SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OnePay is a consumer fintech platform backed by Walmart and Ribbit Capital, offering an all-in-one financial services experience including banking, high-yield savings, credit cards, lending, investing, and crypto. The company also delivers embedded financial services to millions of employees and frontline workers through partnerships with employers and HCM providers.
As a Security and Threat Operations Engineer, you will protect OnePay's fast-moving fintech environment by turning production signals into actionable detection, response, and hardening initiatives. You will work closely with Product Security, Platform Security, and Engineering teams to proactively identify, monitor, and stop compromised behaviors across products and infrastructure.
Key responsibilities include:
- Building and tuning detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments
- Reviewing traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity and anomalous behavior
- Leveraging AI responsibly for triage, analysis, and workflow automation while defining guardrails for AI-enabled systems
- Operating OnePay's vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz and vulnerability scanning
- Developing Python-based tooling and automation to improve investigations, enrichment, response, and operational scale
- Partnering with Product Security to translate threat models and product risks into production detections and response playbooks
- Investigating security events end-to-end, including triage, scoping, containment support, and remediation follow-through
- Supporting vulnerability management and operational security practices aligned with PCI and SOC 2 expectations
- Participating in proactive threat hunting, detection improvement, and 24x7 security incident response on-call rotation
The company uses Node and TypeScript on the server with NestJS framework in a microservice-oriented architecture on Kubernetes and AWS. They embrace AI-assisted development with Claude Code or Cursor.
Requirements:
- 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment
- Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry
- Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts
- Strong Python programming skills with ability to write maintainable code for automation, enrichment, analysis, and security operations tooling
- Experience building and tuning detections in a SIEM or detection platform and working with observability/logging systems such as CloudWatch or Datadog
- Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination
- Familiarity with cloud and application security findings from platforms such as Wiz (CNAPP, runtime, code, and vulnerability scanning)
- Experience with at least one major cloud provider, preferably AWS
- Working knowledge of identity and access systems, modern authentication flows, and security implications of internet-facing applications and APIs
- Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments
- Practical experience using AI tools in security workflows with sound judgment about AI-specific risks (prompt injection, data leakage, excessive tool access, weak auditability)
- Excellent analytical, communication, and cross-functional collaboration skills
- Drive and proactivity as a builder and executor