Senior Security Engineer, Security Operations
Listed on 2026-02-01
-
IT/Tech
Cybersecurity, IT Consultant
About Good Leap
Good Leap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy‑efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on Good Leap’s proprietary, AI‑powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations.
Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
Good Leap is also proud to support our award‑winning nonprofit, Give Power, which is building and deploying life‑saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position SummaryThe Good Leap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of Good Leap’s customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of Good Leap systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within Good Leap to design, build, implement, and operate security and fraud monitoring, detection, and response capabilities.
Your Oversight Will Encompass- Security & Fraud Monitoring, Detection, and Response
:
Identification of potential misuse and abuse cases, determining corresponding events associated with manifestation of such scenarios, design of identification and detection solutions –e.g., correlated/iterative event searches across log sources ranging from infrastructure to applications/SaaS platforms, testing, implementation, monitoring, and fine‑tuning of these solutions, etc. - Toolset design and operations
:
Design and build the monitoring, detection, and response platform, from tool selection and integration – e.g., SIEM, SOAR, agentic SOC, EDR, to daily operations/management - Incident Response
:
Play a leading role in the definition, refinement, and execution of incident response activities. - Overall Security Operations
:
Management and operation of security platforms/solutions outside monitoring, detection, and response platform. - Support Embedded Product Security Team
:
Design, build, and implement monitoring and detection solutions for Good Leap products and services.
Job Duties & Responsibilities
- Lead, participate in, and contribute to security and fraud monitoring, detection, and response activities, inclusive of investigations, threat hunting, etc. Create playbooks for specific incident response scenarios.
- Identify potential misuse and abuse cases in enterprise systems, propose solutions to detect these scenarios, and identify and implement monitoring and detection solutions for such scenarios.
- Support or develop components of the security analytics platform.
- Support embedded (product) security team.
- Support general security operations team with vulnerability management, tools management, and more.
- Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non‑technical audiences.
- Expertise in security event management, monitoring, threat hunting, incident response, playbook creation, orchestration/automations, etc.
- Experience with threat modeling methodologies.
- Expertise with EDR solutions/platforms, such as Crowd Strike, S1, Palo Alto Cortex EDR, etc.
- Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, Cloud Trail,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).