CronJobs

security jobs

Security Operations Engineer

Mesh · EU (Remote)

remoteunknownPosted Aug 19, 2026PythonSIEMSOARSplunkKQLSPLAWSKubernetes

Apply on the employer site

About this role

**Security Operations Engineer** **About Mesh** At Mesh, our mission is to enable consumers to pay and be paid with any asset. We’re bridging the gap between tokenized assets and everyday commerce by making crypto payments reliable, useful, and ubiquitous—backed by investors like PayPal Ventures, Paradigm, and Galaxy Ventures. **Overview** As a Security Ops Engineer, you’ll design, implement, and operate security controls across our infrastructure, systems, and operational workflows. You’ll build security architecture, perform threat modeling, analyze attack vectors, and lead active incident response. You’ll work autonomously across engineering, infrastructure, and product teams to strengthen our defensive posture and ensure rapid, effective response. **What You’ll Do** - Implement security controls and architecture (defensive systems, security integrations, infrastructure guardrails) - Perform threat analysis and modeling (attacker perspective, identify attack surfaces, build mitigations) - Conduct practical code and system reviews (evaluate features/integrations for security risks) - Manage vulnerability remediation (track findings, prioritize by risk, drive fixes to closure) - Own security operations platform management (admin/configure SIEM/SOAR for detection + response) - Engineer detection rules and alerts (write/tune/optimize queries to reduce false positives) - Conduct security investigations and incident response (alert analysis, forensics, escalation/communications) - Document findings (reports for reviews, threat models, and incident investigations) - Support compliance and evidence collection (ensure logging and availability for audits/regulatory needs) - Maintain operational readiness (stay current on emerging threats and security engineering practices) **Who You Are** - Bachelor’s degree in Computer Science, Cybersecurity, or related field - 5–7+ years hands-on experience building defensive security systems, implementing controls, or operating in security response - Strong technical background in attack techniques, threat analysis, and incident response - Experience managing vulnerability findings through remediation - Working knowledge of SIEM/SOAR and detection rule writing (e.g., SPL, KQL, or similar) - Deep understanding of network, host, application, and cloud security concepts - Strong written and verbal communication skills (clear documentation + escalation) - Ability to work independently with minimal supervision in a fast-paced environment - Experience collaborating with small, international teams across time zones - Willingness to work outside normal business hours when needed for incident response **Nice to have** - Threat modeling frameworks (e.g., STRIDE, MITRE ATT&CK) - Automated security controls / infrastructure security tooling - SIEM experience at scale (Sumo Logic, Splunk, Azure Sentinel, Datadog, or similar) - Cloud security monitoring (AWS, Azure, GCP) and native security services - Containerized environments (Docker, Kubernetes) and securing cloud-native workloads - Security/compliance frameworks (ISO 27001/2, NIST, SOC2, GDPR, DORA) - Object-oriented programming experience (Python preferred) - Query language experience (e.g., KQL or similar) **In-Office Expectations** Employees based in **San Francisco, New York, and Bangalore** are expected to work from the office at least **40%** of the time (about two days/week). Additional in-office requirements may apply depending on role/team needs. **Ho

Listing freshness

CronJobs last confirmed this listing 1d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord