About the Role We’re looking for a Product Security Engineer to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with software engineers, infrastructure teams, and technical leadership , helping us proactively reduce risk earlier in the development lifecycle and ship securely by default. This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity. What You’ll Own In this role, you’ll: Identify and close gaps across application security, secure design review, and vulnerability management. Conduct threat modeling, secure design reviews, and code reviews to identify practical remediation paths. Partner closely with engineering teams to provide product-focused security expertise and shape a modern security program. Mature how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment. Distinguish between theoretical risk and material business risk to prioritize security efforts effectively. Improve security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails. Support security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues. Participate in security on-call rotations, helping respond to urgent security events with clear judgment and calm execution. Help manage and mature our bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams. You Might Be a Good Fit If You Have strong experience in product security, application security, or security engineering. Are comfortable working with
Jobiba hiring network
Threat Investigator Jobs
616 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current threat investigator jobs. Use filters to narrow by work mode, employment type, experience and date posted.
About the Team OpenAI’s Security organization exists to enable safe, responsible innovation at scale. As our systems, infrastructure, and research footprint grow, we invest deeply in world-class security capabilities that protect our people, products, and users without slowing progress. This organization safeguards OpenAI’s environments by building advanced detection systems, driving real-time response capabilities, scaling telemetry and logging infrastructure, and delivering actionable threat intelligence to stay ahead of adversaries. About the Role We are seeking a Global Detection and Response Lead to own and scale OpenAI’s cybersecurity detection and response operations. In this role, you will set the strategy and drive execution for security monitoring, incident response, recovery, and post-incident improvements across our global infrastructure. You will be a hands-on leader with deep technical credibility and strong operational instincts. You will build and mentor high-performing teams, partner closely with Infrastructure, Research, Product Security, Enterprise Security, IT, and Engineering, and ensure that detection and response capabilities are embedded by design into the systems that power OpenAI. This is a strategic and practical leadership role requiring deep technical credibility, operational rigor, and the ability to build high-performing teams in a fast-moving environment. In this role, you will: Oversee global detection and response operations, including continuous monitoring, triage, investigation, containment, and remediation of security events across a diverse set of networks and infrastructure. Lead, mentor, and directly manage several small teams of senior engineers across observability, detection and response, and threat intelligence. Hire and scale these functions deliberately and proportionately as OpenAI’s compute footprint and platform ambitions grow. Ensure world-class operational rigor and readiness through management of incident playbooks
About the Team The Integrity team builds the systems OpenAI uses to understand, prevent, and respond to misuse across our products. We partner with Product, Policy, Safety Systems, User Operations, Security, Legal, Privacy, OpenAI for Government, and research teams to turn policy and threat models into product controls, review workflows, measurement systems, and enforcement paths. About the Role We are hiring a Product Manager to own Integrity's product strategy for sensitive deployments: contexts where model capability, customer or deployment setting, privacy constraints, and misuse potential make the operating bar unusually high. This includes government and other high stakes deployments, regulated or high-trust enterprise contexts, zero data retention and privacy-constrained environments, and agentic workflows where harm can unfold across many steps rather than a single prompt. The Sensitive Deployments PM will focus on high-consequence use cases relevant to government deployments and broader deployment-readiness questions for high-risk domains (e.g., healthcare), while building reusable Integrity capabilities for agentic detection and enforcements in these environments. This position is based in San Francisco, CA, with relocation assistance available. In this role, you will: Own the roadmap for sensitive deployment Integrity controls and readiness criteria. Define how we measure residual risk, decision quality, review quality, and mitigation effectiveness. Build agentic investigation and context-assembly workflows for complex, multi-step misuse patterns. Partner with Policy, Legal, Privacy, Safety Systems, User Ops, Government, and product teams to build shared capabilities. Create launch and deployment playbooks for sensitive customer, capability, and product contexts. You might thrive in this role if you: Have shipped complex product systems in AI, integrity, trust and safety, security, privacy, risk, government, regulated enterprise, or AI safety. Can turn am
Spaulding Ridge is an advisory and IT implementation firm. We help global organizations get financial clarity into the complex, daily sales, and operational decisions that impact profitable revenue generations, efficient operational performance, and reliable financial management. At Spaulding Ridge, we believe all business is personal. Core to our values is our relationships with our clients, our business partners, our team, and the global community. Our employees dedicate their time to helping our clients transform their business, from strategy through implementation and business transformation. What You Will Do and Learn: The Cybersecurity Operations Analyst will support the Cybersecurity Manager in maintaining and improving Spaulding Ridge's security posture. This entry-level role is ideal for someone looking to develop a career in cybersecurity while gaining hands-on experience across security operations, vulnerability management, identity and access management, cloud security, and compliance. The analyst will assist in monitoring security events, responding to security alerts, supporting security projects, and maintaining security documentation while learning from senior members of the Technology & Security team. Security Operations Monitor and analyze security alerts from SIEM, EDR, Firewall, WAF, IDS/IPS, email security, and cloud security platforms. Conduct and Support threat hunting and detection of tuning activities. Monitors open-source and proprietary threat intelligence feeds daily to research threat actor tactics, techniques, and procedures (TTPs). Support the investigation and triage of security alerts and incidents under the guidance of the Cybersecurity Manager. Assist with incident response activities, including documentation, evidence collection, and follow-up actions. Help maintain security playbooks and operational procedures. Vulnerability Management Assist with vulnerability scanning across endpoints, servers, and cloud environments.
