Sr. Cyber Security Engineer

Posted Yesterday
Be an Early Applicant
Manila, Metro Manila, National Capital Region, PHL
In-Office
Senior level
Fintech
The Role
Lead deep incident investigations across cloud, identity, endpoint, application, and network layers; engineer high‑fidelity detections and SOAR automations; perform proactive threat hunting; enhance AI-driven SOC capabilities; mentor analysts and participate in mandatory on‑call rotation.
Summary Generated by Built In
Axos Business Center, Corp

About This Job

The Senior Security Engineer is a key technical leader within Axos Bank’s Security Engineering organization and plays a central role in transforming our traditional Security Operations Center into an AI driven, investigation centric threat response function. This lrole is not a traditional SOC analyst position—it is an engineering forward role focused on deep incident investigation, advanced threat detection engineering, proactive threat hunting, and enhancing the AI SOC platform so it can autonomously perform higher quality investigations at scale.
The ideal candidate is highly technical, curious, and hands on—comfortable analyzing complex attack patterns, engineering detections, and building automation that amplifies the speed and precision of Axos’s AI enabled SOC.

Key Responsibilities

Cybersecurity Incident Investigation

  • Lead complex security incident investigations across cloud, identity, endpoint, application, and network layers.

  • Perform root‑cause analysis, kill‑chain reconstruction, and evidence preservation with engineering‑grade depth.

  • Convert investigation findings directly into new detections, automation playbooks, and AI features to reduce recurrence and detection gaps.

  • Participate in a mandatory on‑call rotation, serving as a senior escalation point for complex security incidents—ensuring rapid, high‑quality investigative response and feeding lessons learned back into detections, automations, and the AI SOC platform.

Threat Detection Engineering

  • Design, build, and tune high‑fidelity detection logic across Splunk, SOAR, cloud platforms, and other security telemetry systems.

  • Establish repeatable processes for hypothesis‑driven detection creation, simulation, validation, and tuning.

  • Improve detection precision by reducing false positives and strengthening behavioral and contextual analytics.

Proactive Threat Hunting

  • Conduct proactive, intelligence‑driven hunts across large datasets using advanced analytics, anomaly detection, and adversary‑emulation techniques.

  • Identify unknown threats, emerging attacker behaviors, and gaps in telemetry or tooling.

  • Translate hunting insights into durable detections, AI models, automated enrichment, and new investigation workflows.

AI SOC Platform Enhancement

  • Improve the AI SOC platform’s ability to perform autonomous or semi‑autonomous investigations by contributing high‑value signals, features, and decision logic.

  • Work closely with AI and Security Engineering leadership to integrate hunting patterns, investigation heuristics, and detection insights into AI pipelines.

  • Build feedback loops that allow AI models to learn from analyst investigations and improve over time.

Automation & SOAR Engineering

  • Create high‑reliability automation workflows that handle triage, enrichment, correlation, and containment actions.

  • Collaborate with Detection Engineering and Splunk/automation teams to integrate new data sources, threat‑intelligence feeds, and enrichment pipelines.

Collaboration & Engineering Excellence

  • Work closely with SecOps, Cloud, AppSec, Detection Engineering, and AI Engineering teams to strengthen detection coverage and reduce operational friction.

  • Produce high‑quality documentation, playbooks, knowledge articles, and engineering runbooks.

  • Mentor SOC analysts, junior engineers, and cross‑team partners to uplift investigation quality and detection maturity.

Required Qualifications

  • 5+ years of experience in cybersecurity (incident response, threat detection, security engineering, or threat hunting).

  • Strong technical expertise in cloud security, identity security, endpoint telemetry, network analysis, or application security.

  • Proven ability to perform deep‑dive incident investigations involving cloud IAM, lateral movement, privilege escalation, API abuse, malware, or application‑layer threats.

  • Hands‑on experience with SIEMs (Splunk preferred), EDR tools, SOAR platforms, and automation frameworks.

  • Ability to write and tune detection rules, correlation logic, saved searches, and behavioral analytics.

  • Strong scripting ability (Python preferred) and familiarity with data analysis techniques.

  • Willingness and ability to participate in a mandatory on‑call rotation and act as a senior escalation point during high‑severity incidents.

Preferred Qualifications

  • Experience partnering with AI/ML engineering teams or contributing to AI‑assisted security tooling.

  • Background in threat intelligence, malware analysis, or offensive security (red team, adversary emulation).

  • Knowledge of cloud‑native detection patterns (AWS, Azure), identity‑based attacks, and API security.

  • Certifications such as GCIH, GCDA, GDAT, GCTI, GCFA, or equivalent are a plus.

About Axos

Born digital-first, Axos delivers financial tools and services that allow individuals, small businesses, and companies to access and manage their money how, when, and where they want. We’re a diverse team of dynamic, insightful, and independent innovators who are excited to provide technology-driven solutions that offer unbeatable value to our customers.

