Gravity Payments

Gravity Payments

Gravity Payments provides comprehensive credit card processing services, including electronic check payment processing and e-commerce solutions, designed to support small and medium-sized businesses with transparent and customer-centric practices.

Diversified Financial Services
51-250
Founded 2004

Description

  • Monitor, triage, investigate, and disposition security alerts across SIEM, endpoint, cloud, identity, email, SaaS, network, DLP, and file integrity sources.
  • Participate in the shared 24/7 on-call rotation and perform initial containment and escalation for confirmed incidents.
  • Investigate security incidents, malicious email, suspected fraud, insider threats, and data loss events.
  • Conduct proactive threat hunting, preserve evidence, and produce clear incident reports and follow-up actions.
  • Engineer security automations and integrations, including SOAR playbooks and tool orchestration across the security stack.
  • Apply agentic AI as a tested and fully auditable force multiplier within security workflows.
  • Build and maintain SaaS, endpoint, and application security posture and operate file integrity monitoring.
  • Run phishing simulations, support penetration tests, and track remediation, mitigation, or accepted risk for identified gaps.
  • Support PCI DSS and SOC 2 compliance through evidence collection automation and audit interviews.
  • Maintain weekly and quarterly reporting, documentation, and day-to-day guidance through security help channels.

Requirements

  • At least 3 years of hands-on experience in security operations, incident response, vulnerability management, systems administration, or a closely related role.
  • Experience with independent alert investigation and escalation or containment responsibility.
  • Bachelor's degree in cybersecurity, computer science, information technology, or a related field, or equivalent practical experience, training, and certification.
  • Hands-on experience with SIEM and EDR/XDR platforms and security telemetry from cloud, endpoint, identity, email, and SaaS systems.
  • Experience with CrowdStrike NG-SIEM, AWS CloudTrail, CloudWatch, Security Hub, Okta, Microsoft Entra, Google Workspace, Keeper, Duo, UniFi, Microsoft Defender, Jira, and MintMCP.
  • Ability to query and correlate logs using LogScale/CQL, SPL, or a comparable SIEM query language.
  • Ability to use Python, PowerShell, and shell scripts for repeatable actions and analysis.
  • Advanced knowledge of Windows, macOS, and Linux internals, patch and configuration management, endpoint hardening, network protocols, and identity/access concepts.
  • Demonstrated experience with incident triage, containment, evidence collection, threat hunting, phishing analysis, and incident documentation.
  • Strong understanding of MITRE ATT&CK and advanced attacker techniques.
  • Experience with vulnerability management, including risk-based prioritization, remediation tracking, and CVSS/exploitability/service level targets.
  • Working knowledge of AWS security services and cloud investigation methods; PCI DSS, SOC 2, or similar frameworks is preferred.
  • Ability to participate in a shared 24/7 on-call rotation and respond to time-sensitive events.
  • Relevant certifications such as Security+, CySA+, Microsoft Security Operations Analyst Associate, GCIH, GCIA, or AWS Security Specialty are strongly preferred.
  • Must have access to a wired internet connection with at least 25 Mbps download and 20 Mbps upload speed.

Benefits

  • Competitive wage with profit sharing.
  • Base salary of $90,000 to $168,000.
  • Medical, dental, and vision coverage.
  • 401(k) retirement plan and voluntary life insurance.
  • Short-term and long-term disability coverage.
  • Open PTO available after one year.
  • Training, mentorship, and development opportunities.
  • Wellness resources and time off when needed.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
14 minutes ago

SOC Analyst

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a SOC Analyst to monitor, investigate, and respond to security events across its enterprise and product environments within a collaborative cybersecurity operations team.

LLM PowerShell Python SIEM
29 minutes ago

SOC Analyst

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a SOC Analyst to monitor, investigate, and respond to security incidents across its enterprise and product environments as part of its Cyber Defense Operations team.

LLM PowerShell Python SIEM
29 minutes ago

Cybersecurity Analyst II

CareDx 251-1K Pharmaceuticals

CareDx is hiring a Cybersecurity Analyst II to support security operations for its information systems, AI security program, and compliance environment.

CrowdStrike HIPAA SIEM
59 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers