Sr. Security Operations Engineer, Incident Response

Affirm Affirm · Fintech · Canada · Remote · Information Security

Senior Security Operations Engineer focused on Incident Response within a fintech company. Responsibilities include leading incident response efforts, conducting investigations, partnering with automation teams, and improving security posture. Requires strong experience in cloud environments and security tooling.

What you'd actually do

  1. Lead security incidents end-to-end, from detection and triage through containment, remediation, and post-incident review.
  2. Act as incident commander, driving clear decisions and alignment across teams during high-pressure situations.
  3. Conduct hands-on investigations across cloud and endpoint environments to determine root cause and impact.
  4. Partner with Observability & Automation to improve detections, reduce noise, and build automated response playbooks.
  5. Contribute to and refine incident response playbooks, runbooks, and documentation to improve readiness and consistency.

Skills

Required

  • Security Operations or Detection & Response experience
  • Incident response in cloud environments (AWS and EKS preferred)
  • Leading security incidents
  • Investigative and analytical skills
  • Experience with SIEM and EDR platforms
  • Cloud security concepts
  • Communication skills

Nice to have

  • infrastructure-as-code

What the JD emphasized

  • hands-on incident response in cloud environments
  • lead security incidents
  • hands-on investigations