OneApp
Security and Threat Operations Engineer
About this role
OnePay seeks a Security and Threat Operations Engineer to protect its fintech platform by building detections, investigating security events, and automating threat response across cloud and application environments. You'll work cross-functionally to translate threats into actionable monitoring, manage vulnerabilities, and maintain compliance with PCI and SOC 2 standards.
What you'll do
- Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments
- Analyze traffic patterns in APIs, authentication, and WAF telemetry to identify malicious activity and anomalies
- Develop Python-based automation and tooling for investigations, enrichment, and operational scaling
- Triage and prioritize vulnerability findings from Wiz and scanning tools to drive remediation
- Conduct end-to-end investigation of security events including containment and follow-up remediation
- Participate in threat hunting, detection tuning, and 24x7 incident response on-call rotation
What they're looking for
- Threat detection and incident response (5+ years)
- Python programming for automation and tooling
- SIEM and detection platform configuration
- Cloud security (AWS preferred) and cloud-native environments
- API and authentication security analysis
- Vulnerability management and triage
- Observability platforms (CloudWatch, Datadog)
- Threat modeling and risk prioritization
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
OneApp
OneApp builds a consumer fintech platform offering financial services like cash advances and banking transactions, backed by Walmart. The company is hiring software engineers, frontend engineers, mobile engineers, and support engineers to develop scalable, mobile-first financial products and customer-facing applications.
View all jobs at OneAppLikely interview questions
- Walk us through how you've built and tuned detections in a SIEM to reduce false positives while maintaining visibility into real attacks.
- Describe a time you investigated a complex security event—how did you scope the incident and coordinate remediation?