remote

Salary
Posted
Jul 25, 2026
Location
Last confirmed open
Jul 26, 2026

What this job asks for AI summary

A senior individual contributor role focused on running the day-to-day security operations function at a tokenized-assets finance firm. The work centers on detection engineering in a SIEM, managing EDR and email security tooling, building SOAR automations, and leading incident response end-to-end — including post-mortems and tabletop exercises. The role also covers integrating AI/LLM tooling into SecOps workflows and defining how internal AI usage is monitored.

Senior level · 3+ years · Remote · Full-time

Must have (8)
SIEM, Splunk, Panther, Elastic, Sentinel or ChronicleEDRCrowdStrike, SentinelOne or DefenderSOARPythonGitAWS, GCP or AzureLLMs
Nice to have (1)
on-chain monitoring

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 3,000 people nationally plausibly meet what this posting asks for (information security analysts). range 1,800–6,500

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
SIEM55%Python51%Splunk45%EDR40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

No work location or office is specified in the posting; the role appears fully remote based on the absence of any location requirement.

The experience requirement is stated as '3-5+ years' — the overall years minimum is set to 3 (the lower bound of the range).

The SIEM requirement names Splunk, Panther, Elastic, Sentinel, and Chronicle as acceptable options; 'deep, hands-on experience with at least one' makes this a hard gate on the capability, with any of those tools satisfying it. Splunk is also emitted separately as the primary named tool with the others as alternatives, reflecting the JD's framing.

EDR is a hard gate; CrowdStrike, SentinelOne, and Defender are listed as interchangeable options. SentinelOne is also retained as a preferred skill because it appears independently in the 'What You'll Do' section as a named deployment target alongside CrowdStrike.

Cloud security telemetry (AWS, GCP, or Azure) is required in 'at least one' — marked as a hard gate with alternatives.

AI/LLM integration into security workflows is listed as required but with an explicit 'or' escape ('or a track record of evaluating new tooling rigorously') — still marked as a hard gate on the capability given its placement in the requirements block.

On-chain monitoring tools and blockchain-aware incident response appear only under 'Nice to Have' and are marked preferred.

Email security tooling and phishing TTP knowledge are required but name no specific product; no concrete tool name was emitted per extraction rules.

No compensation figures are provided in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