Ledger - Staff Security Operations Engineer
Requirements
• 9+ years of experience in security operations, incident response, and CSIRT. • A strong track record as a technical expert in incident management, threat hunting, and detection engineering. • Comfortable working both as an individual contributor and as a team player in a fast-paced cloud and SaaS environment. • In-depth expertise in SIEM (ideally Splunk) and SOAR platforms, as well as CTI/OSINT methodologies. • Solid knowledge of AWS security (IAM, audit logs, network configurations, workloads, containers, Kubernetes) and cloud security tools (ideally Wiz, CSPM/CNAPP); experience with an EDR (ideally CrowdStrike). • Strong incident response and forensics skills, with the ability to conduct complex end-to-end investigations. • The ability to automate tasks and reporting using Python, Bash, APIs, GitHub Actions, a SOAR platform, or equivalent. • A solid understanding of infrastructure (cloud, networking, containers, CI/CD) and the ability to build and scale: log/data pipelines, integrations, and internal services. • A strong interest—or experience—in AI applied to security operations, agent-based workflows, and SOC automation. • Rigor and discipline: You follow and improve established processes and ensure consistency in incident handling and reporting; excellent analytical skills, even under pressure. • Clear communication of complex technical concepts to cross-functional teams; ability to document thoroughly and escalate issues with the appropriate level of context; awareness of confidentiality and the proper handling of sensitive information.
Responsibilities
• As a Staff Security Operations Engineer, you are the SecOps team’s top technical expert and our go-to authority on incident management. You lead the response to the most critical and complex incidents (CSIRT), spearhead proactive threat hunting, and define the detection and response strategy that the entire team relies on. Beyond day-to-day operations, you shape the architecture of our detection pipeline, SIEM, and automation—including the management of our internal Agentic SOC—and you establish the standards, playbooks, and methodologies that raise the technical bar for the entire team. Above all, you’re a builder: beyond design, you’ll build and actively evolve our systems—the Agentic SOC, the log pipeline, and automation—with a solid understanding of the underlying infrastructure. This is an expert role (individual contributor): your impact stems from your expertise, your judgment under pressure, and your influence. • Staff Security Operations Engineer • Critical Incident Response (CSIRT) • Serve as the primary point of contact and coordinator for the most complex incidents across the cloud, corporate systems, endpoints, identities, and the data center. • Conduct end-to-end investigations: root cause analysis, forensics, timeline reconstruction, and remediation recommendations to prevent recurrence. • Serve as the team’s go-to expert in incident management, ensuring a rigorous and consistent approach to handling, escalating, and documenting incidents. • Detection Strategy & Threat Hunting • Define the team’s detection strategy, architecture, and methodology. • Lead proactive threat hunting by leveraging CTI and OSINT to identify and neutralize risks before they impact Ledger. • Address the most challenging and emerging detection issues, and translate threat intelligence into concrete improvements in security posture. • Architecture & Agentic SOC • Design and optimize the SIEM (Splunk) architecture and SOAR (Torq) workflows that underpin effective detection, triage, and response. • Bring our Splunk environment up to standard and state-of-the-art: data quality and standardization (CIM), data models, search performance, and detection governance. • Build, evolve, and own the architecture of our internal Agentic SOC and our log/data pipeline, and lead the automation of reporting for the SecOps team. • Technical Leadership & Mentoring • Establish the standards, playbooks, and runbooks that the team relies on. • Mentor and foster the technical growth of senior and junior engineers, and act as a force multiplier within SecOps. • Work with the Engineering, Infrastructure, IT, and Cloud teams to align operational security with the organization’s objectives.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT