security Operations team's mission is to...  ...proactive monitoring, rapid response, and continuous improvement...  ...controls. As a Senior Security Engineer on the Incident Response team, you will... 
    Operations
    Full time
    Local area
    Immediate start
    Remote work
    Work from home

    1Password

    United States
    10 hours ago
  • $137.38k

     ...Incident Response Security Engineer Complex technology implementations in a product centric environment. Bridging the gap between legacy development or operations teams. Ensure developers create the most secure systems while enhancing the privacy of all system users... 
    Operations
    Relocation

    WATI

    Sacramento, CA
    4 days ago
  •  ...Ascend Learning is looking for a Senior Security Engineer to lead SOC operations and provide technical security leadership. The role involves collaborating...  ...should have a strong cybersecurity background, incident response certification, and experience in managing SOC... 
    Operations
    Work from home
    Flexible hours

    Ascend Learning

    Leawood, KS
    2 days ago
  •  ...Houston, Texas is seeking an Information Security professional to support enterprise security operations, focusing on threat detection and vulnerability...  ...security, and strong hands-on skills in incident response and SIEM engineering. The role includes several benefits and... 
    Operations

    The Post Oak

    Houston, TX
    10 hours ago
  • A travel and technology company seeks a Senior Security Operations Engineer to enhance security operations and incident response processes. This role requires deep expertise in AWS, GCP, and SIEM tools, along with a proactive mindset for continuous improvement. The candidate... 
    Operations
    Flexible hours

    TripAdvisor

    New York, NY
    10 hours ago
  •  ...Costco Wholesale IT Security Engineer Costco IT is responsible for the technical future of Costco Wholesale,...  ...retailer in the world with wholesale operations in fourteen countries. Despite...  ...implements mechanisms to detect security incidents in order to enhance compliance... 
    Operations
    Temporary work
    Worldwide

    Costco

    Issaquah, WA
    4 days ago
  • Sembi is seeking a Security Operations Engineer II in Austin, Texas. This role focuses on enhancing and monitoring security operations across all environments. Responsibilities include incident response, vulnerability management, and supporting IAM practices. The ideal... 
    Operations

    Sembi

    Austin, TX
    10 hours ago
  • $175.1k - $236.9k

     ...looking for an experienced security leader to join the...  ...managing a team of incident managers and...  ...be expected to drive engineering teams to take the right...  ...Management in particular, operates at very large scale and...  ...a must. Key job responsibilities - Build and lead a... 
    Operations
    Remote work
    Flexible hours
    Shift work
    Night shift

    Amazon

    Seattle, WA
    4 days ago
  •  ..., is seeking a mid-level resource to support Cyber Operations with a non-profit client. This role demands expertise in incident response and vulnerability management using tools like CrowdStrike and Microsoft Security suite. The ideal candidate has 2–4 years of experience... 
    Operations

    Rapid Strategy

    New York, NY
    2 days ago
  • $70 per hour

     ...seeking a hands-on Cybersecurity Engineer supporting day-to-day security operations within a regulated enterprise environment...  ..., and remediate endpoint-related incidents, with a heavy emphasis on DLP (50...  ...endpoint security, incident response, and vulnerability management.... 
    Operations

    Insight Global

    Boston, MA
    10 hours ago
  • $70k - $80k

     ...Support Analyst to enhance their cybersecurity operations. This remote position requires expertise in security incident response, vulnerability management, and collaboration...  ...3-5 years of experience in cybersecurity engineering, a relevant Bachelor’s degree, and skills in... 
    Operations
    Remote job

    Reconnus

    Indianapolis, IN
    4 days ago
  •  ...Huntsville, Alabama is seeking a cybersecurity analyst. This role involves performing defensive cyber operations, analyzing vulnerabilities, and supporting incident response within a team. Candidates should have relevant certifications, a bachelor's degree, and significant... 
    Operations

    KIHOMAC

    Huntsville, AL
    2 days ago
  • Emory University seeks a Senior Cyber Defense Engineer in Atlanta, Georgia. This role focuses on incident response and security operations in both cloud and on-premise environments. Candidates must possess a Bachelor's degree and minimum six years of relevant IT experience... 
    Operations
    Remote job

