Our mission is to enable effortless credit based on true risk.
Security Operations Engineer II
Location
United States
Posted
8 days ago
Salary
$134.1K - $185.6K / year
Seniority
Mid Level
Job Description
Security Operations Engineer II
Upstart
• Work closely with system owners to ingest new log feeds for security monitoring • Enhance and maintain our Detection and Response platforms • Build in workflows with AI analysis to automatically investigate and triage issues • Be on the frontlines of Incident Response, actively investigating issues and protecting Upstart • Build common response workflows to expedite investigation and response using AI and SOAR Technology
Job Requirements
- 2 years of Incident Detection and Response Engineering experience
- Assume breach mindset, chasing down all threads to completion
- Strong Log-fu (ability to build robust log search queries)
- Solid Proficiency in at least one programming language (preferably Python)
- Strong Git experience (rebasing doesn't scare you!)
Benefits
- Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly
- Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US, CAD in Canada)
- Employee Stock Purchase Plan (ESPP) with discounted stock purchase options for eligible employees (US only)
- Comprehensive health coverage designed to support you and your family, including medical, dental, vision, and wellness resources for US and supplemental health coverage for Canada.
- Health Savings Account contributions from Upstart for eligible plans (US only)
- Income protection benefits, including life insurance and disability coverage for added financial security
- Paid time off, sick leave, and company holidays, in line with local requirements
- Paid family and parental leave to support caregiving and major life moments (duration varies by country)
- Family-centered benefits to support fertility, parenthood, and caregiving needs
- Employee Assistance Program (EAP) offering mental health support and life-centered resources
- Financial wellness resources, including access to financial planning tools and a financial concierge service (US Only)
- Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you
- Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from
- Connection and community through team events, all-company updates, and employee resource groups (ERGs)
- Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our offices in the Bay Area, Austin, Columbus, and New York City (opening Summer 2026!)
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Designing and implementing secure architectures across cloud environments, embedding zero-trust principles and identity-based access controls. • Managing threat detection, vulnerability assessments, and penetration testing to identify and remediate risks proactively. • Leading incident response and leveraging threat intelligence to detect, contain, and prevent evolving cyber threats. • Ensuring compliance with global security standards (ISO 27001, NIST 800-53, CIS, OWASP, SOC 2, CSA) and continuously improving Collibra’s security posture. • Supporting internal and external security audits by providing necessary documentation and evidence.
• Lead, coach, and develop a growing cybersecurity team • Drive the execution of enterprise cybersecurity initiatives and priorities • Oversee cybersecurity operations, including threat detection, monitoring, and incident response • Partner with business and technology leaders to integrate cybersecurity into key decisions and processes • Support compliance with regulatory, audit, privacy, and industry security requirements
Role Description This project will optimize the agency's CrowdStrike SIEM and related CrowdStrike services to improve threat detection, monitoring, and response capabilities. The contractor will expand and tune telemetry, integrate additional high-value log sources, enhance security dashboards, and support the rollout of additional CrowdStrike services. The effort will increase visibility into endpoint and security risk, improve signal quality and correlation, and provide security leadership with clear insight into security operations effectiveness and overall risk posture. Expected Outcomes - Expanded and optimized CrowdStrike SIEM telemetry coverage - Integration of additional high-value log sources - Improved dashboards for operational and executive visibility - Enhanced detection fidelity and monitoring effectiveness - Clearer insight for leadership into endpoint risk and security operations performance Duties to Be Performed - Assess current CrowdStrike SIEM configuration, telemetry coverage, and log ingestion - Enable and tune additional CrowdStrike telemetry to improve visibility and signal quality - Identify and integrate new high-value log sources into CrowdStrike SIEM - Develop and refine security dashboards aligned to SOC and executive use cases - Assist with technical enablement and rollout of additional CrowdStrike services - Validate data quality, parsing, and correlation within the SIEM - Coordinate with Security Operations, IT Operations, and system owners - Identify gaps, risks, and improvement opportunities in monitoring and detection - Provide weekly status updates and monthly executive-level progress summaries - Deliver supporting documentation and recommendations to sustain improvements Deliverables - Summary of work performed and capabilities delivered - Documentation supporting all telemetry enablement, log integrations, and dashboard implementations - Measurable improvements in monitoring, detection, or visibility - Recommendations for future enhancements or next-phase efforts Qualifications - Demonstrated skill with documentation, reporting, and knowledge transfer - Experience with Stakeholder Engagement and Executive Communication - Experience in SIEM Detection Engineering and Alert Optimization - Experience in Log Source Integration and Data Normalization - Hands-On Experience with CrowdStrike SIEM and Dashboard Development - Hands-On Experience with SIEM and Dashboard Development
• Strengthen DEUNA's security posture as we continue scaling our global payments platform. • Build and operate modern cloud security capabilities that protect millions of payment transactions. • Partner closely with Infrastructure, Engineering, Compliance, and Product teams to improve security maturity. • Own security monitoring, threat detection, and incident response processes. • Build and continuously improve SIEM, detection rules, alerting, and security automation. • Lead vulnerability management, remediation tracking, and risk prioritization. • Drive cloud security initiatives across AWS, Kubernetes, containers, IAM, networking, and secrets management. • Manage endpoint security, identity security, privileged access management, and access reviews. • Coordinate external penetration tests, red team exercises, and security assessments. • Develop security metrics, dashboards, and executive reporting.




