Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Operations Engineer image - Rise Careers
Job details

Security Operations Engineer - job 1 of 2

About One

One’s mission is simple - to help customers achieve financial progress. We’re doing this by creating simple solutions to help our customers save, spend, borrow, and grow their money – all in one place.

The U.S. consumer today deserves better. Millions of Americans today can’t access credit, build savings or wealth, and are left to manage their financial lives through multiple disconnected apps. Almost a quarter of U.S. adults are unbanked or underbanked and roughly 80% of fintech users rely on multiple accounts to manage their finances.

What makes us unique? We are backed by a preeminent fintech investor (Ribbit) and the world’s largest retailer (Walmart), maintain the speed and independence of a startup, and employ a strong (and growing) collection of world-class talent.

There’s never been a better moment to build a business that helps people achieve financial progress. Come build with us!

The role

As a Security Operations Engineer, your mandate is to strengthen our detection capabilities, automate incident response processes, and help build a robust security-first culture through product and engineering team partnerships and education. This role will determine the current threat landscape and its applicability to ONE’s environment, and ensure swift responses to security events. This role will impact ONE’s vision by ensuring the safety of customer data and finances through regularly working with a variety of people in security, product, third parties, and other business functions to build detections and automations to rapidly identify and mitigate security issues.

The role is responsible for

  • Mature and optimize a security detection, monitoring, and response ecosystem which implements detection engineering-as-code practices.

  • Combine threat intelligence and business knowledge with technical expertise to build monitors and automations tailored to ONE’s environment.

  • Plan and execute red and purple team exercises to identify vulnerabilities and assess the company’s detection and response capabilities across cloud environments and application layers.

  • Mature ONE’s threat intelligence program to rapidly evolve controls in response to the current threat landscape.

  • Stay abreast of emerging threats, vulnerabilities, and security technologies. Recommend and implement process improvements and security controls to enhance the organization's security posture.

  • Provide training and conduct tabletop exercises to improve security awareness and incident response readiness across the organization.

  • Partner with our Security GRC and Compliance teams to ensure security operations meet or exceed relevant regulatory requirements (e.g., PCI DSS v4.0, SOC 2).

  • Participate in a 24x7 security incident response on-call rotation.

You bring

  • 8+ years working experience in Information Security in a modern infrastructure-as-code environment with experience in proactive security engineering.

  • Experience with incident response frameworks (e.g. NIST 800-61) and techniques, including containment, eradication, recovery, and post-incident activities.

  • Strong skills in building and maintaining security information and event management (SIEM) systems, log analysis, and anomaly detection using tools like Datadog, ELK, and purpose-built open source tools.

  • Business acumen and ability to effectively communicate business risk from cybersecurity issues to audiences with varying levels of technical background.

  • Detection engineering and incident response experience specific to AWS.

  • Strong knowledge of: cloud computing, defense-in-depth strategies, secure design patterns for applications and platforms.

  • Deep understanding of security threat modeling, risk prioritization, and operational and technical security measures (including using industry frameworks, such as MITRE ATT&CK)

  • Preferably, proficiency for automation and tool development .Excellent analytical and problem-solving skills, with the ability to prioritize and manage multiple tasks in a fast-paced environment.

What it’s like working @ One

  • Competitive cash

  • Benefits effective on day one

  • Early access to a high-potential, high-growth fintech

  • Generous stock option packages in an early-stage startup

  • Employer Provident Fund contributions

  • Comprehensive health insurance for you and your family (health insurance, accident and disability insurance, term life insurance), including mental health support and wellness programs

  • Flexible time off programs – vacation, sick and other paid leaves and paid regional holidays

  • Monthly transport allowance over and above fixed cash for office commutes

  • Monthly work-from-home stipend over and above fixed cash for internet and utilities

  • Hybrid working model – work with our team in Bengaluru three times a week

Leveling Philosophy

In order to thoughtfully scale the company and avoid downstream inequities, we’ve adopted a flat titling structure at One. Though we may occasionally post a role externally with a prefix such as “Senior” to reflect the external level of the position, we do not use prefixes in titles like that internally unless in a position which manages a team. Internal titles typically include your specific functional responsibility, such as engineering, product management or sales, and often include additional descriptors to ensure clarity of role and placement within our organization (i.e. “Engineer, Platform”, “Sales, Business Development” or “Manager, Talent”). Employees are paid commensurate with their experience and the internal level within One.

Inclusion & Belonging

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@one.app.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Operations Engineer, ONE

At ONE, we're on a mission to help customers achieve financial progress by creating simple solutions for managing money. We're looking for a passionate Security Operations Engineer to join our Bengaluru team and play a critical role in safeguarding our customer data and finances. In this friendly, collaborative environment, you'll strengthen our detection capabilities and automate incident response processes while engaging with product and engineering teams to cultivate a security-first culture. You'll have the exciting opportunity to assess threat landscapes, develop tailored security measures, and ensure our security operations exceed regulatory standards like PCI DSS and SOC 2. Your hands-on experience with incident response frameworks and building SIEM systems will be invaluable as you lead exercises to identify vulnerabilities across our cloud environments. Plus, your expertise in security threat modeling and automation will help us stay ahead of emerging vulnerabilities and enhance our security posture. The perks are great too – competitive cash compensation, comprehensive health insurance, generous stock options, and a flexible hybrid working model. Come be a part of this innovative journey with ONE, where your work will truly make a difference!

Frequently Asked Questions (FAQs) for Security Operations Engineer Role at ONE
What are the main responsibilities of a Security Operations Engineer at ONE?

A Security Operations Engineer at ONE is pivotal in maturing and optimizing our security detection and response ecosystem. This includes implementing best practices in detection engineering, conducting red and purple team exercises, and staying updated on the current threat landscape to evolve our security controls rapidly. You will partner with teams across the organization to improve security awareness and incident response readiness.

