Senior Software Engineer - Security Operations

Socket.dev

Los Angeles (CA)

Hybrid

USD 200,000 - 250,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Accelerated Growth Environment
Top Tier Compensation Package
Flexible Time Off
Comprehensive Benefits Package

Job summary

StubHub is redefining the live event experience globally. We seek a Security Operations Engineer to drive incident response, threat detection, and SIEM enhancements at scale. You will write production-grade code, architect detection pipelines, and mature our SOC-less approach to Detection & Response.

Location: Hybrid (3 days in office/2 days remote) – New York, NY or Century City, CA. You will collaborate across Cloud Security, Identity Engineering, and cross-functional teams to strengthen

Qualifications

  • 3+ years experience in security engineering or related field.
  • Hands-on incident response leadership including complex investigations.
  • Proficiency in Python or other programming languages for security problems.
  • Deep familiarity with SIEM platforms and query languages.

Responsibilities

  • Lead and coordinate end-to-end security incident response: detect, triage, contain, eradicate, recover, and review.
  • Design, build, and tune detection rules and analytics across cloud, endpoint, network, and apps.
  • Maintain threat models and map detections to MITRE ATT&CK.
  • Develop and maintain security automation, tooling, and integration dashboards.
  • Collaborate with red team and third-party security partners to validate coverage.

Skills

Python
Go
SIEM
Incident response
Threat detection
Cloud security
Communication

Education

Security certifications (GCIH, GCIA, GCFE, OSCP)

Tools

Splunk
ELK
Chronicle
Panther
SOAR
EDR

Job description

StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world.

The Security Operations team owns incident response, threat detection, SIEM engineering, log management, and third-party security risk forming the frontline defense for StubHub's global operations.

As a Security Operations Engineer you will bring deep hands‑on experience in incident response and threat detection. You will help extend the existing tooling, automation, and detection infrastructure that enables the team to operate at scale. This is not a purely operational role; we are looking for an engineer who writes production-quality code to solve security problems, architects detection pipelines, and help mature StubHub’s SOC-less approach to Detection & Response.

You will work closely with Cloud and Infrastructure Security, Identity Engineering, and cross‑functional stakeholders. Your work will directly shape how StubHub detects, responds to, and learns from threats.

Location: Hybrid (3 days in office/2 days remote) – New York, NY or Century City, CA

What You’ll Do:
  • Incident Response
  • Lead and coordinate security incident response end-to-end: detection, triage, containment, eradication, recovery, and post‑incident review
  • Develop and maintain incident response playbooks
  • Drive root cause analysis and translate findings into durable improvements to detection and prevention capabilities
  • Act as an escalation point for complex or high‑severity incidents across the organization
  • Threat Detection
  • Design, build, and tune detection rules, event correlation logic, and behavioral analytics across cloud, endpoint, network, and application data sources
  • Assist in maintaining a threat model for StubHub's environment and mapping detection coverage to the MITRE ATT&CK framework
  • Proactively hunt for threats and indicators of compromise across the environment
  • Collaborate with red team and pen test partners to validate detection coverage and identify gaps
  • SIEM & Log Engineering
  • Continually improve SIEM capabilities including data ingestion pipelines, normalization, enrichment, and alerting workflows
  • Own log collection strategy: define what gets collected, at what fidelity, and for how long across cloud providers, SaaS applications, endpoints, and internal services
  • Write and maintain parsers, ETL pipelines, and data transformation logic to ensure high‑quality signal in the SIEM
  • Own and operate security tooling where needed (SIEM, SOAR, EDR, etc.)
  • Security Automation & Tooling
  • Write internal software in Python, Go, or similar to automate detection, response, enrichment, and reporting workflows
  • Build integrations between security tools, internal APIs, and third‑party services to accelerate analyst workflows and reduce mean time to respond
  • Develop dashboards, metrics, and reporting to communicate operational health and coverage to security leadership
  • Contribute to shared security infrastructure and internal libraries used across the security engineering organization
  • Third‑Party Security
  • Support the third‑party security program by evaluating vendor security posture, reviewing assessments, and triaging risk findings
  • Build or maintain tooling to automate third‑party risk intake, tracking, and reporting
  • Collaborate with Legal, Procurement, and Engineering to ensure third‑party risks are identified and remediated appropriately
What You’ve Done:
  • 3+ years of experience in security engineering, security operations, or a related discipline
  • Demonstrated, hands‑on experience leading incident response efforts, including complex, multi‑system investigations
  • Strong threat detection engineering experience: writing detection rules, tuning alerts, building correlation logic, and reducing false positive rates at scale
  • Proficiency in at least one programming or scripting language (Python strongly preferred; Go, Ruby, or Bash also relevant) — you regularly write code to solve security problems, not just configure tools
  • Deep familiarity with SIEM platforms (e.g., Splunk, ELK, Chronicle, Panther, or similar) including query languages and datra data onboarding.
  • Experience with cloud environments (AWS, GCP, or Azure) and the associated log sources, threat models, and detection strategies
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs); experience mapping detections to MITRE ATT&CK
  • Excellent written and verbal communication skills; able to convey technical risk clearly to non‑technical stakeholders
Preferred Experience:
  • Experience operating in a SOC environment, either in‑house or as part of an MSSP
  • Familiarity with SOAR platforms and automation‑driven response workflows
  • Experience with threat intelligence platforms and operationalizing threat feeds into detection pipelines
  • Prior involvement in third‑party or vendor security risk programs
  • Experience at high‑growth technology companies or marketplaces where scale and velocity present unique security challenges
  • Familiarity with data engineering concepts — streaming pipelines, schema design, log normalization — applied to security contexts
  • Relevant certifications (GCIH, GCIA, GCFE, OSCP, or equivalent) are a plus, but not required
What We Offer:
  • Accelerated Growth Environment: An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale.
  • Top Tier Compensation Package: Competitive base, equity, and upside that tracks with your impact.
  • Flexible Time Off: Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed.
  • Comprehensive Benefits Package: Prioritize your well‑being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options.

