Jobherder
  • How it works
  • Pricing
  • Sample output
  • Jobs
  • Blog
  • Help
Log inTry a free sample

← All jobs

Remote

Information Security Engineer - CSOC (R14207)

OportunRemote - MXPosted 5 Sept 2026

Start a search — €9.99Apply on employer site

About this role

ABOUT OPORTUN Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $22.7 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

POSITION OVERVIEW The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering. Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation. Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.

Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments. Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems. Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks. Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.

Jobherder

Stop searching. Start applying.

Product

How a search worksPlans and pricingExample deliveryJob board

Resources

ArticlesHelp centreFor recruitersAgentsAffiliate programme

Features

CV tailoringRemote job searchCareer change

Experience performing root cause analysis and correlating activity across multiple security technologies. Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders. Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations. Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.

Continuous learning, security automation, and process improvement. WHO YOU ARE / WHAT YOU BRING Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality Experience in conducting purple team exercises Coordinate external takedowns and threat remediation with third-party providers.

Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems. Experience using Wiz Cloud Native Application Protection Platform (CNAPP) Experience conducting Threat Hunting using the MITRE ATT&CK framework. Experience developing, tuning, or maintaining security detections and SIEM use cases. Experience with SOAR platforms and security automation. Experience conducting fraud investigations or partnering with Fraud Operations.

Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud. Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent. #LI-REMOTE #LI-GK1 We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

<p style="margin: 0in;

Source listing: greenhouse_oportun

Prefer jobs chosen for you?

Upload your CV and Jobherder returns handpicked roles with a tailored CV and cover letter for each — built from your real experience.

Start a search — €9.99

© 2026 Jobherder

PrivacyTermsSupport