Join Rise to see the full answer
What qualifications are necessary for the Security Operations Engineer role at ONE?

To be a successful Security Operations Engineer at ONE, candidates should have over 8 years of experience in Information Security within a modern infrastructure-as-code environment. Key qualifications include a robust understanding of incident response frameworks like NIST 800-61, expertise with SIEM systems, and specialized knowledge in AWS security practices. Proficiency in automation and problem-solving skills is also essential.

Join Rise to see the full answer
How does ONE support employee growth and benefits for Security Operations Engineers?

At ONE, we provide a competitive cash package alongside generous stock options in our high-growth fintech startup. Our benefits include comprehensive health insurance, a monthly transport allowance, and a monthly work-from-home stipend. Importantly, our culture emphasizes professional development and continuous learning opportunities, ensuring our engineers are continually evolving in their roles.

Join Rise to see the full answer
What kind of security tools do Security Operations Engineers use at ONE?

Security Operations Engineers at ONE utilize a variety of tools for monitoring and detection, including Datadog and ELK, as well as open-source tools tailored to our needs. Developing and maintaining security information and event management (SIEM) systems is a key responsibility, providing insight into anomalies and potential security threats in our environment.

Join Rise to see the full answer
What is the working environment like for a Security Operations Engineer at ONE?

ONE offers a dynamic working environment that encourages collaboration and innovation. As a Security Operations Engineer, you will engage with various teams to foster a security-first culture and conduct important incident response and training exercises, all while benefiting from a flexible hybrid work model that promotes work-life balance.

Join Rise to see the full answer
Common Interview Questions for Security Operations Engineer
Can you describe your experience with incident response frameworks, particularly NIST 800-61?

When answering this question, detail your familiarity with incident response phases, such as containment, eradication, and recovery. Share specific examples where you've effectively implemented these phases in past roles and how you contributed to post-incident analysis.

Join Rise to see the full answer
How do you prioritize security threats when developing response strategies?

Discuss your approach to risk prioritization using threat modeling. Mention the role of frameworks like MITRE ATT&CK in evaluating threats and how you would assess impacts to business operations to ensure crucial vulnerabilities are addressed first.

Join Rise to see the full answer
What tools have you used for security monitoring and detection?

Be specific about tools such as Datadog and ELK, providing examples of how you've implemented and optimized these systems in your previous positions to enhance ongoing monitoring and incident detection efforts.

Join Rise to see the full answer
How do you stay updated on the latest security threats and vulnerabilities?

Emphasize your commitment to continuous learning through security blogs, industry conferences, webinars, and participating in community forums. Mention any specific resources or networks you leverage to stay informed about emerging threats relevant to your role.

Join Rise to see the full answer
Can you share an experience where you improved a company's security posture?

Provide a concrete example of a project where you identified a vulnerability and implemented new processes or technologies that significantly bolstered security measures. Focus on the measurable results and improvements that followed.

Join Rise to see the full answer
Explain the concept of defense-in-depth and its importance.

Define defense-in-depth as a layered security approach, highlighting its relevance in creating multiple barriers against threats. Provide examples of how you've applied this concept in your security practices to mitigate risks effectively.

Join Rise to see the full answer
What is your understanding of automation in security, and how have you applied it?

Discuss the importance of automating threat detection and incident response tasks. Share instances where you've developed scripts or used automation tools to streamline processes and enhance efficiency within security operations.

Join Rise to see the full answer
How would you conduct a red team exercise, and what are its objectives?

Outline the steps to plan and execute a red team exercise, focusing on realistic simulation patterns. Emphasize the objectives of identifying vulnerabilities and testing the effectiveness of detection and response capabilities within the organization.

Join Rise to see the full answer
What are your methods for enhancing security awareness across teams?

Talk about your strategies for conducting training sessions, tabletop exercises, and interactive workshops to instill a culture of security awareness. Emphasize the importance of engaging employees at all levels to understand their role in safeguarding information.

Join Rise to see the full answer
How do you communicate cyber risks to non-technical stakeholders?

Explain your approach to translating complex cybersecurity concepts into understandable language. Illustrate this by sharing a past experience where you communicated risks effectively, ensuring that stakeholders understood potential impacts and the need for action.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
ONE Remote No location specified
Posted 11 days ago
Mission Driven
Inclusive & Diverse
Growth & Learning
Transparent & Candid
Flex-Friendly
401K Matching
Paid Sick Days
Paid Time-Off
Medical Insurance
Equity
Maternity Leave
Paternity Leave
Photo of the Rise User
ONE Remote No location specified
Posted 6 days ago
Mission Driven
Inclusive & Diverse
Growth & Learning
Transparent & Candid
Flex-Friendly
401K Matching
Paid Sick Days
Paid Time-Off
Medical Insurance
Equity
Maternity Leave
Paternity Leave
Posted 9 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Foodics Remote No location specified
Posted 6 days ago
Photo of the Rise User
Servus Credit Union Remote No location specified
Posted 8 days ago

We're seeking team members who are hungry, humble, and honest to help us build simple solutions for people to save, spend, and grow their money — all in one place.

82 jobs
MATCH
Calculating your matching score...
BADGES
Badge Flexible CultureBadge Future MakerBadge InnovatorBadge Office VibesBadge Rapid Growth
CULTURE VALUES
Mission Driven
Inclusive & Diverse
Growth & Learning
Transparent & Candid
BENEFITS & PERKS
Flex-Friendly
401K Matching
Paid Sick Days
Paid Time-Off
Medical Insurance
Equity
Maternity Leave
Paternity Leave
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 30, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!