We are looking for a hands-on Senior Security Engineer to own and improve security operations across our corporate IT, cloud, and Kubernetes environments. The role covers security monitoring and detection, incident response, security tooling and integrations, automation, and day-to-day IT security.
What You'll Do- Own security monitoring, triage, investigation, and incident response across endpoint, identity, email, network, SaaS, GCP, and GKE environments.
- Operate and improve security capabilities across SIEM, EDR, DLP, cloud security, network security, and identity security.
- Integrate security tools and telemetry into the SOC to improve visibility, correlation, investigation, and response.
- Build and tune detections, correlation rules, alerts, dashboards, and monitoring use cases based on attack scenarios and observed activity.
- Build automated workflows for alert enrichment, triage, investigation, containment, escalation, and response using APIs and scripting.
- Investigate incidents end-to-end, including scoping, evidence collection, root-cause analysis, containment, remediation, and post-incident actions.
- Monitor and investigate GCP and GKE activity, including IAM changes, service-account activity, cloud audit events, Kubernetes activity, workload behaviour, and network events.
- Identify gaps and misconfigurations across cloud IAM, Kubernetes RBAC, workloads, containers, secrets, network controls, logging, and security configurations.
- Manage and tune DLP controls and investigate potential data-exfiltration or policy-violation events.
- Investigate phishing and account-compromise activity, including email headers, URLs, domains, attachments, authentication events, and indicators of compromise.
- Support IT security across endpoints, device posture, identity and access, SaaS applications, privileged access, and security configurations.
- Work with infrastructure and engineering teams to remediate security findings and improve logging, detection coverage, and preventive controls.
- Maintain practical incident-response playbooks, detection documentation, and investigation procedures.
- 5–7 years of hands-on cybersecurity experience, with strong experience in security operations, security engineering, or incident response.
- Strong hands-on experience with SIEM and EDR, including log analysis, detection development, alert tuning, investigation, and response.
- Experience integrating security technologies and telemetry using APIs, webhooks, scripts, or automation/orchestration platforms.
- Experience building and automating SOC and incident-response workflows rather than relying entirely on manual triage.
- Hands-on experience securing and monitoring Google Cloud Platform (GCP).
- Strong understanding of GCP IAM, service accounts, audit logging, VPC networking, storage, KMS, and cloud security controls.
- Hands-on security experience with Kubernetes/GKE, including RBAC, service accounts, namespaces, secrets, network policies, workload security, container security, and audit logging.
- Ability to investigate activity across cloud control-plane, Kubernetes, container/workload, identity, and network telemetry.
- Good understanding of DLP and experience tuning policies and investigating data-security events.
- Strong networking fundamentals, including DNS, HTTP/S, TCP/IP, VPNs, proxies, firewalls, and network traffic analysis.
- Experience investigating phishing, credential compromise, endpoint threats, suspicious network activity, cloud events, and container/Kubernetes security events.
- Understanding of common attacker behaviours and techniques, including privilege escalation, credential abuse, persistence, lateral movement, and data exfiltration.
- Working knowledge of MITRE ATT&CK and its practical application to detection and investigation.
- Hands-on scripting or automation experience with Python, shell scripting, or similar technologies.
- Ability to independently take a security event from initial detection through investigation, containment, remediation, and closure.
- Experience building or maturing a SOC/security operations capability in a cloud-first environment.
- Experience with security orchestration and automated response.
- Experience with cloud security posture management, vulnerability management, and container/workload security.
- Experience developing custom detections using telemetry from multiple security and infrastructure sources.
- Familiarity with Infrastructure-as-Code and CI/CD security from an operational security perspective.
Skills Required
- 5+ years driving security and compliance in dynamic, regulated environments securing cloud-native platforms and hybrid infrastructures
- Deep expertise with GCP security (IAM, KMS, VPC Service Controls, Cloud Logging/Audit, WAF, SecOps) and Kubernetes application hardening
- Strong Infrastructure-as-Code skills (Terraform or equivalent) and GitOps experience (ArgoCD, Flux)
- Proficiency in Python scripting and policy-as-code frameworks (OPA, Gatekeeper)
- Experience with monitoring, logging, SIEM exports, alerting, and building incident response runbooks
- Excellent communicator able to translate technical findings into clear policies and remediation plans
- Familiarity with fintech and portfolio-management standards and supporting distributed, remote teams
- Familiarity with multi-cloud security controls
- Security certifications (GCP Professional Security Engineer, CISSP, CKA/CKS)
- Experience with service mesh (Istio/Anthos) or zero-trust architectures
What We Do
Arcana enables institutional investors to understand their portfolio risks, decompose single stock & book performance, drill into crowding, and isolate their idiosyncratic differentiation. Built on our proprietary crowding, ownership, factor risk, and performance datasets. The company's investors include D1 Capital, Duquesne (Stan Druckenmiller), Tiger Global, Abstract Ventures, GoldenTree Asset Management, Ryan Roslansky (CEO LinkedIn), and Akshay Kothari (COO Notion), among others.








