Jobs · Information Technology

Senior Security Operations Analyst (Detection & Response)

Point · United States · 1 wk ago
RemoteRemoteInformation Technology$151k–$167k/yrFull-time

Point is on a mission to make homeownership more valuable and accessible. Your work directly helps homeowners access their wealth, achieve financial flexibility, and realize life-changing goals. Backed by over $175M from top investors like Andreessen Horowitz, WestCap, Greylock, and Prudential, Point is scaling fast and building a category-defining company in home equity. With a 4.7 Trustpilot rating, an A+ from the BBB, and 20,000+ customers, we’re a Certified Great Place to Work and a Fortune Best Workplace in the Bay Area. We’re remote-first, with a people-first culture that values genuine connection and collaboration from anywhere in the U.S.

About the role

Point Digital Finance is expanding its Information Security function, and this is the team's first dedicated monitoring and response hire—a high-visibility role with immediate, measurable impact. As Senior Security Operations Analyst (Detection & Response), you will be the second half of an incident-response rotation, partnering directly with the security lead to detect, investigate, and contain threats across a regulated consumer-finance environment that protects the financial data of hundreds of thousands of homeowners.

This is not an alert-watching seat: you will engineer the detections, automate the response, and harden visibility across our AWS, Google Workspace, and SaaS estate. You'll help stand up a modern detection & response practice from an early-stage footing, with the autonomy to own problems end-to-end and the mandate to turn noisy alerts into fast, repeatable, well-documented response. If you like building as much as responding—and want your work to directly reduce risk to real people's financial lives—this role is for you.

Responsibilities

  • Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead—triaging, investigating, and driving containment of security alerts and incidents.
  • Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
  • Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
  • Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
  • Own vulnerability management: run day-to-day vulnerability management—prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
  • Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
  • Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
  • Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
  • Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
  • Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.

Requirements

  • 5+ years of experience in security operations, incident response, SOC, or detection engineering (mid-to-senior individual contributor).
  • Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
  • Strong SIEM skills—authoring and tuning detections, correlation rules, and dashboards (Coralogix, Splunk, Elastic, Microsoft Sentinel, or similar).
  • Practical cloud security experience in AWS and Google Workspace, including identity and log sources.
  • Demonstrated ability to investigate and contain incidents end-to-end—e.g., phishing/AiTM, account takeover, business email compromise, and cloud/identity threats.
  • Working knowledge of vulnerability management and coordinating remediation with engineering teams.
  • Scripting and automation ability (Python or similar) for detection-as-code and SOAR-style workflows.
  • Clear written and verbal communication—able to produce runbooks, metrics, and audit-ready documentation.
  • Comfortable operating with autonomy on a small team and owning problems end-to-end.
  • Authorized to work in the United States, and able to participate in an off-hours on-call rotation.

Nice to have

  • Hands-on experience using AI/LLMs for security analysis, investigation, and alert engineering (detection authoring, correlation, tuning, and automation).
  • Experience in a regulated financial-services or fintech environment (GLBA, NYDFS Part 500, SOC 2).
  • Relevant certifications (e.g., GCIA, GCIH, GCED, GIAC, CySA+, Security+, or AWS Security Specialty).
  • Experience standing up detection & response practices from an early or greenfield state.

Pay

Compensation at Point will be determined by skills, experience, and geographic location. Point has identified the expected annual base salary for this role at this level based on the market by tiers:

  • Tier 1 | San Francisco Bay Area, New York, and Seattle: $151,050 - $166,950
  • Tier 2 | Austin, Boston, Chicago, Denver, Los Angeles, Miami, Philadelphia, Portland, Sacramento, San Diego, Santa Barbara & Washington DC: $127,300 - $140,700
  • Tier 3 | All other US metro areas: $117,800 - $130,200

This does not include equity, benefits, or perks. At the offer stage, final compensation is determined using interview signals, experience, location, and other job-related factors.

Schedule

This is a remote position. Candidates must reside in one of Point’s states of operation: AL, AR, AZ, CA, CO, CT, DC, FL, GA, IL, KS, KY, MA, MD, ME, MI, MN, MO, NC, NH, NJ, NV, NY, OH, OR, PA, SC, TN, TX, UT, VA, WA, WI.

Benefits

  • Generous health benefits: Comprehensive medical, dental, and vision plans with options for flexible spending accounts (FSA) and health savings accounts (HSA).
  • Unlimited paid time off: Recharge with unlimited paid time off and 10 company holidays.
  • Flexible remote and onsite work: Support for fully remote work and an in-person environment in downtown Palo Alto, CA HQ.
  • Fully paid parental leave: Point supplements state Paid Family Leave (PFL) so employees receive 100% of their regular base pay, plus two additional weeks of fully paid leave after state PFL ends. In states without PFL, Point offers up to 8 weeks of paid parental leave. Employees also receive 4 weeks of fully paid transition time, during which you may work 2–3 days per week while receiving full base pay.
  • Equity: Meaningful equity to share in the value you help create.
  • Financial wellness: 401K retirement plans, guaranteed life insurance, and short- and long-term disability coverage.
  • Extra work/life benefits: Monthly stipends for internet, mobile plans, wellness perks, a one-time home office reimbursement, and company-provided equipment including a MacBook and monitor.

Similar jobs