×
Register Here to Apply for Jobs or Post Jobs. X

Senior Software Engineer - Security Operations

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-07-31
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 200000 - 250000 USD Yearly USD 200000.00 250000.00 YEAR
Job Description & How to Apply Below

Stub Hub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want Stub Hub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world.

The Security Operations team owns incident response, threat detection, SIEM engineering, log management, and third-party security risk forming the frontline defense for Stub Hub's global operations.

As a Security Operations Engineer you will bring deep hands‑on experience in incident response and threat detection. You will help extend the existing tooling, automation, and detection infrastructure that enables the team to operate s is not a purely operational role; we are looking for an engineer who writes production-quality code to solve security problems, architects detection pipelines, and help mature Stub Hub’s SOC-less approach to Detection & Response.

You will work closely with Cloud and Infrastructure Security, Identity Engineering, and cross‑functional stakeholders. Your work will directly shape how Stub Hub detects, responds to, and learns from threats.

Location:

Hybrid (3 days in office/2 days remote) – New York, NY or Century City, CA

What You’ll Do:
  • Incident Response
  • Lead and coordinate security incident response end-to-end: detection, triage, containment, eradication, recovery, and post‑incident review
  • Develop and maintain incident response playbooks
  • Drive root cause analysis and translate findings into durable improvements to detection and prevention capabilities
  • Act as an escalation point for complex or high‑severity incidents across the organization
  • Threat Detection
  • Design, build, and tune detection rules, event correlation logic, and behavioral analytics across cloud, endpoint, network, and application data sources
  • Assist in maintaining a threat model for Stub Hub's environment and mapping detection coverage to the MITRE ATT&CK framework
  • Proactively hunt for threats and indicators of compromise across the environment
  • Collaborate with red team and pen test partners to validate detection coverage and identify gaps
  • SIEM & Log Engineering
  • Continually improve SIEM capabilities including data ingestion pipelines, normalization, enrichment, and alerting workflows
  • Own log collection strategy: define what gets collected, at what fidelity, and for how long across cloud providers, SaaS applications, endpoints, and internal services
  • Write and maintain parsers, ETL pipelines, and data transformation logic to ensure high‑quality signal in the SIEM
  • Own and operate security tooling where needed (SIEM, SOAR, EDR, etc.)
  • Security Automation & Tooling
  • Write internal software in Python, Go, or similar to automate detection, response, enrichment, and reporting workflows
  • Build integrations between security tools, internal APIs, and third‑party services to accelerate analyst workflows and reduce mean time to respond
  • Develop dashboards, metrics, and reporting to communicate operational health and coverage to security leadership
  • Contribute to shared security infrastructure and internal libraries used across the security engineering organization
  • Third‑Party Security
  • Support the third‑party security program by evaluating vendor security posture, reviewing assessments, and triaging risk findings
  • Build or maintain tooling to automate third‑party risk intake, tracking, and reporting
  • Collaborate with Legal, Procurement, and Engineering to ensure third‑party risks are identified and remediated appropriately
What You’ve Done:
  • 3+ years of experience in security engineering, security operations, or a related discipline
  • Demonstrated, hands‑on experience leading incident response efforts, including complex, multi‑system investigations
  • Strong threat detection engineering experience: writing detection rules, tuning alerts, building correlation logic, and reducing false positive rates at scale
  • Proficiency in at least one…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary