SecOps Engineer

Papaya Global

United States

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Papaya Global is seeking a SecOps Engineer to join our cybersecurity team. You will defend the organization end-to-end across cloud, endpoints, identities, and applications, while maturing our security operations capability.

This hands-on role involves investigation of complex problems, building repeatable security operations in a growing cloud-native environment, and occasional after-hours incident response as required.

Qualifications

  • 3 years of hands-on experience in security operations or similar cybersecurity roles.
  • Experience with IT security, endpoint protection, identity security, and security operations.
  • Hands-on experience with SIEM, alert triage, investigation, dashboards, and detection tuning.
  • Strong cloud security knowledge across major cloud platforms.
  • Experience with incident response and DFIR workflows on Windows, Linux, macOS.
  • Proficiency in Python, Bash, and PowerShell for automation.
  • Familiarity with SOAR platforms and automated playbooks.
  • Strong communication and cross-team collaboration.
  • Willingness to participate in after-hours response.

Responsibilities

  • Operate and improve the security operations stack including SIEM, identity, endpoint, cloud, and application telemetry.
  • Investigate alerts and threats via triage, DFIR, and threat hunting.
  • Lead incident response from detection through containment, recovery, and post-incident review.
  • Build and tune detection rules, SIEM queries, and dashboards for high‑risk attack paths.
  • Automate response and enrichment workflows with scripting and SOAR.
  • Support security reviews of vendors and SaaS platforms, and partner with engineering to validate controls.
  • Assist with security monitoring for AI-enabled workflows and related tooling.
  • Develop agentic playbooks and evidence correlation workflows during investigations.
  • Evaluate AI-assisted investigation tools for accuracy and performance.

Skills

Security operations
Incident response
Detection engineering
Cloud security
Python
Bash
PowerShell
SOAR platforms
Threat hunting
Communication skills

Tools

SIEM platforms
SOAR platforms
AI tools
Cloud security tooling

Job description

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries.

About the job

We are looking for a SecOps Engineer to join our cybersecurity team. In this role, you will help defend the organization end-to-end across cloud, endpoints, identities, and applications while building and maturing our security operations capability.

You will work across SIEM and telemetry, detection engineering, alert investigation, threat hunting, digital forensics and incident response, threat intelligence, and response automation. You will partner closely with IT, DevOps, Application Security, R&D, and business stakeholders to turn security signals into effective action and lasting improvements.

This is a hands-on role for someone who enjoys investigating complex problems, improving controls, and building repeatable security operations in a growing environment. The role may participate in an on-call rotation and occasional after-hours incident response as required.

Responsibilities
  • Operate and improve the security operations stack --- SIEM, identity, endpoint, cloud, and application telemetry --- including log source onboarding, health monitoring, and coverage-gap remediation.
  • Investigate security alerts and threats through triage, host and artifact analysis, DFIR, and threat hunting.
  • Lead incident response from detection through containment, recovery, and post-incident review.
  • Build and tune detection rules, SIEM queries, and dashboards for high-risk attack paths, and convert threat intelligence into new detections, hunts, and control improvements.
  • Automate response and enrichment workflows by using AI tools, scripting (Python, Bash, PowerShell), or SOAR tools to cut response time, and report incident metrics --- root cause, impact, and remediation status.
  • Support security reviews of vendors, SaaS platforms, and internal applications, and partner with engineering to validate whether existing controls detect and mitigate relevant threats.
  • Support security monitoring and response for AI-enabled workflows and artifacts where applicable, including agentic tooling, integrations, and related operational risks.
  • Use AI-assisted triage and anomaly-detection models to prioritize alerts and cut time-to-detect across SIEM and endpoint telemetry.
  • Develop agentic workflows to speed up evidence correlation, RCA, timeline reconstruction, and case write-ups during investigations.
  • Evaluate AI agentic investigation tools for accuracy and performance and use the results to fine-tune and further enhance the automated playbooks.
  • 3 years of hands-on experience in security operations, incident response, detection engineering, or a similar cybersecurity role.
  • Strong practical experience with IT security, endpoint protection, identity security, and security operations.
  • Hands-on experience with SIEM platforms, including alert triage, investigation, query development, dashboards, and detection tuning.
  • Solid understanding of cloud security and practical experience with one or more major cloud platforms, including identity, logging, network, and workload security concepts.
  • Experience with incident response and DFIR workflows, including host-based and artifact analysis on Windows, Linux and macOS.
  • Proficiency in Python, Bash, PowerShell, or similar scripting languages for automation and operational tooling.
  • Familiarity with SOAR platforms, automated playbooks, alert enrichment, and response workflows.
  • Strong written and verbal communication skills, with the ability to collaborate across DevOps, IT, R&D, security, and business teams.
  • Ability and willingness to participate in occasional after-hours response when required by a material security incident.
  • Strong familiarity with AI tools and experience putting them to work in security investigations.
  • Experience building detections and incident-response capability in a growing or cloud-native organization.
  • Experience with threat hunting, malware analysis, host forensics, and mapping activity to common adversary tactics, techniques, and procedures.
  • Experience with containerized or cloud-native architectures, identity providers, and modern endpoint security platforms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SecOps Engineer - SIEM, IR & Cloud Security
SecOps Engineer - SIEM, IR & Cloud Security

Papaya Global • United States

On-site
USD 120,000 - 180,000
Security Engineer, Incident Response
Security Engineer, Incident Response

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 180,000
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000