CareerMoonshot

Information Security Engineer - CSOC (R14207)

Oportun Financial Corp · Remote

📍 Remote - MXvia greenhousePosted 2026-09-21
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Oportun Financial Corp.
Who We Are Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $22.7 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually. The Opportunity The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools.   The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.   The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development.   Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.   At Oportun, we move fast, and we hold each other to a high bar. If you care about doing your best work while actually moving the needle for real people, you'll fit right in.   What You'll Do Your day-today You’ll lead and coordinate cybersecurity investigations from initial detection through containment, remediation, and root cause analysis. You’ll investigate suspicious activity across cloud, endpoint, identity, SaaS, email, network, AWS, Kubernetes, GitHub, and authentication environments. You’ll analyze and correlate telemetry from SIEM, EDR, firewalls, identity providers, proxies, cloud platforms, and email security solutions. You’ll perform threat hunting and help develop, tune, and maintain security detections and SIEM use cases. You’ll partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to investigate incidents and coordinate response. You’ll create clear investigation timelines, executive summaries, playbooks, lessons learned, and technical documentation. You’ll identify opportunities to improve security operations through automation, AI-assisted workflows, and process improvements. You’ll help strengthen Oportun’s security posture by identifying recurring threats, control gaps, and opportunities to improve detection and response. Who You Are The right fit looks like this   You're comfortable navigating complexity and don't wait for perfect information to move forward. You communicate clearly, give direct feedback, and expect the same in return.   What You Bring Skills & experience   Required   2–5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, Detection Engineering, or a related area. Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent relevant experience. Experience leading or supporting cybersecurity investigations from initial detection through containment and remediation. Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting. Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments. Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems. Strong understanding of Windows, Linux, Active Directory, Entra ID, AWS IAM, and modern identity-based attacks. Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures. Experience performing root cause analysis and correlating activity across multiple security technologies. Strong written and verbal communication skills, including the ability to explain technical findings to technical and non-technical audiences. Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned. A continuous-learning mindset with an interest in security automation and process improvement. Nice to Have Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, or documentation. Experience identifying repetitive operational tasks and implementing AI-enabled or automated workflows. Experience conducting purple team exercises. Experience coordinating external takedowns and threat remediation with third-party providers. Experience using Wiz or another Cloud Native Application Protection Platform. Experience conducting threat hunting using the MITRE ATT&CK framework. Experience with SOAR platforms and security automation. Experience conducting fraud investigations or partnering with Fraud Operations. Experience investigating account takeover, payment fraud, synthetic identity fraud, or other cyber-enabled fraud. Experience with AWS, Kubernetes, GitHub, SaaS platforms, and identity systems. Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent. Our AI Mindset We build with AI. We lead with judgment. AI isn't a feature here. It's how we work. We're excited about what AI makes possible, and we're looking for people who share that curiosity. You don't need to be an expert. Y

More Remote jobs

Remote jobs · Browse all locations