Security Engineer - Operations / Incident Response (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Engineer - Operations / Incident Response (Cybersecurity): Owning the day-to-day defense and technical lead for SIEM, EDR, and SOAR stacks with an accent on detection engineering and automated response. Focus on building AI-native SecOps workflows, leading incident response, and monitoring internal AI usage.
Location: Remote (Must be based in the US)
Company
is building institutional-grade financial infrastructure for tokenized real-world assets at the intersection of traditional finance and on-chain systems.
What you will do
- Manage the detection engineering lifecycle in SIEM (e.g., Splunk, Panther), including writing, tuning, and versioning detections in code.
- Oversee EDR deployment and policy tuning across macOS and Linux fleets, and manage the email security stack.
- Build and operate SOAR and response automations to eliminate repetitive analyst tasks.
- Lead incident response efforts, including triage, containment, recovery, and writing detailed post-mortems.
- Develop AI-native workflows for LLM-assisted triage, alert summarization, and monitoring for AI-driven attacks.
- Collaborate with Infrastructure and Product Security to integrate cloud and application-layer telemetry.
Requirements
- 3-5+ years of experience in security operations, detection engineering, or incident response.
- Must be authorized to work in the United States without employer sponsorship.
- Deep hands-on experience with at least one SIEM (Splunk, Panther, Elastic, etc.) and EDR (CrowdStrike, SentinelOne, etc.).
- Strong scripting skills in Python and proficiency with Git.
- Working knowledge of cloud security telemetry in AWS, GCP, or Azure.
- Practical experience integrating AI/LLMs into security workflows.
Nice to have
- Experience defending crypto, fintech, or other high-value target environments.
- Knowledge of on-chain monitoring tools and blockchain-aware incident response.
- Expertise in threat hunting against identity-based attacks.
- Public output in detection engineering or IR (blogs, talks, open-source).
Culture & Benefits
- Full-time remote work arrangement.
- Opportunity to work on institutional-grade financial infrastructure.
- Environment at the cutting edge of TradFi and Web3.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →