Threat Detection & Response Engineer (Remote-friendly)

OnePay

United States

Remote

USD 140,000 - 190,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Stock options
Health benefits from Day 1
401(k) plan with company match
Remote-friendly (US)
Flexible time off
Growth opportunities

Job summary

OnePay is seeking a Security and Threat Operations Engineer to protect a fast-moving fintech environment. You will turn production signals into detections, responses, and hardening initiatives, partnering with Product/Platform Security and Engineering teams across cloud, apps, and identity.

You will build detections, review traffic patterns, and develop automation to scale investigations and responses. This role emphasizes proactive threat hunting, incident response, and alignment with PCI/SOC 2

Qualifications

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.
  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.
  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.
  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.
  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.
  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
  • Experience with at least one major cloud provider, preferably AWS.
  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.
  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.
  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.
  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.
  • Drive and proactivity - everyone here is a builder and executor

Responsibilities

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.
  • Help operate OnePay's vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.
  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.
  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.
  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.
  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.
  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

Skills

Python
SIEM
Cloud security
Threat detection
AWS
AI in security
Threat hunting
Incident response
Communication
Cross-functional collaboration
Drive and proactivity

Tools

NestJS
TypeScript
Kubernetes
AWS
CloudWatch
Datadog
Claude Code
Cursor

Job description

OnePay is seeking a Security and Threat Operations Engineer to protect a fast-moving fintech environment. You will turn production signals into detections, responses, and hardening initiatives, partnering with Product/Platform Security and Engineering teams across cloud, apps, and identity.

You will build detections, review traffic patterns, and develop automation to scale investigations and responses. This role emphasizes proactive threat hunting, incident response, and alignment with PCI/SOC 2

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Threat Operations Engineer — FinTech Security Innovator
Remote Threat Operations Engineer — FinTech Security Innovator

Apply • Northern (KY)

Hybrid
USD 140,000 - 190,000
Stock options
Remote-friendly
Flexible time off
+1
Remote Threat Operations Engineer: Cloud Security & IR
Remote Threat Operations Engineer: Cloud Security & IR

Remote Genie • Northern (KY)

Hybrid
USD 120,000 - 180,000
Health benefits
Stock options
401(k) match
+1
Remote Security and Threat Ops Engineer — Stock Options
Remote Security and Threat Ops Engineer — Stock Options

One • United States

On-site
USD 120,000 - 160,000
Remote-friendly US
Flexible time off
Stock options
+2
Threat Detection & Response Engineer (Remote)
Threat Detection & Response Engineer (Remote)

Runway Financial, Inc. • Northern (KY)

Hybrid
USD 150,000 - 230,000
Threat Detection & Incident Response Engineer
Threat Detection & Incident Response Engineer

Whatnot • New York (NY)

On-site
USD 175,000 - 260,000
Health Insurance
Work From Home Support
Home office setup allowance
+4
Security Detection & Response Engineer - Remote-ready
Security Detection & Response Engineer - Remote-ready

Assort Health • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
Competitive Compensation
Lifelong Learning
Office Setup Stipend
+6
Senior Security Engineer, AI-Driven Detection & Response
Senior Security Engineer, AI-Driven Detection & Response

DaParrot Ltd • Northern (KY)

Hybrid
USD 140,000 - 200,000
Health insurance
Equity stock options
Retirement plans
+2
Senior Cyber Defense & Threat Response Lead - Remote
Senior Cyber Defense & Threat Response Lead - Remote

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Senior Security Engineer: SOC, Threat Hunting & Automation
Senior Security Engineer: SOC, Threat Hunting & Automation

REPAY Company • Atlanta (GA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Healthcare coverage
Life Insurance
Disability Insurance
+4
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5