TextNow is on a mission to make communications affordable and accessible for everyone. As a full MVNO operating our own mobile core network over LTE and 5G NSA, we have the unique advantage of controlling our network infrastructure end-to-end. We operate the HSS, PGW, and other critical network functions, giving us the flexibility to innovate and deliver exceptional service to millions of users. About the Role Join us in our mission to break down barriers to communication and free the flow of conversation for people everywhere. T extNow is looking for a new SecOps team member to secure, monitor , and enable automated response within our infrastructure. What You’ll Do Ensure Secure & Reliable Systems: Design, implement, and maintain security-focused infrastructure to protect TextNow’s services while ensuring reliability and scalability. Security Automation & Infrastructure as Code: Develop and enforce best practices using Terraform, Ansible, Crowdstrike , and AWS security tools , ensuring secure configurations, automated compliance checks, and infrastructure as code. Threat Detection & Incident Response: Participate in an on-call rotation to respond to security incidents, investigate vulnerabilities, and implement proactive measures to prevent future threats. Work closely with engineering teams to remediate security risks. Monitoring & Logging for Security: Improve observability by implementing security monitoring solutions, logging best practices, and alerting mechanisms to detect anomalies and suspicious activity. Access Control & Identity Management: Manage IAM roles, permissions, and policies to ensure least privilege access and enforce security controls across cloud and internal systems. Collaboration & Security Advocacy: Wo
Location Details: Remote, India At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings Join Our Team... GoDaddy’s Product Security team is looking for a Security Engineer who is passionate about helping build secure products and services used by millions of customers worldwide. In this role, you will work closely with engineering and platform teams to identify security risks, improve security practices, and help embed security throughout the software development lifecycle. You will have the opportunity to learn from experienced security professionals while contributing to initiatives that improve the security and resilience of our products, platforms, and cloud environments. The ideal candidate is curious, hands-on, eager to learn, takes ownership of their work, and excited to solve security challenges at scale! What you'll get to do... Identify, assess, and help remediate security risks across applications, infrastructure, cloud environments, and AI-enabled services Partner with engineering and platform teams to design, implement, and improve security controls throughout the software development lifecycle Conduct security reviews, threat modelling, and risk assessments to help build secure, resilient, and scalable systems Develop and enhance automation, tooling, and processes that strengthen security coverage, improve detection and response capabilities, and increase operational efficiency Investigate security findings, stay informed on emerging threats and technologies, and contribute to a culture of security awareness and continuous learning Your experience should include... 2+ yea
At Franklin Templeton, we believe success is built through powerful partnerships. As a forward‑thinking asset manager, we build dynamic relationships with clients, understand their goals, and navigate complex markets together. We leverage cutting‑edge strategies and deep insights to unlock opportunities for long‑term wealth creation. Our talented, global teams bring expertise that is both broad and unique. From our welcoming, inclusive, and supportive culture to our globally diverse business, we offer opportunities not only to help you reach your potential, but also to contribute to our clients’ success. About the department: The Global Compliance Transaction Monitoring Team at Fiduciary Trust Company International helps protect the organization from money laundering, sanctions, and terrorist financing risks. The team monitors client activity, reviews higher-risk transactions, conducts sanctions screening, and supports regulatory reporting requirements. Team members work closely with compliance, risk, and business stakeholders to strengthen the firm’s control environment and support regulatory compliance across global operations. How you will add value? Core Responsibilities: You will administer the GIFTS transaction monitoring platform. You will support the Threat matrix monitoring program. You will conduct Anti-Money Laundering investigations. You will perform quality assurance reviews. You will consolidate alerts and case information. You will maintain search-list profiles within GIFTS. You will oversee daily monitoring operations activities.
