Ondo Finance

Ondo Finance

Security Engineer - Operations / Incident Response

Remote (US)

Sponsorship not specifiedDetected 23 days ago
PythonGitAWSGCPLinuxOAuthLLMsCybersecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseResearch

About the role

  • We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense of Ondo. You will be a technical lead for our SIEM, EDR, email security, and SOAR stack. This is a hands-on role: you will write detections, tune them, run incidents, build automations, and decide what tooling we keep, replace, or retire.
  • You will partner closely with IT, Infrastructure, Product Security, and our Security Incident Response Team (SIRT) to mature how Ondo detects and responds to threats across SaaS, endpoints, cloud, and identity.
  • We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense of Ondo.

Responsibilities

  • Email security stack: tune detections, investigate phish, run takedowns, and drive user reporting workflows.
  • Build and operate SOAR / response automation to take repetitive analyst work to zero.
  • Particpate in and lead incident response: triage, contain, eradicate, recover, and write the post-mortem. Run tabletop exercises with engineering and exec stakeholders.
  • Build and maintain the on-call rotation, runbooks, and severity definitions for the SIRT.
  • Build, deploy, and operate AI-native workflows in our SecOps stack - LLM-assisted triage, alert summarization, evidence collection, draft IR comms, and analyst copilots - with the guardrails to keep them safe and auditable.

Requirements

  • 3-5+ years in security operations, detection engineering, or incident response, including time as a senior IC at a fast-moving company.
  • Deep, hands-on experience with at least one SIEM (Splunk, Panther, Elastic, Sentinel, Chronicle)
  • Production experience with EDR tuning and IR (CrowdStrike, SentinelOne, Defender, or equivalent).
  • Solid working knowledge of email security tooling and modern phishing TTPs (BEC, OAuth consent phishing, vendor impersonation, callback phishing).
  • Practical experience integrating AI/LLMs into security workflows, *or* a track record of evaluating new tooling rigorously and shipping it into production.

Nice to have

  • Background defending crypto, fintech, or other high-value-target environments.
  • Experience with on-chain monitoring tools and blockchain-aware incident response.
  • Threat hunting against identity-based attacks (OAuth abuse, session token theft, IdP compromise).
  • Public detection-engineering, IR, or research output (blogs, talks, open-source).
  • Strong scripting skills (Python preferred)
  • comfortable working in Git and treating detections as code.

Skills

  • Integrate identity telemetry and SaaS audit logs into detection coverage; close the gap between IT signals and security signals.
  • Working fluency with cloud security telemetry in at least one of AWS, GCP, or Azure.

Benefits

  • Integrate identity telemetry and SaaS audit logs into detection coverage
  • Partner with Infrastructure Security on cloud detection coverage and with Product Security on application-layer signals.

Company info

  • Define how we monitor *internal* AI usage (sanctioned LLMs, MCP servers, browser-based agents) and how we detect AI-driven attacks against our employees and customers (deepfake voice/video, AI phishing, prompt injection in shared tooling).
  • What We're Looking For

This listing is sourced directly from Ondo Finance's careers page and normalized into a canonical job model.