SlipstreamJobsFresh Startup & VC-Backed Jobs

Security and Threat Operations Engineer

Even.com - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OnePay is a consumer fintech platform backed by Walmart and Ribbit Capital, offering an all-in-one financial services platform combining banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto. The company also delivers embedded financial services to millions of employees and frontline workers through partnerships with employers, HCM providers, and gig platforms. As a Security and Threat Operations Engineer, you will protect OnePay's fast-moving fintech environment by turning production signals into actionable detection, response, and hardening initiatives. You will work closely with Product Security, Platform Security, and Engineering teams to proactively identify, monitor, and stop compromised behaviors across OnePay's products and infrastructure. Key responsibilities include: - Building and tuning detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments - Reviewing traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior - Using AI responsibly as a force multiplier for triage, analysis, and workflow automation while defining guardrails for AI-enabled systems - Operating OnePay's vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz and vulnerability scanning - Developing Python-based tooling and automation to improve investigations, enrichment, response, and operational scale - Partnering with Product Security to translate threat models and security reviews into production detections and response playbooks - Investigating security events end-to-end, including triage, scoping, containment support, and remediation follow-through - Supporting vulnerability management and operational security practices aligned with PCI and SOC 2 expectations - Participating in proactive threat hunting, detection improvement, and 24x7 security incident response on-call rotation The tech stack includes Node and TypeScript on the server with NestJS framework in a microservice-oriented architecture running on Kubernetes and AWS. Client-side development uses React Native for iOS, Android, and web platforms. The company embraces AI-assisted development with Claude Code or Cursor. Requirements: - 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment - Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with ability to distinguish attacker behavior from normal production noise - Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts - Strong Python programming skills and ability to write maintainable code for automation, enrichment, analysis, and security operations tooling - Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar - Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination - Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases - Experience with at least one major cloud provider, preferably AWS - Working knowledge of identity and access systems, modern authentication flows, and security implications of internet-facing applications and APIs - Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments - Practical experience using AI tools in security workflows with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability - Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams - Drive and proactivity as a builder and executor

Similar roles