Security Intrusion Analyst II - ATO

AppFolio, Inc.
Dallas, TX, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$104,000.0 - $130,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Software as a Service Cyber Security Fraud Prevention and Detection Identity and Access Management Mobile Application Software Log Analysis OAuth Phishing Security Assertion Markup Language (SAML) Session Management
+8 more
Security Information and Event Management Okta Snowflake Software Security Mitre Att&ck Information Technology Cybercrime Splunk

Job description

We’re innovators, changemakers, and collaborators. We’re more than just a software company - we’re pioneers in cloud and AI who deliver magical experiences that make our customers’ lives easier. We’re revolutionizing how people do business in the real estate industry, and we want your ideas, enthusiasm, and passion to help us keep innovating.

We seek a highly skilled and motivated Information Security Analyst to join our security team. This role is critical in ensuring the protection of our organization’s assets, monitoring security events, and responding to cyber threats. The ideal candidate will have excellent verbal and written communication skills, deep technical knowledge, strong analytical skills, and a passion for staying ahead of emerging threats.

Your impact

  • Monitor security alerts and events to detect, investigate, and respond to cybersecurity incidents in real-time.
  • Investigate suspected Account Takeover (ATO) cases by analyzing authentication logs, user behavior, device intelligence, and related signals across AppFolio’s platform.
  • Identify, contain, and remediate fraudulent activity associated with compromised accounts to minimize customer impact.
  • Collaborate closely with customer support, fraud, and engineering teams to triage reports, escalate critical threats, and support impacted users.
  • Develop detection logic and alerting mechanisms that identify early indicators of ATO attempts using SIEM, identity platforms, and threat intelligence.
  • Perform root cause analysis of account compromises and contribute to process improvements to prevent recurrence.
  • Build and maintain investigation runbooks, documentation, and workflows specific to ATO detection, response, and customer notification.
  • Analyze emerging attack trends targeting SaaS authentication flows, such as phishing, session hijacking, and token theft, to evolve defenses.
  • Contribute to internal training and knowledge sharing around ATO patterns, prevention, and investigative techniques.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent practical experience.
  • 3-5 years of experience in incident response, fraud investigation, or security operations with a focus on user or application security.
  • Hands-on experience with identity and access management systems (e.g., Okta, Duo, or similar).
  • Experience investigating ATOs or credential-based threats using logs from SIEM, IAM, and behavioral analytics platforms. Familiarity with common ATO tactics (e.g., credential stuffing, phishing, session reuse) and the MITRE ATT&CK framework.

  • Strong analytical skills with the ability to recognize subtle patterns across disparate data sources. Proficiency in log analysis and querying tools (e.g., Splunk, Snowflake) to investigate activity and develop detections.

  • Ability to work independently and cross-functionally in a fast-paced, customer-impacting environment.
  • Excellent verbal and written communications skills

Nice to have

  • Experience building detections for ATO or fraud-related activity in a SaaS environment.
  • Familiarity with fraud signals such as IP reputation, device fingerprinting, geolocation anomalies, and behavioral risk scoring.
  • Cyber Security certifications such as GIAC GCIH, GCFA, GCFE, or AWS Security Specialty.
  • Understanding of OAuth, SAML, and session management in web and mobile applications.
  • Experience working with customer support, fraud, and legal teams in the context of user-impacting security events.

Benefits & conditions

The base salary/hourly wage that we reasonably expect to pay for this role is: $104,000-$130,000

The actual base salary/hourly wage for this role will be determined by a variety of factors, including but not limited to: the candidate’s skills, education, experience, etc.

Please note that base pay is one important aspect of a compelling Total Rewards package. The base pay range indicated here does not include any additional benefits or bonuses/commissions that you may be eligible for based on your role and/or employment type.

Regular full-time employees are eligible for benefits - see here.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:27 min

Reviewing modern authentication workflows and telecom integrations

Alvaro Navarro · World Congress 2024

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all