Senior Security Operations Analyst (Detection & Response)
About Point
β¨ Real Impact, Real People: Our mission at Point is to make homeownership more valuable and accessible. Your work directly helps homeowners access their wealth, achieve financial flexibility, and realize life changing goals.
β¨ Funding: With over $175M raised from top investors like Andreessen Horowitz, WestCap, Greylock, and Prudential, weβre scaling fast! You have the opportunity to join us at a pivotal stage.
β¨ Game-changing Product: We're building a category defining company in home equity. Weβve earned a 4.7 Trustpilot rating and an A+ from the BBB, a testament to the value we provide to our 20,000+ customers.
β¨ Great Place to Work: Our employees love working here! We are a Certified Great Place to Work and a Fortune Best Workplaces in the Bay Area.
β¨ Remote First Culture, Genuine Connection: Work from anywhere in the U.S., while staying closely connected through virtual collaboration, team gatherings, and a people-first culture.
Local or 100% Remote
About the role
Point Digital Finance is expanding its Information Security function, and this is the team's first dedicated monitoring and response hire β a high-visibility role with immediate, measurable impact. As Senior Security Operations Analyst (Detection & Response), you will be the second half of an incident-response rotation, partnering directly with the security lead to detect, investigate, and contain threats across a regulated consumer-finance environment that protects the financial data of hundreds of thousands of homeowners. This is not an alert-watching seat: you will engineer the detections, automate the response, and harden how we see our AWS, Google Workspace, and SaaS estate. You'll help stand up a modern detection & response practice from an early-stage footing, with the autonomy to own problems end to end and the mandate to turn noisy alerts into fast, repeatable, well-documented response. If you like building as much as responding β and want your work to directly reduce risk to real people's financial lives β this role is for you.
Check out our latest Engineering Blog to learn more about why it's a great time to join Point's Engineering team!
Your responsibilities
- Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead β triaging, investigating, and driving containment of security alerts and incidents.
- Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
- Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
- Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
- Own vulnerability management: run day-to-day vulnerability management β prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
- Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
- Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
- Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
- Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
- Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.
About you
- 5+ years of experience in security operations, incident response, SOC, or detection engineering (mid-to-senior individual contributor).
- Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
- Strong SI