Every week, somewhere in our environment, something tries to break. A credential gets phished. A mule account starts moving money it shouldn't. An adversary finds a gap between two systems that were never designed to talk to each other. Most people at Rate never see it happen, because a tight, sharp, and relentless team already did. That team is the Risk Operations Center (ROC), and Rate is looking for a mid-to-senior level response engineer who wants to be the one that gets the page, reads the signal that no one else caught, and calls the shots when the room goes quiet and everyone looks at you. This opportunity is not simply a one-lane job. You will rotate and flex across five unique, yet overlapping terrains, often in the same week. You'll work from a real IR plan mapped to NIST CSF 2.0, a growing playbook library, and a team that has already done the hard work of building the scaffolding — you're here to run on it, sharpen it, and push it further. The five domains are: Incident Response — Take incident command on active events. Establish ground truth fast, drive containment and eradication, and own the post-incident review that makes the next one shorter. Threat Hunting — Don't wait for the alert. Go looking for what the tooling missed — hypothesis-driven hunts across endpoint, identity, and network telemetry. Detection Engineering — Turn every incident and hunt into a new detection. Write, tune, and retire rules; you're building the team's muscle memory into code. Threat Intelligence — Track the actors and techniques relevant to financial services. Translate raw intel into detections, playbooks, and briefings people actually use. Fraud Investigations — Cross into fraud ops when account takeover, mule activity, or payment fraud overlaps with a security incident — which, in this environment, is often.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level