Axos Financial is our holding company and is publicly traded on the New York Stock Exchange under the symbol "AX" (NYSE: AX).

Learn More about working at Axos Business Center

Pre-Employment Background Check, Medical, and Drug Test:

All offers are contingent upon the candidate successfully passing a credit check, criminal background check, and pre-employment medical and drug screening. 

Equal Employment Opportunity:

Axos is an Equal Opportunity employer. We are committed to providing equal employment opportunities to all employees and applicants without regard to race, religious creed, color, sex (including pregnancy, breast feeding and related medical conditions), gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship status, military and veteran status, marital status, age, protected medical condition, genetic information, physical disability, mental disability, or any other protected status in accordance with all applicable federal, state, and local laws.

Job Functions and Work Environment:

While performing the duties of this position, the employee is required to sit for extended periods of time. Manual dexterity and coordination are required while operating standard office equipment such as computer keyboard and mouse, calculator, telephone, copiers, etc.

The work environment characteristics described here are representative of those an employee may encounter while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

Skills Required

  • 5+ years of experience in cybersecurity (incident response, threat detection, security engineering, or threat hunting).
  • Strong technical expertise in cloud security, identity security, endpoint telemetry, network analysis, or application security.
  • Proven ability to perform deep‑dive incident investigations involving cloud IAM, lateral movement, privilege escalation, API abuse, malware, or application‑layer threats.
  • Hands‑on experience with SIEMs (Splunk preferred).
  • Experience with EDR tools, SOAR platforms, and automation frameworks.
  • Ability to write and tune detection rules, correlation logic, saved searches, and behavioral analytics.
  • Strong scripting ability (Python preferred) and familiarity with data analysis techniques.
  • Willingness and ability to participate in a mandatory on‑call rotation and act as a senior escalation point during high‑severity incidents.
  • Experience partnering with AI/ML engineering teams or contributing to AI‑assisted security tooling.
  • Background in threat intelligence, malware analysis, or offensive security (red team, adversary emulation).
  • Knowledge of cloud‑native detection patterns (AWS, Azure), identity‑based attacks, and API security.
  • Certifications such as GCIH, GCDA, GDAT, GCTI, GCFA, or equivalent.

Axos Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Axos Bank and has not been reviewed or approved by Axos Bank.

  • Healthcare Strength Health coverage includes medical, dental, and vision with multiple plan choices, plus HSA/FSA options and an Employee Assistance Program. Employer HSA contributions and extras like pet insurance and onsite fitness centers at some locations expand the wellness offering.
  • Leave & Time Off Breadth Time off includes around 15 days of vacation for new hires, paid sick leave, and up to 11 company holidays annually. Availability of certain perks and holiday specifics can vary by location or subsidiary, but the baseline PTO/holiday combination is broadly competitive.
  • Retirement Support A 401(k) with company match is offered alongside additional financial programs like a 529 plan, employee mortgage loans, and banking/trading perks. Automatic enrollment and structured matching underscore tangible retirement support for longer‑tenured employees.

Axos Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Diego, CA
1,001 Employees
Year Founded: 2000

What We Do

Axos is a technology-driven financial services company providing a diverse and ever-growing range of innovative products and services for personal, business and institutional clients nationwide. Powered by exceptional team members, a clearly defined set of values and a culture that is both meritocratic and self-governing, we are transforming banking as we know it. Our mission is summed up in two words: Banking Evolved. Banking Evolved means providing products and services that are technologically superior to our competitors and that offer our customers an unbeatable value proposition. Banking Evolved means continuously innovating and excelling in the following areas: • The incubation, creation and deployment of new businesses and tools that best serve our customers; • The evolution, optimization, delivery, distribution and marketing of our products; • The harnessing of data and technology to manage our business most effectively and efficiently; and • The development and engagement of our team members. To be part of the Axos team is to live our values as your own, to work with a strong sense of individual purpose and to embody a commitment to the shared success of our business. As a meritocracy, we believe that success is earned. We reward individuals on the basis of their achievements. As a self-governing organization, we derive strength from the internal resourcefulness of each individual. We emphasize independence, goal-setting and personal accountability.

Similar Jobs

ICAP Logo ICAP

Security Engineer

Financial Services
In-Office
Manila, First District NCR, National Capital Region, PHL
2661 Employees

Mondelēz International Logo Mondelēz International

Global Mobility Advisor, MEU

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
Manila, Metro Manila, National Capital Region, PHL
90000 Employees

Smartly Logo Smartly

Technical Support

AdTech • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • Software • Generative AI
Easy Apply
Remote or Hybrid
Philippines
805 Employees

Optum Logo Optum

Senior Software Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
City of Taguig, Southern Manila District, National Capital Region, PHL
160000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account