Security Engineer
Remote - MX
ABOUT OPORTUN
Oportun (Nasdaq: OPRT) is a digital banking platform that puts its 1.9 million members' financial goals within reach. With intelligent borrowing, savings, budgeting, and spending capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $15.5 billion in responsible and affordable credit, saved its members more than $2.3 billion in interest and fees, and helped our members save an average of more than $1,800 annually. For more information, visit Oportun.com.
WORKING AT OPORTUN
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
RESPONSIBILITIES:
As a Security Engineer, you will
• Monitor and analyze traffic and events/alerts escalated by L2 and advise on remediation actions.
• Review and assess impact and remediation actions for incidents.
• Lead P1 and P2 incident calls from CSOC end
• Investigate intrusion attempts and perform in-depth analysis of exploits by correlating various sources and determining which system or data set is affected.
• Follow standard operating procedures for detecting, classifying, and reporting incidents.
• Demonstrate network expertise to support timely and effective decision making of when to declare an incident.
• Help and Train L2 Analyst on handling tickets
• Conduct proactive threat research.
• Analyze a variety of network and host-based security appliance logs (EDR, Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths for each incident.
• Independently follow procedures to identify, contain, analyze, document and eradicate malicious activity.
• Document all activities during an incident and provide leadership with status updates during the life cycle of the incident.
• Escalate information regarding intrusion events, security incidents, and other threat indicators and warning information to the client.
• Track trends and configure systems as required to reduce false positives from true events.
• Create new rules in SIEM to identify threats.
• Assist with the development of processes and procedures to improve incident response times, analysis of incident, and overall, SOC functions.
• Provide written analysis for reports on an as-needed basis.
REQUIREMENTS:
• 8-10 years of relevant experience in SOC, Incident response and Cyber Forensics.
• Ability to communicate efficiently with internal team members at all levels and across functional and organizational boundaries.
• Working knowledge of the OSI, TCP/IP suite of protocols.
• Conceptual knowledge of network and systems architecture.
• Familiarity with Intrusion Detection Systems configuration and operation.
• Web application architecture.
• Active Directory Solid understanding of how major application layer protocols function (e.g., HTTP, SMTP, DNS).
• Knowledge of categories of malware and how they function (e.g., rootkits, trojans, adware, exploits, fileless).
• Organizational skills and time management/prioritization.
• Comfortable working against deadlines in a fast-paced environment.
• Experience in creating playbooks/runbooks for SOC
• Experience in SIEM configuration and use across the response lifecycle.
• At least 7 year of prior SOC experience (can include internships).
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun's CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory Banking CCPA CSOC DNS EDR Exploits Firewalls Forensics Incident response Intrusion detection Malware Privacy SIEM SMTP SOC TCP/IP Threat Research
Perks/benefits: Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Agile-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open CISM-related jobs
- Open Pentesting-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open APIs-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs