Oportun
Oportun

Information Security Engineer (R14207)

engineeringfull-timeRemote - MX
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
fintech
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

#LI-REMOTE

#LI-GK1

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now