Senior Security Operations Analyst (Detection & Response)

Point Digital Finance, Inc.Palo Alto, CA
$117,800 - $166,950Remote

About The Position

Point Digital Finance is expanding its Information Security function, and this is the team's first dedicated monitoring and response hire — a high-visibility role with immediate, measurable impact. As Senior Security Operations Analyst (Detection & Response), you will be the second half of an incident-response rotation, partnering directly with the security lead to detect, investigate, and contain threats across a regulated consumer-finance environment that protects the financial data of hundreds of thousands of homeowners. This is not an alert-watching seat: you will engineer the detections, automate the response, and harden how we see our AWS, Google Workspace, and SaaS estate. You'll help stand up a modern detection & response practice from an early-stage footing, with the autonomy to own problems end to end and the mandate to turn noisy alerts into fast, repeatable, well-documented response. If you like building as much as responding — and want your work to directly reduce risk to real people's financial lives — this role is for you.

Requirements

  • 5+ years of experience in security operations, incident response, SOC, or detection engineering (mid-to-senior individual contributor).
  • Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
  • Strong SIEM skills — authoring and tuning detections, correlation rules, and dashboards (Coralogix, Splunk, Elastic, Microsoft Sentinel, or similar).
  • Practical cloud security experience in AWS and Google Workspace, including identity and log sources.
  • Demonstrated ability to investigate and contain incidents end to end — e.g., phishing/AiTM, account takeover, business email compromise, and cloud/identity threats.
  • Working knowledge of vulnerability management and coordinating remediation with engineering teams.
  • Scripting and automation ability (Python or similar) for detection-as-code and SOAR-style workflows.
  • Clear written and verbal communication — able to produce runbooks, metrics, and audit-ready documentation.
  • Comfortable operating with autonomy on a small team and owning problems end to end.
  • Authorized to work in the United States, and able to participate in an off-hours on-call rotation.

Nice To Haves

  • Hands-on experience using AI/LLMs for security analysis, investigation, and alert engineering (detection authoring, correlation, tuning, and automation).
  • Experience in a regulated financial-services or fintech environment (GLBA, NYDFS Part 500, SOC 2).
  • Relevant certifications (e.g., GCIA, GCIH, GCED, GIAC, CySA+, Security+, or AWS Security Specialty).
  • Experience standing up detection & response practices from an early or greenfield state.

Responsibilities

  • Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead — triaging, investigating, and driving containment of security alerts and incidents.
  • Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
  • Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
  • Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
  • Own vulnerability management: run day-to-day vulnerability management — prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
  • Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
  • Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
  • Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
  • Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
  • Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.

Benefits

  • Generous health benefits: We provide comprehensive medical, dental, and vision plans with options for flexible spending accounts (FSA) and health savings accounts (HSA).
  • Unlimited paid time off: Recharge with unlimited paid time off and 10 company holidays.
  • Flexible remote and onsite work: Our teams work from many different locations and time zones. We support fully remote work and also have an amazing in-person environment in our downtown Palo Alto, CA HQ.
  • Fully paid parental leave: Point will supplement state Paid Family Leave (PFL) so employees receive 100% of their regular base pay, plus two additional weeks of fully paid leave after state PFL ends. In states without PFL, Point offers up to 8 weeks of paid parental leave. In addition, employees also receive 4 weeks of fully paid transition time, during which you may work 2–3 days per week while receiving full base pay.
  • Equity: We offer meaningful equity because we believe in sharing the value you help create. Your contributions directly impact our growth, and your equity gives you a stake in our future success.
  • Financial wellness: We provide 401K retirement plans for employees as well as guaranteed life insurance and short- and long-term disability coverage.
  • Extra work/life benefits: We provide monthly stipends for internet, mobile plans, wellness perks, a one-time home office reimbursement, and company provided equipment including a MacBook and monitor.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service