Security Operations Engineer
- Location
- New York, NY
- Work type
- Full Time
- Posted
- 2026-07-20
Job description
The Role:
As a Security Operations Engineer, you’ll join our small, growing security team in a hands-on, execution-focused role supporting our vulnerability management and detection programs. This is a critical role — you’ll be the bridge between security findings and engineering teams, making sure our tools, processes, and compliance posture stay effective as Arch scales. You’ll work across the organization on a variety of security projects, from vendor due diligence to infrastructure security checks.
Your responsibilities will include:
Own vulnerability scanning, triage, and remediation tracking, coordinating with engineering teams to make sure patches get deployed.
Maintain our SIEM/SOC stack and build and refine detections for DLP, IoC, and cloud vulnerabilities.
Maintain and improve security logging and audit processes to support SOC 2 and ISO 27001 requirements.
Support the team on infrastructure security checks and assist with security investigations.
Engage in cross-functional projects as a core member of a small, nimble team — including managing vendor security due diligence, refining IT asset management, and owning various security tasks based on team priorities.
Reach out to us if you have:
Experience working in a small, fast-paced security team.
Hands-on experience with vulnerability management (CVSS, patch lifecycles) and detection engineering (SIEM, log analysis, alerting).
An understanding of security fundamentals (OWASP, NIST, CIS Benchmarks, SOC 2).
Experience with cloud infrastructure security, specifically AWS (IAM, VPC, Secrets Manager).
Proficiency in scripting and automation (Python, Bash, or Go) and basic familiarity with reading code to assist with security investigations or automation tasks.
A collaborative mindset and willingness to tackle a variety of security tasks across the team.
Bonus points if you have:
Familiarity with Infrastructure as Code security (e.g., Terraform) or CI/CD pipeline security and automated scanning tools (e.g., Snyk).
Prior experience with threat modeling or security design reviews.
Relevant industry certifications (e.g., Security+, CISSP, AWS Certified Security).