Gem.com

Security Engineer - Operations / Incident Response

Gem.com$120K — $150K *
US-AnywhereRemote in United States
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5+ years in security operations, detection engineering, or incident response at a fast-paced company.
  • Hands-on experience with at least one SIEM like Splunk or Panther.
  • Production experience with EDR tools such as CrowdStrike or SentinelOne.
  • Knowledge of email security tools and modern phishing tactics.
  • Experience with SOAR and automation technologies.
  • Strong scripting skills, preferably in Python, and familiarity with Git.
  • Operational maturity and capability to lead incident responses effectively.
  • Fluency in cloud security telemetry, particularly in AWS, GCP, or Azure.
  • Experience integrating AI/LLMs into security workflows or evaluating new security tools.

Responsibilities

  • Lead the detection engineering lifecycle in the SIEM, writing and tuning performance detections.
  • Deploy and tune EDR policies across macOS and Linux environments.
  • Manage email security stack, investigating phishing incidents and driving user reporting.
  • Automate response processes to minimize repetitive tasks for analysts.
  • Lead incident response activities including triage, containment, and recovery, while conducting tabletop exercises.
  • Maintain the on-call rotation and runbooks for the Security Incident Response Team.
  • Integrate identity telemetry and SaaS logs for enhanced detection coverage.
  • Collaborate with infrastructure and product security teams to improve cloud and application-layer detection.
  • Develop AI-native workflows for incident response operations while ensuring safety and auditability.
  • Define monitoring and detection strategies for both internal AI usage and AI-driven attacks.

Benefits

  • Flexible work environment with remote options.
  • Opportunity to work with cutting-edge security technologies including AI.
  • Collaborative team culture with a focus on continuous learning.
  • Pathways for career advancement in a fast-moving tech company.
Full Job Description
About the Role

We are hiring a Senior Security Engineer - Operations / Incident Response to own the day-to-day defense of Ondo. You will be a technical lead for our SIEM, EDR, email security, and SOAR stack. This is a hands-on role: you will write detections, tune them, run incidents, build automations, and decide what tooling we keep, replace, or retire.

You will partner closely with IT, Infrastructure, Product Security, and our Security Incident Response Team (SIRT) to mature how Ondo detects and responds to threats across SaaS, endpoints, cloud, and identity.

What You'll Do

  • Detection engineering lifecycle in our SIEM (e.g., Splunk, Panther, or equivalent) - write detections, tune for noise, version them in code, and measure their performance.
  • EDR (e.g., CrowdStrike, SentinelOne) deployment, policy tuning, exclusions hygiene, and response playbooks across macOS-heavy and Linux fleets.
  • Email security stack: tune detections, investigate phish, run takedowns, and drive user reporting workflows.
  • Build and operate SOAR / response automation to take repetitive analyst work to zero.
  • Particpate in and lead incident response: triage, contain, eradicate, recover, and write the post-mortem. Run tabletop exercises with engineering and exec stakeholders.
  • Build and maintain the on-call rotation, runbooks, and severity definitions for the SIRT.
  • Integrate identity telemetry and SaaS audit logs into detection coverage; close the gap between IT signals and security signals.
  • Partner with Infrastructure Security on cloud detection coverage and with Product Security on application-layer signals.
  • Build, deploy, and operate AI-native workflows in our SecOps stack - LLM-assisted triage, alert summarization, evidence collection, draft IR comms, and analyst copilots - with the guardrails to keep them safe and auditable.
  • Define how we monitor *internal* AI usage (sanctioned LLMs, MCP servers, browser-based agents) and how we detect AI-driven attacks against our employees and customers (deepfake voice/video, AI phishing, prompt injection in shared tooling).
  • Help us decide where AI belongs in critical workflows (incident comms drafting, log search, detection tuning) and where it does not (signing actions, irreversible response, anything touching customer funds).


What We're Looking For

  • 3-5+ years in security operations, detection engineering, or incident response, including time as a senior IC at a fast-moving company.
  • Deep, hands-on experience with at least one SIEM (Splunk, Panther, Elastic, Sentinel, Chronicle)
  • Production experience with EDR tuning and IR (CrowdStrike, SentinelOne, Defender, or equivalent).
  • Solid working knowledge of email security tooling and modern phishing TTPs (BEC, OAuth consent phishing, vendor impersonation, callback phishing).
  • SOAR / automation experience
  • Strong scripting skills (Python preferred); comfortable working in Git and treating detections as code.
  • Operational maturity: you can lead an incident, write a clean post-mortem, and push organizational changes that come out of it.
  • Working fluency with cloud security telemetry in at least one of AWS, GCP, or Azure.
  • Practical experience integrating AI/LLMs into security workflows, *or* a track record of evaluating new tooling rigorously and shipping it into production.


Nice to Have

  • Background defending crypto, fintech, or other high-value-target environments.
  • Experience with on-chain monitoring tools and blockchain-aware incident response.
  • Threat hunting against identity-based attacks (OAuth abuse, session token theft, IdP compromise).
  • Public detection-engineering, IR, or research output (blogs, talks, open-source).

About Gem.com

Industry
Founded
2013

Similar Jobs

More Jobs at Gem.com

More Finance & Insurance Jobs

Find similar Security Engineer - Operations / Incident Response jobs: