> Markdown version of [/jobs/ext/1346327-security-intrusion-analyst-ii-ato](https://www.wearedevelopers.com/jobs/ext/1346327-security-intrusion-analyst-ii-ato). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Intrusion Analyst II - ATO - **Company:** AppFolio, Inc. - **Location:** Santa Barbara, CA, United States - **Experience:** Experienced - **Salary:** $104,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Cyber Security, Fraud Prevention and Detection, Identity and Access Management, Mobile Application Software, Log Analysis, OAuth, Phishing, Security Assertion Markup Language (SAML), Session Management, Security Information and Event Management, Okta, Snowflake, Software Security, Mitre Att&ck, Information Technology, Cybercrime, Splunk - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bc1d998ad180d080 ## About the Role * Bachelor's degree in Information Security, Computer Science, or a related field, or equivalent practical experience. * 3-5 years of experience in incident response, fraud investigation, or security operations with a focus on user or application security. * Hands-on experience with identity and access management systems (e.g., Okta, Duo, or similar). * Experience investigating ATOs or credential-based threats using logs from SIEM, IAM, and behavioral analytics platforms. Familiarity with common ATO tactics (e.g., credential stuffing, phishing, session reuse) and the MITRE ATT&CK framework. * Strong analytical skills with the ability to recognize subtle patterns across disparate data sources. Proficiency in log analysis and querying tools (e.g., Splunk, Snowflake) to investigate activity and develop detections. * Ability to work independently and cross-functionally in a fast-paced, customer-impacting environment. * Excellent verbal and written communications skills Nice to have * Experience building detections for ATO or fraud-related activity in a SaaS environment. * Familiarity with fraud signals such as IP reputation, device fingerprinting, geolocation anomalies, and behavioral risk scoring. * Cyber Security certifications such as GIAC GCIH, GCFA, GCFE, or AWS Security Specialty. * Understanding of OAuth, SAML, and session management in web and mobile applications. * Experience working with customer support, fraud, and legal teams in the context of user-impacting security events. ## Description We're innovators, changemakers, and collaborators. We're more than just a software company - we're pioneers in cloud and AI who deliver magical experiences that make our customers' lives easier. We're revolutionizing how people do business in the real estate industry, and we want your ideas, enthusiasm, and passion to help us keep innovating. We seek a highly skilled and motivated Information Security Analyst to join our security team. This role is critical in ensuring the protection of our organization's assets, monitoring security events, and responding to cyber threats. The ideal candidate will have excellent verbal and written communication skills, deep technical knowledge, strong analytical skills, and a passion for staying ahead of emerging threats. Your impact * Monitor security alerts and events to detect, investigate, and respond to cybersecurity incidents in real-time. * Investigate suspected Account Takeover (ATO) cases by analyzing authentication logs, user behavior, device intelligence, and related signals across AppFolio's platform. * Identify, contain, and remediate fraudulent activity associated with compromised accounts to minimize customer impact. * Collaborate closely with customer support, fraud, and engineering teams to triage reports, escalate critical threats, and support impacted users. * Develop detection logic and alerting mechanisms that identify early indicators of ATO attempts using SIEM, identity platforms, and threat intelligence. * Perform root cause analysis of account compromises and contribute to process improvements to prevent recurrence. * Build and maintain investigation runbooks, documentation, and workflows specific to ATO detection, response, and customer notification. * Analyze emerging attack trends targeting SaaS authentication flows, such as phishing, session hijacking, and token theft, to evolve defenses. * Contribute to internal training and knowledge sharing around ATO patterns, prevention, and investigative techniques. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)