SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenFX is building infrastructure to enable cross-border payments at scale, processing billions in monthly transaction volume. The company is backed by top-tier investors (Accel, Faction, NfX) and led by a team with experience from JP Morgan, Goldman Sachs, FalconX, PayPal, Affirm, and other leading fintech and crypto firms.
As Security Operations Center (SOC) Engineer, you will build and operationalize a fintech-grade security operations function from the ground up. This is a hands-on leadership role that combines deep technical expertise with team building and strategic security architecture.
Key responsibilities include:
- Establish comprehensive monitoring across cloud infrastructure, identity systems, endpoints, and transaction processing pipelines
- Design and implement detection strategies aligned to MITRE ATT&CK and fintech-specific fraud threat models
- Lead incident response end-to-end: containment, eradication, recovery, and root cause analysis
- Optimize mean time to detect (MTTD) and mean time to respond (MTTR) while reducing false positives
- Build high-signal alerting and SIEM correlation rules tailored to transaction flows and money movement controls
- Define security KPIs and KRIs (detection coverage, false positive rates, incident severity trends)
- Integrate security reviews into product launches; ensure logging and auditability are designed upfront
- Detect abnormal patterns in account behavior, API misuse, and privilege escalation
- Hire, mentor, and develop security analysts and detection engineers; establish escalation and on-call processes
- Ensure SOC processes support ISO 27001, PCI DSS, NIST compliance with defensible audit evidence
Required qualifications: 8–12+ years in cybersecurity operations with proven experience building or maturing a SOC in complex environments. Deep hands-on expertise in incident response, SIEM platforms, detection rule engineering, cloud security (AWS/GCP/Azure), identity systems, and SaaS telemetry. Strong experience defining KPIs, dashboards, and operational metrics. Demonstrated leadership and team management capability. Ability to communicate security risk clearly to executives and non-technical stakeholders.
Preferred: fintech or payments industry experience, knowledge of SOC 2/ISO 27001/NIST/CIS, hands-on experience with EDR/SOAR/DLP/CASB/MDM/Email Security, familiarity with fraud detection models and transaction risk monitoring, Product Security and CI/CD Security experience, relevant certifications (CISSP, CISM, CISA).