Gravity Payments

Gravity Payments

Gravity Payments provides comprehensive credit card processing services, including electronic check payment processing and e-commerce solutions, designed to support small and medium-sized businesses with transparent and customer-centric practices.

Diversified Financial Services
51-250
Founded 2004

Description

  • Monitor, triage, investigate, and disposition security alerts across SIEM, endpoint, cloud, identity, email, SaaS, network, DLP, and file integrity sources.
  • Participate in the shared 24/7 on-call rotation and perform initial containment and escalation for confirmed incidents.
  • Investigate security incidents, malicious email, suspected fraud, insider threats, and data loss events.
  • Conduct proactive threat hunting, preserve evidence, and produce clear incident reports and follow-up actions.
  • Engineer security automations and integrations, including SOAR playbooks and tool orchestration across the security stack.
  • Apply agentic AI as a tested and fully auditable force multiplier within security workflows.
  • Build and maintain SaaS, endpoint, and application security posture and operate file integrity monitoring.
  • Run phishing simulations, support penetration tests, and track remediation, mitigation, or accepted risk for identified gaps.
  • Support PCI DSS and SOC 2 compliance through evidence collection automation and audit interviews.
  • Maintain weekly and quarterly reporting, documentation, and day-to-day guidance through security help channels.

Requirements

  • At least 3 years of hands-on experience in security operations, incident response, vulnerability management, systems administration, or a closely related role.
  • Experience with independent alert investigation and escalation or containment responsibility.
  • Bachelor's degree in cybersecurity, computer science, information technology, or a related field, or equivalent practical experience, training, and certification.
  • Hands-on experience with SIEM and EDR/XDR platforms and security telemetry from cloud, endpoint, identity, email, and SaaS systems.
  • Experience with CrowdStrike NG-SIEM, AWS CloudTrail, CloudWatch, Security Hub, Okta, Microsoft Entra, Google Workspace, Keeper, Duo, UniFi, Microsoft Defender, Jira, and MintMCP.
  • Ability to query and correlate logs using LogScale/CQL, SPL, or a comparable SIEM query language.
  • Ability to use Python, PowerShell, and shell scripts for repeatable actions and analysis.
  • Advanced knowledge of Windows, macOS, and Linux internals, patch and configuration management, endpoint hardening, network protocols, and identity/access concepts.
  • Demonstrated experience with incident triage, containment, evidence collection, threat hunting, phishing analysis, and incident documentation.
  • Strong understanding of MITRE ATT&CK and advanced attacker techniques.
  • Experience with vulnerability management, including risk-based prioritization, remediation tracking, and CVSS/exploitability/service level targets.
  • Working knowledge of AWS security services and cloud investigation methods; PCI DSS, SOC 2, or similar frameworks is preferred.
  • Ability to participate in a shared 24/7 on-call rotation and respond to time-sensitive events.
  • Relevant certifications such as Security+, CySA+, Microsoft Security Operations Analyst Associate, GCIH, GCIA, or AWS Security Specialty are strongly preferred.
  • Must have access to a wired internet connection with at least 25 Mbps download and 20 Mbps upload speed.

Benefits

  • Competitive wage with profit sharing.
  • Base salary of $90,000 to $168,000.
  • Medical, dental, and vision coverage.
  • 401(k) retirement plan and voluntary life insurance.
  • Short-term and long-term disability coverage.
  • Open PTO available after one year.
  • Training, mentorship, and development opportunities.
  • Wellness resources and time off when needed.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Middle Information Security Access Specialist

GR8 Tech 251-1K IT Services

GR8_TECH is hiring an IAM and access management professional to secure and automate employee access across its global B2B iGaming technology organization.

Active Directory AWS Azure
7 hours, 16 minutes ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by handling fraud and insider-threat cases from initial signal through resolution, protecting the company and its customers.

Python SIEM SQL
7 hours, 31 minutes ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by resolving fraud and insider-threat cases and protecting the company and its customers.

Python SIEM SQL
7 hours, 31 minutes ago

Cyber Threat Intelligence Analyst

Toyota Tsusho Systems 51-250 IT Services

Toyota Tsusho Systems US, Inc., a Toyota group technology and mobility company, is hiring a CTI Analyst to conduct cyber threat intelligence operations, malware and TTP research, and supporting engineering that strengthens global security defenses.

Cybersecurity
1 day, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers