Corporate Security Engineer

Security Engineer · Mid · Full Time

US - San FranciscoUSD 130k – 200k1d ago
Apply for this role

Opens Airwallex's application page

Role

What you'll do.

As a Corporate Security Engineer at Airwallex, you'll defend enterprise systems and employees from sophisticated threats including malware, phishing, and unauthorized access across a modern corporate environment. This highly technical role combines digital forensics, incident response, and security tool development to protect corporate IT infrastructure, endpoints, and identity providers at a rapidly scaling global fintech organization. You'll need 3+ years of security engineering experience, expertise with tools like CrowdStrike and Splunk, and a strong understanding of attacker techniques and detection methodologies.

Responsibilities

  • Incident Response and Digital Forensics: Lead and contribute to incident response efforts for malware infections, phishing campaigns, and unauthorized access incidents. Conduct thorough digital forensics investigations to determine attack vectors, scope of compromise, and remediation strategies.
  • Security Control Design and Development: Design, develop, test, and evaluate new corporate security controls tailored for a rapidly growing business environment. Implement technical solutions that balance security rigor with operational efficiency to enable fast business growth.
  • Threat Hunting and Log Analysis: Proactively hunt through security log sources using SIEM and endpoint detection platforms to identify anomalous behavior, emerging threats, and indicators of compromise across the corporate environment.
  • Security Alert and Workflow Implementation: Design and implement automated security alerts, detection rules, and incident response workflows that support the complete incident response lifecycle from detection through remediation and closure.
  • Corporate Infrastructure Security: Secure and maintain corporate IT infrastructure including identity providers, endpoints, corporate networks, and cloud platforms. Identify vulnerabilities, implement remediation measures, and maintain compliance with security standards.
  • Security Tool Deployment and Operations: Deploy, configure, and operationalize security tooling across the enterprise with a strategic focus on maximizing security impact. Manage endpoint protection, mobile device management, and identity and access management solutions.

Qualifications

What we look for.

Technical

  • Security Monitoring and SIEM Tools

    Expert-level proficiency with CrowdStrike, Splunk, or equivalent security monitoring and incident response platforms for log analysis, threat detection, and investigation.

  • Endpoint Detection and Response (EDR)

    Deep hands-on experience with EDR solutions including CrowdStrike Falcon, with ability to configure detection rules, investigate alerts, and remediate endpoints.

  • Identity and Access Management

    Working knowledge of cloud-based identity platforms like Okta and Google Workspace, including authentication mechanisms, access control policies, and security configurations.

  • Endpoint Management

    Experience with mobile device management (MDM) and endpoint management tooling such as Kandji, Intune, or similar platforms for corporate device security.

  • Cloud Security

    Practical experience securing infrastructure across cloud platforms including GCP, Alibaba Cloud, or equivalent, with understanding of cloud-native security controls.

  • Network Security and VPN

    Understanding of corporate network architecture and experience with cloud-based VPN services for secure remote access and threat detection.

  • Scripting and Automation

    Proficiency with scripting languages such as Python, Bash, or PowerShell to automate security workflows, develop detection logic, and improve incident response efficiency.

  • Digital Forensics

    Hands-on experience conducting digital forensics investigations on endpoints and systems, including evidence collection, analysis, and chain of custody.

  • Threat Analysis and Attacker Techniques

    In-depth understanding of common attacker tools and techniques (MITRE ATT&CK framework), ability to recognize malware behavior, and knowledge of detection and prevention strategies.

Education

  • Bachelor's Degree in Computer Science or Cybersecurity

    Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a closely related technical discipline required.

Experience

  • Security Engineering or Incident Response

    Minimum 3+ years of professional experience working as a security engineer, incident responder, or security operations analyst in a technology company environment.

  • Corporate Security Environment

    Experience defending corporate IT environments against real-world threats including malware, phishing, and unauthorized access attempts.

  • Investigation and Problem-Solving

    Demonstrated ability to conduct in-depth investigations with high quality analysis, strong judgment in threat assessment, and evidence-based decision making in security incidents.

  • High-Growth Startup Context

    Experience working in fast-paced, high-growth technology companies where balancing security with business velocity and rapid scaling is essential.

Skills

Required

  • CrowdStrike Falcon

    Expert-level experience with CrowdStrike endpoint detection and response platform for threat detection, investigation, and endpoint remediation.

  • Splunk

    Proficient with Splunk Security Information and Event Management for log ingestion, analysis, threat hunting, and creating detection rules.

  • Incident Response

    Ability to rapidly investigate security incidents, document findings, communicate with stakeholders, and execute remediation with high quality and thoroughness.

  • Malware Analysis and Detection

    Understanding of malware behavior, ability to detect and analyze malicious code, knowledge of detection methodologies and prevention techniques.

  • Phishing Investigation

    Experience investigating phishing campaigns, understanding attack vectors, and implementing controls to prevent and detect phishing at scale.

  • Cloud Platform Security

    Familiarity with securing infrastructure across cloud platforms with understanding of cloud-native security controls and threats.

  • Technical Communication

    Ability to explain complex security, infrastructure, and software concepts to non-technical stakeholders, executives, and business teams.

  • Linux and Windows Administration

    Working knowledge of Linux and Windows system administration, log files, system hardening, and security configuration.

Preferred

  • Python Scripting

    Nice to have

    Experience with Python for automation scripts, security tool integration, and developing custom detection logic for security tools.

  • Bash and PowerShell

    Nice to have

    Proficiency with Bash and PowerShell scripting for automating security workflows, system administration, and investigation tasks.

  • Okta Administration

    Nice to have

    Hands-on experience configuring and securing Okta identity platforms, including authentication policies and access controls.

  • Mobile Device Management (MDM)

    Nice to have

    Experience deploying and managing enterprise MDM solutions like Kandji or Microsoft Intune for securing corporate devices.

  • Google Cloud Platform (GCP)

    Nice to have

    Practical experience with GCP security features, cloud security architecture, and securing cloud-native workloads.

  • MITRE ATT&CK Framework

    Nice to have

    Deep familiarity with MITRE ATT&CK framework for mapping attacker techniques, building detection strategies, and threat analysis.

  • Threat Intelligence

    Nice to have

    Experience consuming and applying threat intelligence to identify threats specific to fintech, payments, and financial services sectors.

  • Security Compliance and Standards

    Nice to have

    Knowledge of security compliance frameworks such as ISO 27001, SOC 2, or PCI DSS relevant to fintech companies.

Tech stack

Languages

PythonBashPowerShell

Tools

CrowdStrike FalconSplunkOktaGoogle Workspace SecurityKandjiMicrosoft IntuneGoogle Cloud Platform (GCP)

Other

Digital Forensics ToolsMITRE ATT&CK FrameworkIncident Response WorkflowsThreat Intelligence

Compensation

Pay and benefits.

Base·USD 130,000 – 200,000

Equity·Stock options

Benefits

  • Equity and Stock Options

    Participate in Airwallex's equity program as part of your compensation package, with ownership stake in a $11 billion valued fintech platform.

  • Comprehensive Health Insurance

    Access to medical, dental, and vision coverage with employer contributions to support your health and wellness.

  • Professional Development and Learning

    Budget and support for security certifications, training courses, conference attendance, and continuous learning in cybersecurity and incident response.

  • Flexible Work Arrangements

    Work arrangement flexibility supporting both collaboration and focused deep work for security investigations and engineering tasks.

  • Retirement Planning

    Competitive retirement benefits including employer matching contributions to help you plan for long-term financial security.

  • Paid Time Off

    Generous paid vacation, sick leave, and personal days to maintain work-life balance while working on high-impact security initiatives.

  • Global Team and Mobility

    Opportunity to work with security professionals across 27 offices globally, with potential for travel and international collaboration.

Process

Interview steps.

  1. 01

    Initial Screening and Resume Review

    Hiring team reviews your resume, experience, and background for alignment with core security engineering and incident response requirements. This step typically takes 3-5 business days.

  2. 02

    Technical Phone Screening

    Conversation with a security engineer or technical recruiter covering your background in incident response, familiarity with security tools like CrowdStrike and Splunk, understanding of attacker techniques, and specific experience with corporate security environments.

  3. 03

    Technical Deep-Dive Interview

    Detailed technical discussion with security engineers on your experience with digital forensics, incident response case studies, knowledge of detection mechanisms, tool deployment experience, and approach to threat hunting and investigation.

  4. 04

    System Design and Problem-Solving Interview

    Evaluation of your ability to design security controls, create detection workflows, architect security solutions for a scaling business, and approach complex security challenges with technical depth and business pragmatism.

  5. 05

    Team and Culture Fit Discussion

    Conversation with Information Security leadership or team members about your collaboration style, communication skills, ability to work in fast-paced environments, and alignment with Airwallex's operating principles and values around speed, rigor, and ownership.

  6. 06

    Final Review and Offer

    Hiring team reviews interview feedback, technical assessment results, and overall candidate profile. Successful candidates receive offer discussion covering compensation, equity, benefits, and role expectations.

Full posting

Original listing.

About Airwallex

Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.

Proudly founded in Melbourne, we have a team of over 2,300 of the brightest and most innovative people in tech across 27 offices around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.

 

Attributes We Value

We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.

You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.

 

About the team

Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company—from secure product and infrastructure design to risk reduction, incident response, audits, and compliance—so security is built into how we operate, not treated as a blocker.

What You'll do

As a Corporate Security Engineer, you will be a critical part of defending Airwallex’s enterprise systems and employees from threats such as malware, phishing and unauthorised access.

This role is a highly technical opportunity to detect, investigate and prevent security issues across a modern corporate environment. You will work on digital forensics, incident response and tool development and deployment, protecting a range of corporate IT platforms from endpoints to identity providers.

This role is based in San Francisco

Responsibilities:

  • Contribute to incident response for malware, phishing, digital forensics.

  • Design, develop, test, and evaluate new corporate security controls for a rapidly growing business.

  • Perform incident response and hunt through log sources to identify new threats.

  • Design and implement security alerts and workflows to support the incident response lifecycle.

  • Secure corporate IT infrastructure and remediate issues across identity providers, endpoints, corporate networks and other platforms.

  • Deploy, configure and operate security tooling with a laser focus on impact.

Who you are

We’re looking for people who meet the minimum qualifications for this role. The preferred qualifications are great to have, but are not mandatory.

Minimum Qualifications:

  • A passion for solving the complex challenges of high-growth startups.

  • Self motivation and drive to learn new skills, or dive deeper into existing skills.

  • Bachelor's degree in Computer Science, Cybersecurity or similar.

  • 3+ years working in a security engineering or incident response role within a tech company.

  • Strong experience with Crowdstrike, Splunk or other common security monitoring tools.

  • In depth understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation.

  • Experience with GCP, Alibaba Cloud or other cloud platforms is preferred.

  • Experience with Okta, Google Workspace and cloud-based VPN services is preferred.

  • Experience securing endpoints, including with MDM tooling such as Kandji, Intune

  • Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience.

Preferred Qualifications:

  • Strong Engineering mindset with scripting experience such as with Python, Bash, Powershell.

Applicant Safety Policy: Fraud and Third-Party Recruiters

To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page.

Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.

Equal opportunity

Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.

Redirects to Airwallex's application page.

Other roles

More at Airwallex.

View all 160 roles