Senior Security Operations Analyst (Detection & Response)

Point Digital FinanceSan Francisco, CA
Remote

About The Position

Point Digital Finance is expanding its Information Security function, and this is the team's first dedicated monitoring and response hire — a high-visibility role with immediate, measurable impact. As Senior Security Operations Analyst (Detection & Response), you will be the second half of an incident-response rotation, partnering directly with the security lead to detect, investigate, and contain threats across a regulated consumer-finance environment that protects the financial data of hundreds of thousands of homeowners. This is not an alert-watching seat: you will engineer the detections, automate the response, and harden how we see our AWS, Google Workspace, and SaaS estate. You'll help stand up a modern detection & response practice from an early-stage footing, with the autonomy to own problems end to end and the mandate to turn noisy alerts into fast, repeatable, well-documented response. If you like building as much as responding — and want your work to directly reduce risk to real people's financial lives — this role is for you. Check out our latest Engineering Blog to learn more about why it's a great time to join Point's Engineering team!

Requirements

  • 5+ years of experience in security operations, incident response, SOC, or detection engineering (mid-to-senior individual contributor).
  • Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
  • Strong SIEM skills — authoring and tuning detections, correlation rules, and dashboards (Coralogix, Splunk, Elastic, Microsoft Sentinel, or similar).
  • Practical cloud security experience in AWS and Google Workspace, including identity and log sources.
  • Demonstrated ability to investigate and contain incidents end to end — e.g., phishing/AiTM, account takeover, business email compromise, and cloud/identity threats.
  • Working knowledge of vulnerability management and coordinating remediation with engineering teams.
  • Scripting and automation ability (Python or similar) for detection-as-code and SOAR-style workflows.
  • Clear written and verbal communication — able to produce runbooks, metrics, and audit-ready documentation.
  • Comfortable operating with autonomy on a small team and owning problems end to end.
  • Authorized to work in the United States, and able to participate in an off-hours on-call rotation.

Nice To Haves

  • Hands-on experience using AI/LLMs for security analysis, investigation, and alert engineering (detection authoring, correlation, tuning, and automation).
  • Experience in a regulated financial-services or fintech environment (GLBA, NYDFS Part 500, SOC 2).
  • Relevant certifications (e.g., GCIA, GCIH, GCED, GIAC, CySA+, Security+, or AWS Security Specialty).
  • Experience standing up detection & response practices from an early or greenfield state.

Responsibilities

  • Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead — triaging, investigating, and driving containment of security alerts and incidents.
  • Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
  • Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
  • Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
  • Own vulnerability management: run day-to-day vulnerability management — prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
  • Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
  • Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
  • Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
  • Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
  • Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.

Benefits

  • Equity
  • Benefits
  • Perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service