The anticipated gross base pay range is below for this role. Actual compensation will vary depending on factors such as a candidate’s qualifications, skills, experience, and competencies. Base annual salary is one component of StubHub’s total compensation and competitive benefits package, which includes equity, 401(k), paid time off, paid parental leave, and comprehensive health benefits.

Salary Range

$200,000 — $250,000 USD

About Us

StubHub is the world’s leading marketplace to buy and sell tickets to any live event, anywhere. Through StubHub in North America and viagogo, our international platform, we service customers in 195 countries in 33 languages and 49 available currencies. With more than 300 million tickets available annually on our platform to events around the world -- from sports to music, comedy to dance, festivals to theater -- StubHub offers the safest, most convenient way to buy or sell tickets to the most memorable live experiences. Come join our team for a front‑row seat to the action.

For California Residents: California Job Applicant Privacy Notice found here

We are an equal opportunity employer and value diversity on our team. We do not discriminate on the basis of race, color, religion, sex, national origin, gender, sexual orientation, age, disability, veteran status, or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer – Security Operations
Senior Software Engineer – Security Operations

StubHub • Los Angeles (CA)

Hybrid
USD 200,000 - 250,000
Unlimited Flex Time Off
Competitive compensation and equity
Health, Vision and Dental Insurance
+1
Senior Software Engineer - Security Operations
Senior Software Engineer - Security Operations

Socket.dev • New York (NY)

Hybrid
USD 200,000 - 250,000
Accelerated growth
Top-tier compensation
Flexible time off
+1
Senior Software Engineer – Security Operations
Senior Software Engineer – Security Operations

StubHub • United States

Hybrid
USD 200,000 - 250,000
Growth environment
Compensation
Flexible time off
+1
Software Engineer II - Product Security
Software Engineer II - Product Security

StubHub • Los Angeles (CA)

Hybrid
USD 165,000 - 200,000
Accelerated growth
Top compensation
Flexible time off
+1
Senior Software Engineer - Edge-Services Security
Senior Software Engineer - Edge-Services Security

Stubhubinc • Los Angeles (CA)

Hybrid
USD 200,000 - 250,000
Accelerated Growth Environment
Top Tier Compensation Package
Flexible Time Off
+1
Senior Software Engineer - Edge-Services Security
Senior Software Engineer - Edge-Services Security

Stubhubinc • Aliso Viejo (CA)

Hybrid
USD 200,000 - 250,000
Accelerated Growth Environment
Top Tier Compensation Package
Flexible Time Off
+1
Senior Software Engineer - Edge-Services Security
Senior Software Engineer - Edge-Services Security

Stubhubinc • New York (NY)

On-site
USD 200,000 - 250,000
Accelerated Growth Environment
Top Tier Compensation Package
Flexible Time Off
+1
Software Engineer II - Active Support
Software Engineer II - Active Support

Stubhubinc • New York (NY)

On-site
USD 165,000 - 200,000
Unlimited Flex Time Off
Comprehensive Health Benefits
401k Plan
Staff Governance, Risk and Compliance Analyst
Staff Governance, Risk and Compliance Analyst

Stubhubinc • New York (NY)

Hybrid
USD 200,000 - 250,000
Accelerated Growth Environment
Top Tier Compensation Package
Flexible Time Off
+1
Senior Software Engineer
Senior Software Engineer

StubHub • Los Angeles (CA)

Hybrid
USD 200,000 - 275,000
Top Tier Compensation Package
Flexible Time Off
Comprehensive Benefits Package
+1