Senior Security Operations Engineer

Brex Brex · Fintech · New York, NY +3 · Engineering

Senior Security Operations Engineer at Brex, focusing on preventing, detecting, and responding to security threats in corporate and cloud environments. The role involves using and developing security systems and tools, collaborating with other teams, and contributing to open-source projects. Requires experience in security alert triage, incident response, CI/CD, cloud environments, and coding in Go/Python.

What you'd actually do

  1. Work on a highly cross-functional team to prevent, detect and respond to security threats across Brex's corporate and cloud environments
  2. Perform security incident response, investigation, remediation, and documentation, participate in periodic threat hunting and security exercises
  3. Leading, scoping and building features, participate in designing, and maintaining tools and systems which support the team’s domains – corporate security, detection & response and infrastructure security
  4. Collaborating and partnering with engineering and operations teams to drive remediation of security issues, while balancing prioritization of those security issues within SLA and teams’ respective backlogs
  5. Caring about secure system design, valuing building things correctly, an understanding of a MVP approach and an empathetic mindset when working with others

Skills

Required

  • corporate security
  • detection & response
  • infrastructure security
  • security alert triage
  • security incident response
  • CI/CD systems
  • DevOps workflows
  • cloud environments (AWS, Azure, GCP)
  • SIEM
  • data pipelines
  • SOAR
  • domain monitoring
  • endpoint tooling
  • email protection tooling
  • cloud security tools
  • Go
  • Python

Nice to have

  • Proficiency with Go
  • Proficiency with other programming languages
  • Securing distributed systems in AWS
  • Securing cloud environments
  • Securing Kubernetes environments
  • Contributions to the wider technical community (open source, public research, mentorship, community organizing, blogging, presentations, etc)

What the JD emphasized

  • security alert triage
  • security incident response
  • coding is required