freehire is live on Product Hunt today.

Support the launch →

Senior Security Operations Engineer (Security Operations & AI-Driven Defense)

Summary

Builds AI-driven security systems to proactively detect, respond to, and prevent threats in a high-scale fintech trading platform. Focuses on SIEM optimization, automated threat hunting, cloud security hardening, and integrating security into DevOps workflows.

We’re not hiring a security engineer to keep up with threats. We’re hiring someone to make threats irrelevant before they become incidents.

Most security teams react. They tune SIEM rules after the alert fires. They write playbooks after the incident closes. They patch after the scan flags. At Deriv, we’re building an autonomous security operations platform that hunts proactively, responds automatically, and learns continuously. Real money, real regulations, real consequences — and a security function built to match.



Why This Matters

Deriv’s mission is Trading for Anyone, Anywhere, Anytime. Millions of traders across the globe, around the clock, across regulatory environments. At this scale, a misconfigured WAF rule or undetected lateral movement isn’t a technical inconvenience — it’s a trader’s funds at risk and a regulator on the phone.

Our Security Operations team isn’t defending a perimeter. We’re protecting a living, distributed system that processes transactions 24/7. When the threat surface never sleeps, your detection and response capabilities can’t either — which is exactly why we’re embedding AI and automation at every layer of the security stack.



Why Deriv

We’re already in production, not planning:
  • Automated security review on every pull request — continuous code-level scanning, not quarterly audits
  • Dozens of fraud detection models running continuously in production, protecting real transactions at scale
  • AI-driven anomaly detection across identity, endpoint, and network telemetry
  • 400+ internal users on our workflow orchestration platform — including security response workflows


Scope of Work

You’ll own outcomes across Security Operations with focus on four areas:

  • Threat Detection & Response — SIEM optimisation, EDR/XDR tuning, incident investigation, threat hunting
  • AI-Driven Defence — Anomaly detection models, UEBA, automated triage, phishing detection pipelines
  • Security Hardening — Cloud security posture (AWS, GCP, Azure), WAF/CDN configuration, SSO and IAM policy enforcement
  • Cross-functional Security — Integrating controls into engineering workflows, CI/CD pipelines, and DevOps processes



What You’ll Do

Detect and Hunt
  • Build detection logic that fires early: Extend SIEM custom rules, AI-powered anomaly baselines, and automated alert enrichment that reduce noise and surface what matters.
  • Run threat hunts with hypotheses, not hunches: Use behavioural analytics, log forensics, and threat intelligence to surface adversarial activity hiding below the alert threshold.
  • Tune signal, not noise: Optimise EDR/XDR configurations to cut false positives and make attack visibility actionable — not overwhelming.
Automate the Response
  • Replace manual triage with intelligent playbooks: Build incident response automation that contains threats in minutes, not hours.
  • Encode institutional knowledge into systems: When a senior analyst’s six-step response becomes a runbook, you turn it into a workflow that runs at 3am without them.
  • Ship real-time visibility: Build automated dashboards tracking detection coverage, active incidents, misconfiguration trends, and policy compliance — for the team and for leadership.
Harden the Perimeter
  • Review configurations before attackers do: Run security assessments across cloud, endpoint, network, and application layers — mapping gaps against MITRE ATT&CK, CIS, and NIST benchmarks.
  • Enforce Zero Trust in practice, not just policy: Work with IT and Engineering to close IAM gaps, apply least privilege across cloud workloads, and strengthen MFA and conditional access controls.
  • Protect the build pipeline: Ensure container security, CI/CD guardrails, and automated compliance scanning prevent vulnerabilities from reaching production.



Who You Are
  • 8+ years in security operations — incident response, threat detection, or blue team work. You know what attacks actually look like in logs, not just textbooks.
  • Your SIEM is a weapon, not a logging system: You write custom detection rules, tune thresholds, and build correlation logic. You’ve reduced false positives by an order of magnitude at least once.
  • You automate before you escalate: Python, Bash, or Terraform is how you respond to repetitive problems. When a manual step happens twice, you script it the third time.
  • You understand AI’s role in security — and its limits: You’ve worked with ML-based anomaly detection, UEBA, or AI-driven phishing models. You know where they catch things humans miss, and where they need guardrails.
  • You secure cloud environments at scale: AWS, GCP, or Azure — you’ve reviewed posture, implemented compliance scanning, and closed misconfigurations before they became incidents.
  • You communicate risk, not just findings: You translate technical exposure into decisions that reach engineering leads and executives without losing accuracy.
  • Certifications are a signal, not a requirement: CISSP, GSEC, AWS Security Specialty, or equivalent. What matters is what you’ve actually built and stopped.
Tech Stack
  • Languages & Automation: Python, Bash, Terraform
  • SIEM / Detection: Custom rule logic, AI-driven anomaly baselines, automated alert triage
  • Endpoint: EDR/XDR platforms, UEBA, behavioural analytics
  • Identity & Access: Okta, Google Workspace, Azure AD — SSO, MFA, conditional access
  • Cloud: AWS, GCP, Azure — security posture management, automated compliance scanning
  • Perimeter: WAF/CDN hardening, API abuse prevention, bot mitigation



The Honest Reality

This is demanding work. You’ll build systems that catch threats your colleagues haven’t seen yet — and raise findings that aren’t always welcome. You’ll tune detections where a 1% miss rate means real exposure in a regulated environment. You’ll balance moving fast in engineering culture with the security controls that make speed sustainable.

But you’ll build security operations that actually catch things — continuously, automatically, at scale. Automated security review already ships on every PR. Fraud models run in production. The investment in AI-driven defence is real, not a slide deck.

If you want to maintain existing tools and respond to tickets, this isn’t it. If you want to build security systems that render entire threat categories obsolete, it might be.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available