Security Engineer - Operations / Incident Response
Ondo Finance, Inc.
About Ondo Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems. About the Role We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense of Ondo. You will be a technical lead for our SIEM, EDR, email security, and SOAR stack. This is a hands-on role: you will write detections, tune them, run incidents, build automations, and decide what tooling we keep, replace, or retire. You will partner closely with IT, Infrastructure, Product Security, and our Security Incident Response Team (SIRT) to mature how Ondo detects and responds to threats across SaaS, endpoints, cloud, and identity. What You'll Do
- Detection engineering lifecycle in our SIEM (e.g., Splunk, Panther, or equivalent) - write detections, tune for noise, version them in code, and measure their performance.
- EDR (e.g., CrowdStrike, SentinelOne) deployment, policy tuning, exclusions hygiene, and response playbooks across macOS-heavy and Linux fleets.
- Email security stack: tune detections, investigate phish, run takedowns, and drive user reporting workflows.
- Build and operate SOAR / response automation to take repetitive analyst work to zero.
- Particpate in and lead incident response: triage, contain, eradicate, recover, and write the post-mortem. Run tabletop exercises with engineering and exec stakeholders.
- Build and maintain the on-call rotation, runbooks, and severity definitions for the SIRT.
- Integrate identity telemetry and SaaS audit logs into detection coverage; close the gap between IT signals and security signals.
- Partner with Infrastructure Security on cloud detection coverage and with Product Security on application-layer signals.
- Build, deploy, and operate AI-native workflows in our SecOps stack - LLM-assisted triage, alert summarization, evidence collection, draft IR comms, and analyst copilots - with the guardrails to keep them safe and auditable.
- Define how we monitor *internal* AI usage (sanctioned LLMs, MCP servers, browser-based agents) and how we detect AI-driven attacks against our employees and customers (deepfake voice/video, AI phishing, prompt injection in shared tooling).
- Help us decide where AI belongs in critical workflows (incident comms drafting, log search, detection tuning) and where it does not (signing actions, irreversible response, anything touching customer funds).
- 3-5+ years in security operations, detection engineering, or incident response, including time as a senior IC at a fast-moving company.
- Deep, hands-on experience with at least one SIEM (Splunk, Panther, Elastic, Sentinel, Chronicle)
- Production experience with EDR tuning and IR (CrowdStrike, SentinelOne, Defender, or equivalent).
- Solid working knowledge of email security tooling and modern phishing TTPs (BEC, OAuth consent phishing, vendor impersonation, callback phishing).
- SOAR / automation experience
- Strong scripting skills (Python preferred); comfortable working in Git and treating detections as code.
- Operational maturity: you can lead an incident, write a clean post-mortem, and push organizational changes that come out of it.
- Working fluency with cloud security telemetry in at least one of AWS, GCP, or Azure.
- Practical experience integrating AI/LLMs into security workflows, *or* a track record of evaluating new tooling rigorously and shipping it into production.
- Background defending crypto, fintech, or other high-value-target environments.
- Experience with on-chain monitoring tools and blockchain-aware incident response.
- Threat hunting against identity-based attacks (OAuth abuse, session token theft, IdP compromise).
- Public detection-engineering, IR, or research output (blogs, talks, open-source).
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer - Operations / Incident Response in United States vacancy
$139.2k - $218.4k
...to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation... ...of this role As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will play a critical role in...OperationsFull timeRemote workFlexible hours$159.3k - $202.4k
...Hunting team is looking for a Security Engineer, Threat Hunting who is... ...our customers. Key job responsibilities - You will query and collate... ...- You will work alongside incident responders and support the... ...and enable threat hunting operations at petabyte scale. - You...OperationsFlexible hoursShift work$136k - $184k
...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every investigation into... ...24/7 security response through a follow-the-sun operating model. The service combines automated triage workflows...OperationsInternshipImmediate startFlexible hours$169.15k - $191.25k
...a part of our journey! The Security Team is responsible for providing key security capabilities... ...and enterprise security, incident response, detection and GRC.... ...other security functions, engineering, product, support, business operations to identify appropriate detection...OperationsLocal areaRemote workHome officeFlexible hours$153k - $214k
...productivity without compromising security by ensuring every identity... ...foundation. The Security Operations team's mission is to... ...proactive monitoring, rapid response, and continuous improvement... ...controls. As a Senior Security Engineer on the Incident Response team, you will...OperationsFull timeLocal areaImmediate startRemote workWork from home$137.38k
...Incident Response Security Engineer Complex technology implementations in a product centric environment. Bridging the gap between legacy development or operations teams. Ensure developers create the most secure systems while enhancing the privacy of all system users...OperationsRelocation- ...Ascend Learning is looking for a Senior Security Engineer to lead SOC operations and provide technical security leadership. The role involves collaborating... ...should have a strong cybersecurity background, incident response certification, and experience in managing SOC...OperationsWork from homeFlexible hours
- ...Houston, Texas is seeking an Information Security professional to support enterprise security operations, focusing on threat detection and vulnerability... ...security, and strong hands-on skills in incident response and SIEM engineering. The role includes several benefits and...Operations
- A travel and technology company seeks a Senior Security Operations Engineer to enhance security operations and incident response processes. This role requires deep expertise in AWS, GCP, and SIEM tools, along with a proactive mindset for continuous improvement. The candidate...OperationsFlexible hours
- ...Costco Wholesale IT Security Engineer Costco IT is responsible for the technical future of Costco Wholesale,... ...retailer in the world with wholesale operations in fourteen countries. Despite... ...implements mechanisms to detect security incidents in order to enhance compliance...OperationsTemporary workWorldwide
