Security Operations Engineer

2 days, 8 hours ago
Full-time
Junior
DevOps and Infrastructure
Alpaca

Alpaca

Alpaca is a developer-first API for stock and crypto trading, offering easy-to-use APIs for building apps and trading algorithms.

Capital Markets
51-250
Founded 2015
$87M raised

Description

  • Own the relationship with the managed SOC, including alert quality, escalation workflows, SLAs, runbooks, and ongoing improvement of detection and response effectiveness.
  • Operate and maintain the SIEM, including log onboarding, parsing, normalization, correlation rules, alert tuning, and lifecycle management.
  • Ensure critical systems produce the right security telemetry across endpoints, identity providers, network devices, SaaS tools, and cloud platforms.
  • Refine detection logic based on threat intelligence, SOC feedback, incident learnings, and emerging attack techniques.
  • Assist with security incident handling, including containment, eradication, and recovery in collaboration with IT, Engineering, and external partners.
  • Develop, maintain, and improve incident response playbooks, escalation paths, and communication procedures.
  • Track and report security operations metrics such as alert volumes, false positive rates, MTTD, MTTR, and SOC performance.
  • Act as the security liaison to the IT Helpdesk to triage, prioritize, and resolve security-related tickets.
  • Provide guidance to IT teams on security alerts, risks, and required actions to improve frontline security maturity.

Requirements

  • 3+ years of experience in Security Operations roles.
  • Hands-on experience operating and tuning a SIEM, either on-prem or cloud-based.
  • Hands-on experience maintaining Kubernetes clusters.
  • Working knowledge of Linux.
  • Scripting or automation experience with Python or Bash for security operations tasks.
  • Experience working with a third-party SOC or MSSP.
  • Strong incident response and alert investigation skills across identity, endpoint, network, and cloud environments.
  • Understanding of common attacker techniques and detection methodologies.
  • Experience working closely with IT/helpdesk teams and translating security requirements into operational workflows.
  • Familiarity with endpoint security, identity monitoring, and log-based detections.
  • Strong written and verbal communication skills, especially during incidents.
  • Comfort working cross-functionally and handling escalations calmly and decisively.
  • Experience securing financial, trading, or other highly regulated platforms.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or PCI.
  • Experience with detection engineering frameworks such as MITRE ATT&CK.
  • Knowledge of cloud security logging across AWS, GCP, or Azure, and SaaS security telemetry.
  • Experience working with GitOps and CI/CD pipelines.
  • Experience running tabletop exercises or incident response simulations.
  • Security certifications such as GCIA, GCIH, GCED, CISSP, or similar.

Benefits

  • Competitive salary with stock options.
  • Health benefits.
  • One-time USD $500 new hire home-office setup stipend.
  • USD $150 monthly stipend via a Brex Card.
  • 100% remote team environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Risk Intelligence Analyst

Signifyd 251-1K IT Services

Signifyd is hiring a Risk Analyst to join its Risk Intelligence team, focusing on detecting fraud patterns, monitoring risk, and improving payment risk decisioning for e-commerce merchants worldwide.

Looker Machine Learning SQL
1 hour, 56 minutes ago

Security Analyst I

Tactacam 51-250 Household Durables

Tactacam is seeking a Security Analyst to monitor and respond to security threats across its digital infrastructure while supporting vulnerability management, remediation, documentation, and employee security awareness.

Cybersecurity Network Security SIEM
4 hours, 41 minutes ago

FBS Information Security Analyst (Remote)

Capgemini 100K+ Internet Software & Services

Farmers Information Security’s External Vendor Risk Assessment team is hiring an Information Security Analyst to support cybersecurity assessments of vendors and third parties, manage security risk reviews, and help protect company systems and data.

Cybersecurity
10 hours, 14 minutes ago

Information Security Specialist

SymSoft Solutions Web Design, Development, and System Integration

Symsoft Solutions is seeking a remote, six-month contractor to support state and local government digital services for California state agencies on a large IT project.

18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers