Senior Software Engineer - Security Operations
StubHub · New York, NY
$200,000–$250,000
Jul 22, 2026
New York, NY
Jul 23, 2026
What this job asks for AI summary
A senior engineering role within a security operations team, focused on incident response, threat detection, and SIEM/log infrastructure. Day-to-day work spans leading complex investigations, building and tuning detection rules mapped to MITRE ATT&CK, writing production code in Python or Go to automate response workflows, and owning log ingestion pipelines. The role also touches third-party vendor risk and suits engineers who write software to solve security problems rather than purely operate tools.
Senior level · 5+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
Pay in the description: $200,000–$250,000
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 240 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 85–310
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
This role is a genuine hybrid between security analysis (15-1212) and software engineering (15-1252): the JD explicitly requires writing production-quality code in Python/Go to build detection pipelines, automation, and internal tooling, not just configuring security tools. 15-1212 was chosen as primary because the core mission — incident response, threat detection, SIEM engineering — is security analysis; the coding is in service of that mission.
Two office locations are listed: New York, NY and Century City (Los Angeles), CA. The CBSA is set to New York as the first-listed location; the Los Angeles-Long Beach-Anaheim, CA CBSA (31080) is an equally valid alternative.
The role is hybrid (3 days in office, 2 days remote) — not fully remote.
SIEM platform names (Splunk, ELK, Chronicle, Panther) appear in a required qualifications block with 'e.g.' framing, indicating the specific tool is interchangeable but SIEM proficiency itself is a hard gate. They are captured as alternatives under a single SIEM skill.
Cloud platform (AWS, GCP, Azure) is similarly framed as 'or' in the required section — one cloud platform is a hard gate; the specific provider is interchangeable.
Detection rule writing is extracted as a distinct required skill from the qualifications block ('writing detection rules, tuning alerts, building correlation logic') even though no single named tool is specified — it is a concrete, testable capability explicitly gated on.
SOAR, EDR, threat intelligence platforms, Go, and ETL/data engineering concepts appear under the 'Preferred Experience' section and are marked accordingly.
Certifications (GCIH, GCIA, GCFE, OSCP) are explicitly called 'a plus, but not required' — omitted from skills as they are credentials, not technologies.
No degree requirement is stated anywhere in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.