- Sembi is seeking a Security Operations Engineer II in Austin, Texas. This role focuses on enhancing and monitoring security operations across all environments. Responsibilities include incident response, vulnerability management, and supporting IAM practices. The ideal...Operations
$175.1k - $236.9k
...looking for an experienced security leader to join the... ...managing a team of incident managers and... ...be expected to drive engineering teams to take the right... ...Management in particular, operates at very large scale and... ...a must. Key job responsibilities - Build and lead a...OperationsRemote workFlexible hoursShift workNight shift- ..., is seeking a mid-level resource to support Cyber Operations with a non-profit client. This role demands expertise in incident response and vulnerability management using tools like CrowdStrike and Microsoft Security suite. The ideal candidate has 2–4 years of experience...Operations
$70 per hour
...seeking a hands-on Cybersecurity Engineer supporting day-to-day security operations within a regulated enterprise environment... ..., and remediate endpoint-related incidents, with a heavy emphasis on DLP (50... ...endpoint security, incident response, and vulnerability management....Operations$70k - $80k
...Support Analyst to enhance their cybersecurity operations. This remote position requires expertise in security incident response, vulnerability management, and collaboration... ...3-5 years of experience in cybersecurity engineering, a relevant Bachelor’s degree, and skills in...OperationsRemote job- ...Huntsville, Alabama is seeking a cybersecurity analyst. This role involves performing defensive cyber operations, analyzing vulnerabilities, and supporting incident response within a team. Candidates should have relevant certifications, a bachelor's degree, and significant...Operations
- Emory University seeks a Senior Cyber Defense Engineer in Atlanta, Georgia. This role focuses on incident response and security operations in both cloud and on-premise environments. Candidates must possess a Bachelor's degree and minimum six years of relevant IT experience...OperationsRemote job
- ...IT Security Engineer II - Incident Responder Orrick currently has an excellent opportunity for an IT Security Engineer II - Incident Responder... ...'s security team, reporting to the Director of Threat Response Operations and collaborating daily with senior engineers. This...OperationsRemote workFlexible hours
$141.6k - $212.4k
...Senior Security Engineer – Detection and Response Klaviyo is looking for a Senior Security Engineer to add... ...and support with threat response operations. As a Senior Security Engineer, you... ...models, and efficient querying during incidents. Develop high-fidelity rule-...OperationsRemote work- ...Staff Detection And Response Engineer Join WRITER's security team as a staff detection and response engineer... ...exist in textbooks yet. You'll be the operational arm of our security function,... ...real-time detections, coordinating incident response across multiple teams, and...OperationsFull timeRemote work
- ...Senior Security Engineer - Detect & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security Engineer to join our Security Operations and Response Team as a senior individual contributor... ...and respond to security incidents across Marqeta's environment...OperationsWork at officeRemote work
- ...Senior Security Engineer - Detection & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security... ...Engineer to join our Security Operations and Response Team as a senior... ...investigate and respond to security incidents across Marqeta's environment, proactively...OperationsWork at officeRemote work
$260k - $405k
...Security Engineer, Insider Threat Detection & Response Security - San Francisco, Seattle, New York City, and Remote... ...technical in what we build but are operational in how we do our work, and are... ...experience running and leading incidents. ~ Proficiency with a scripting...OperationsRemote work$150k - $201.6k
...currently has an excellent opportunity for a Senior IT Security Engineer, Threat Response. This position could be based in any of our U.S.... ...Threat Hunter will work closely with our Security Operations Center (SOC), incident response teams, and other IT stakeholders to stay...OperationsTemporary workRemote workFlexible hours$141.6k - $212.4k
...Klaviyo is looking for a Senior Security Engineer to add to our growing Detection and Response (D&R) Team. This is a hands-on... ...support with threat response operations. As a Senior Security Engineer... ...and efficient querying during incidents. Develop high-fidelity rule...Operations- ...Role We are seeking a seasoned Security Engineer with a specialization in detection and response to join our team. As a... ...business objectives and daily operations. Responsibilities Design, implement... ...Expertise : Experience running incidents. Knows how to run and optimize...Operations
$202k - $230k
At Asana, security is foundational to our mission of helping humanity... ...security throughout our product and operations. We are looking for a Security Engineer, Threat Response to join our Security blue team... ...stakeholders to drive better incident response outcomes. This role...OperationsTemporary workWork at officeLocal areaWork from homeWorldwide$157k - $185k
...the rewards. The Security Operations (SecOps) team works to safeguard... ...partners closely with engineering and infrastructure teams to... ...strengthen detection coverage and response readiness. The team's focus... ..., and contain security incidents. You will design and...OperationsWork at officeFlexible hoursShift work3 days per week$139k - $204k
...actors know it. The Advanced Response Team exists to fight back.... ...You'll lead our most critical incidents, hunt adversaries before... ...left of boom Work alongside security partners who hold a high bar... ...incident response, security operations roles, and/or threat hunting...OperationsPermanent employmentTemporary workCasual workWork at officeFlexible hours- ...Senior Cyber Incident Response Analyst Location: Bulgaria Salary:... ...cybersecurity and PCI specialist operating across Europe, Africa, the... ...Canada, supported by six Security Operations Centres (SOCs)... ...and network, malware reverse engineering, Digital forensics and...OperationsWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Operations / Incident Response. Be the first to apply!
Related searches
- sr information security engineer United States
- security engineer intern United States
- senior application security engineer United States
- security solutions engineer United States
- associate security engineer United States
- azure security engineer United States
- principal security engineer United States
- security engineering manager United States
- aws cloud security engineer United States
- dlp security engineer United States

