Jobs · Engineering · New York

Senior Software Engineer - Security Operations

StubHub · New York, NY · 1 mo ago
Engineering$200k–$250k/yrFull-time

About the role

The Security Operations team owns incident response, threat detection, SIEM engineering, log management, and third-party security risk forming the frontline defense for StubHub's global operations. As a Senior Security Operations Engineer, you will bring deep hands-on experience in incident response and threat detection.

Responsibilities

  • Lead and coordinate security incident response end-to-end: detection, triage, containment, eradication, recovery, and post-incident review
  • Drive root cause analysis and translate findings into durable improvements to detection and prevention capabilities
  • Act as an escalation point for complex or high-severity incidents across the organization
  • Design, build, and tune detection rules, event correlation logic, and behavioral analytics across cloud, endpoint, network, and application data sources
  • Assist in maintaining a threat model for StubHub's environment and mapping detection coverage to the MITRE ATT&CK framework
  • Proactively hunt for threats and indicators of compromise across the environment
  • Collaborate with red team and pen test partners to validate detection coverage and identify gaps
  • Continually improve SIEM capabilities including data ingestion pipelines, normalization, enrichment, and alerting workflows
  • Own log collection strategy: define what gets collected, at what fidelity, and for how long across cloud providers, SaaS applications, endpoints, and internal services
  • Write and maintain parsers, ETL pipelines, and data transformation logic to ensure high-quality signal in the SIEM
  • Own and operate security tooling where needed (SIEM, SOAR, EDR, etc.)
  • Write internal software in Python, Go, or similar to automate detection, response, enrichment, and reporting workflows
  • Build integrations between security tools, internal APIs, and third-party services to accelerate analyst workflows and reduce mean time to respond
  • Develop dashboards, metrics, and reporting to communicate operational health and coverage to security leadership
  • Contribute to shared security infrastructure and internal libraries used across the security engineering organization
  • Support the third-party security program by evaluating vendor security posture, reviewing assessments, and triaging risk findings
  • Build or maintain tooling to automate third-party risk intake, tracking, and reporting
  • Collaborate with Legal, Procurement, and Engineering to ensure third-party risks are identified and remediated appropriately

Requirements

You will need 5+ years of experience in security engineering, security operations, or a related discipline. You should demonstrate, hands-on experience leading incident response efforts, including complex, multi-system investigations. Strong threat detection engineering experience is necessary, including writing detection rules, tuning alerts, building correlation logic, and reducing false positive rates at scale. Proficiency in at least one programming or scripting language (Python strongly preferred; Go, Ruby, or Bash also relevant) is essential, as you regularly write code to solve security problems, not just configure tools. Deep familiarity with SIEM platforms (e.g., Splunk, ELK, Chronicle, Panther, or similar) including query languages and data data onboarding is required. Experience with cloud environments (AWS, GCP, or Azure) and the associated log sources, threat models, and detection strategies is important. Excellent written and verbal communication skills are necessary to convey technical risk clearly to non-technical stakeholders.

Preferred Experience

  • Experience operating in a SOC environment, either in-house or as part of an MSSP
  • Familiarity with SOAR platforms and automation-driven response workflows
  • Experience with threat intelligence platforms and operationalizing threat feeds into detection pipelines
  • Prior involvement in third-party or vendor security risk programs
  • Experience at high-growth technology companies or marketplaces where scale and velocity present unique security challenges
  • Familiarity with data engineering concepts — streaming pipelines, schema design, log normalization — applied to security contexts
  • Relevant certifications (GCIH, GCIA, GCFE, OSCP, or equivalent) are a plus, but not required

Similar jobs

Senior Software Engineer

PIADA ITALIAN STREET FOODColumbus, OH· 2 days ago
$120k–$180k/yrapply on careers-thepiadagroup.icims.com

Senior Software Engineer

Delta Dental Ins.Alpharetta, GA· 2 mo ago
Information Technology$152k–$154k/yrapply on ejep.fa.us2.oraclecloud.com

Senior Software Engineer

Johns Hopkins Applied Physics LaboratoryLaurel, MD· 1 mo ago
Engineering$105k/yrapply on careers.jhuapl.edu