    Emory University

    Atlanta, GA
    10 hours ago
  •  ...IT Security Engineer II - Incident Responder Orrick currently has an excellent opportunity for an IT Security Engineer II - Incident Responder...  ...'s security team, reporting to the Director of Threat Response Operations and collaborating daily with senior engineers. This... 
    Operations
    Remote work
    Flexible hours

    Orrick

    United States
    2 days ago
  • $141.6k - $212.4k

     ...Senior Security Engineer – Detection and Response Klaviyo is looking for a Senior Security Engineer to add...  ...and support with threat response operations. As a Senior Security Engineer, you...  ...models, and efficient querying during incidents. Develop high-fidelity rule-... 
    Operations
    Remote work

    Venturefizz Product Management Community

    United States
    9 days ago
  •  ...Staff Detection And Response Engineer Join WRITER's security team as a staff detection and response engineer...  ...exist in textbooks yet. You'll be the operational arm of our security function,...  ...real-time detections, coordinating incident response across multiple teams, and... 
    Operations
    Full time
    Remote work

    Writer Corporation

    United States
    3 days ago
  •  ...Senior Security Engineer - Detect & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security Engineer to join our Security Operations and Response Team as a senior individual contributor...  ...and respond to security incidents across Marqeta's environment... 
    Operations
    Work at office
    Remote work

    Marqueta Referrals

    United States
    3 days ago
  •  ...Senior Security Engineer - Detection & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security...  ...Engineer to join our Security Operations and Response Team as a senior...  ...investigate and respond to security incidents across Marqeta's environment, proactively... 
    Operations
    Work at office
    Remote work

    Marqeta

    United States
    3 days ago
  • $260k - $405k

     ...Security Engineer, Insider Threat Detection & Response Security - San Francisco, Seattle, New York City, and Remote...  ...technical in what we build but are operational in how we do our work, and are...  ...experience running and leading incidents. ~ Proficiency with a scripting... 
    Operations
    Remote work

    OpenAI

    Los Angeles, CA
    2 days ago
  • $150k - $201.6k

     ...currently has an excellent opportunity for a Senior IT Security Engineer, Threat Response. This position could be based in any of our U.S....  ...Threat Hunter will work closely with our Security Operations Center (SOC), incident response teams, and other IT stakeholders to stay... 
    Operations
    Temporary work
    Remote work
    Flexible hours

    Orrick

    Washington DC
    1 day ago
  • $141.6k - $212.4k

     ...Klaviyo is looking for a Senior Security Engineer to add to our growing Detection and Response (D&R) Team. This is a hands-on...  ...support with threat response operations. As a Senior Security Engineer...  ...and efficient querying during incidents. Develop high-fidelity rule... 
    Operations

    Klaviyo

    Boston, MA
    4 days ago
  •  ...Role We are seeking a seasoned Security Engineer with a specialization in detection and response to join our team. As a...  ...business objectives and daily operations. Responsibilities Design, implement...  ...Expertise : Experience running incidents. Knows how to run and optimize... 
    Operations

    Cape

    New York, NY
    10 hours ago
  • $202k - $230k

    At Asana, security is foundational to our mission of helping humanity...  ...security throughout our product and operations. We are looking for a Security Engineer, Threat Response to join our Security blue team...  ...stakeholders to drive better incident response outcomes. This role... 
    Operations
    Temporary work
    Work at office
    Local area
    Work from home
    Worldwide

    Asana

    San Francisco, CA
    1 day ago
  • $157k - $185k

     ...the rewards. The Security Operations (SecOps) team works to safeguard...  ...partners closely with engineering and infrastructure teams to...  ...strengthen detection coverage and response readiness. The team's focus...  ..., and contain security incidents. You will design and... 
    Operations
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    2 days ago
  • $139k - $204k

     ...actors know it. The Advanced Response Team exists to fight back....  ...You'll lead our most critical incidents, hunt adversaries before...  ...left of boom Work alongside security partners who hold a high bar...  ...incident response, security operations roles, and/or threat hunting... 
    Operations
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    Livingston, NJ
    3 days ago
  •  ...Senior Cyber Incident Response Analyst Location: Bulgaria Salary:...  ...cybersecurity and PCI specialist operating across Europe, Africa, the...  ...Canada, supported by six Security Operations Centres (SOCs)...  ...and network, malware reverse engineering, Digital forensics and... 
    Operations
    Work at office
    Remote work
    Flexible hours

    Integrity360

    United States
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer - Operations / Incident Response. Be the first to apply!