Search...

Senior Security Engineer Operations and Incident Response

Ondo logo
Ondo

Ondo helps institutions and individuals access traditional financial assets on blockchain through tokenized US Treasuries and investment products.

Cayman Islands
About Ondo

Ondo brings traditional financial assets onchain through institutional-grade platforms and infrastructure. The protocol offers tokenized US Treasuries and investment products with daily yield distributions, while developing Ondo Chain, a Layer 1 blockchain optimized for real-world assets. Products include USDY for non-US investors and OUSG for qualified purchasers, supported by regulated custodians and audited smart contracts.

View jobs by Ondo

Skills

About the Role

You will lead day-to-day security defense by operating and improving detection, endpoint, email, and response-automation tooling. You will investigate and lead incidents, maintain on-call processes and runbooks, integrate telemetry across systems, and implement safe, auditable AI-enabled security workflows.

Requirements

  • 3-5+ years of experience in security operations, detection engineering, or incident response, including senior individual contributor experience.
  • Hands-on experience with at least one SIEM, such as Splunk, Panther, Elastic, Sentinel, or Chronicle.
  • Production experience with EDR tuning and incident response.
  • Working knowledge of email security tooling and modern phishing techniques.
  • SOAR or automation experience.
  • Strong Python scripting skills and comfort using Git and detections as code.
  • Ability to lead incidents, write post-mortems, and drive organizational changes.
  • Working fluency with cloud security telemetry in AWS, GCP, or Azure.
  • Experience integrating AI or LLMs into security workflows, or evaluating and shipping new tooling into production.

Responsibilities

  • Develop, tune, version, and measure SIEM detections.
  • Deploy and tune EDR policies, exclusions, and response playbooks across macOS and Linux fleets.
  • Tune email security detections, investigate phishing, run takedowns, and improve user reporting workflows.
  • Build and operate SOAR and response automation.
  • Lead incident triage, containment, eradication, recovery, post-mortems, and tabletop exercises.
  • Maintain the SIRT on-call rotation, runbooks, and severity definitions.
  • Integrate identity telemetry and SaaS audit logs into detection coverage.
  • Partner on cloud and application-layer detection coverage.
  • Build and operate AI-enabled security operations workflows with safety and auditability guardrails.
  • Monitor internal AI usage and detect AI-driven attacks.
  • Define appropriate uses of AI in critical security workflows.
Senior Security Engineer Operations and Incident Response at Ondo | JobStash