New

Information Security Engineer (R14207)

Remote - MX

ABOUT OPORTUN

Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

 

WORKING AT OPORTUN


Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

 

#LI-REMOTE

#LI-GK1

We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

 

California applicants can find a copy of Oportun's CCPA Notice here:  https://oportun.com/privacy/california-privacy-notice/.

 

We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...

Select...
Select...
Select...
Select...
Select...
Select...
Select...