Remote
Information Security Engineer - CSOC (R14207)
About this role
ABOUT OPORTUN Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $22.7 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.
POSITION OVERVIEW The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.
The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.
WHAT YOU’LL DO Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering. Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation. Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments. Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems. Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks. Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.