About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe’s business or users. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed, working across multiple AMER time zones, and will regularly coordinate with stakeholders in EMEA and APAC. What you’ll do You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity. Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms. Responsibilities Analyze and inv
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team... We are seeking a highly skilled Senior Security Engineer to join our advanced Security Operations team. This role is focused on leading complex incident response and forensic investigations across Windows, macOS, Linux, and AWS environments while helping modernize security operations through automation and AI-driven capabilities. The ideal candidate is a hands-on security expert with deep AWS security expertise, strong threat detection and digital forensic skills, and experience leveraging AI and machine learning technologies to improve detection, response, and operational efficiency. You will play a key role in protecting critical assets, conducting high-impact investigations, mentoring team members, and driving the evolution of our security program against sophisticated and emerging threats. What You'll Get to Do... Lead high-priority incident response and forensic investigations, serving as the primary escalation point for advanced analysis, containment, recovery, root cause determination, and executive-level reporting. Drive threat detection and response across AWS, Windows, macOS, Linux, and endpoint security platforms, leveraging services such as GuardDuty, Security Hub, Detective, CloudTrail, IAM, VPC Flow Logs, and SentinelOne. Conduct malware analysis, host and cloud forensics, evidence collection, and threat hunting activi
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role: Responsible for physical security operations, investigations, executive protection support, incident response, and threat management functions across corporate environments and operational facilities. Serve as an operational leader within the broader Global Security & Investigations organization, responsible for managing day-to-day security operations, sensitive investigations, workplace violence prevention initiatives, executive protection assignments, and emergency response coordination while supporting enterprise security strategy and operational resilience. This role combines investigative expertise, operational leadership, and protective operations experience with strong judgment, crisis response capabilities, and cross-functional collaboration. The position assists with physical security operations including
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Austin, TX About the team Cloudflare’s mission is to help build a better internet and the Threat Application Services (TAS) team lives at the core of that effort. The team builds the automated services and systems that transform Cloudflare’s massive network telemetry into actionable intelligence. We empower customers with products to combat advanced threats, enabling them to query, investigate, and automatically mitigate attac
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi
ABOUT THE ROLE Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts. YOUR DAILY IMPACT AT PELOTON Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams Recommend and build countermeasures based on threat analysis, intelligence, and forecasting Develop, implement, and maintain security incident playbooks/runbooks Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . As a Security Operations Specialist on the Security Operations team, you'll defend Coinbase and its customers against some of the most sophisticated attackers in the world. This team - spanning CDRE, Insider Threat, Blockops and Threat Intelligence - protects billions of dollars in digital assets while scaling security coverage for the next billion crypto users. You'll own frontline incident response, build detection and automation capabilities, and partner across the organization to keep Coinbase safe as it launches new Web3 products globally. What you'll do: Own second-line triage and response for security alerts, leading incident management through resolution and driving post-incident improvements Build and maintain runbooks for repeatable response patterns, then define and implement automation to eliminate manual toil Partner with teams across Security Operations to develop monitoring strategies informed by attacker investigation findings Drive Security monitoring and incident response for emerging Web3 product launches Strengthen team capabilities by mentoring peers, sharing knowledge, and participating in 24/7 rotational coverage across time zones Required Skills and Experience: 3+ years of hands-on security operations experience including incident response, alert triage, and network/host forensics across cloud, SaaS, and container environments Demonstrated abi
Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way. The Community You Will Join: The Community Support org handles tens of millions of interactions yearly, engaging with Airbnb customers by phone, messaging, chat, or social media channels. The group handles hundreds of issues across categories including Cancellations, Account Issues, Refunds, Payments, Reservations, Extenuating Circumstances, Booking & Listing issues, Safety & Claims. The organization is globally distributed with offices in San Francisco, Dublin, Montreal, Seattle, Singapore, Manila, Gurgaon and an extensive partner network serving all regions. The Difference You Will Make: In this role you will own the strategic design and continuous evolution of risk frameworks, the risk registry, and executive risk narratives for Community Support — translating investigative findings, AI/ML model outputs, operational signals, and emerging threats into decisions and actions that protect Airbnb. A defining element of this role is your close partnership with the Insider Threat program. Together, you will form a complementary unit: you will ensure that investigative outcomes are contextualized within the broader risk ecosystem — informing risk appetite decisions, shaping detection strategy, and driving remediation accountability. You will co-own escalation frameworks, jointly challenge detection model effectiveness, and ensure that the feedback loop between investigations, risk governance, and AI-driven detection is robust and continuously improving. Beyond analysis and governance design, you will serve as the program manager for systemic root cause resolution — ensuring that when investigations, incident
Get new threat investigator jobs by email
Daily job updates · Unsubscribe anytime