> Markdown version of [/jobs/ext/2867793-security-and-threat-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2867793-security-and-threat-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security and Threat Operations Engineer - **Company:** Nilon Global LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, User Authentication, Cloud Computing, Cyber Security, Information Leak Prevention, Cursor (Graphical User Interface Elements), Intrusion Detection and Prevention, Python (Programming Language), Node.Js, Security Information and Event Management, Software Engineering, TypeScript, Software Vulnerability Management, Web Platforms, Datadog, Cloud Platform System, Software Security, Kubernetes, React Native, Cloudwatch, NestJS, Vulnerability Analysis, Microservices - **Published:** September 12, 2026 - **Apply:** https://startup.jobs/security-and-threat-operations-engineer-one-10031263 ## About the Role * 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment. * Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise. * Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts. * Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling. * Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms. * Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination. * Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases. * Experience with at least one major cloud provider, preferably AWS. * Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs. * Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments. * Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability. * Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams. * Drive and proactivity - everyone here is a builder and executor Tools We Use We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don't need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly. ## Description As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay's products and infrastructure, ensuring the continued safety and trust of our business and customers. You will: * Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments. * Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior. * Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems. * Help operate OnePay's vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows. * Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale. * Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks. * Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation. * Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations. * Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation. ## Related Videos - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)