Detection & Response, Lead

Ramp Ramp · Fintech · New York, NY · Security

This role focuses on security detection and response within a fintech company, involving incident handling, log analysis, and automation of security processes. It requires experience in security operations and log management platforms.

What you'd actually do

  1. Respond and assist with security requests and incidents submitted by Ramp team members
  2. Review logging, alerting, and audit sources to identify potential security incidents and perform initial triage on identified incidents
  3. Contribute to the creation, upkeep, and tuning of runbooks and security alerts to effectively handle, triage, and improve security alerts
  4. Work closely with the Ramp Security Engineers to improve security alerting and automated remediation
  5. Utilize log ingestion platform for security analytics and identification of tactics, techniques and patterns of attackers

Skills

Required

  • information security experience
  • Computer/Security Incident Response Team (C/SIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC) or a Security Operations Center (SOC) experience
  • query-based log management solutions (ELK, Datadog, Panther, etc)
  • deductive reasoning
  • critical thinking skills
  • communicate complex security issues
  • document technical details

Nice to have

  • working with government entities
  • highly regulated environment
  • Security Certifications (CompTIA Security+, Network+)
  • workflow automation tooling (Tines, Swimlane, etc.)

What the JD emphasized

  • federal and public sector environments