Summary
Varo Bank is an entirely new kind of bank, designed for the way customers live their lives. They are seeking a Security Engineer to help secure their banking systems, automate defenses, and protect customers and employees.
Responsibilities
- Automate Security Checks: Write and maintain Python scripts that automatically check if our security tools are installed and working properly on all company systems
- Write Detections: Create and fine-tune alert rules to spot cyber threats and suspicious behavior before they cause harm
- Manage EDR: Oversee and configure our Endpoint Detection and Response (EDR) platform to monitor and defend all company laptops, desktops, and servers
- Track Down Phishing Sites: Use our external vendor tools to scan the internet, find fake websites mimicking our bank, and get them taken down
- Stop Insider Threats: Partner directly with our financial crimes team to design, implement, and monitor safeguards against internal fraud and data theft
Skills
- Strong ability to write and debug Python scripts to automate routine security tasks and connect different tools via APIs
- Hands-on experience managing and configuring an enterprise EDR platform (such as CrowdStrike, Defender, or SentinelOne)
- Experience writing security rules (such as Sigma, YARA, or SIEM-specific query languages) to detect malicious activity
- Ability to work clearly and effectively with non-technical teams, specifically when coordinating on fraud and insider threat investigations
- Familiarity with brand protection or anti-phishing vendor platforms to find and report malicious domains
Qualifications
Must Haves
- Strong ability to write and debug Python scripts to automate routine security tasks and connect different tools via APIs
- Hands-on experience managing and configuring an enterprise EDR platform (such as CrowdStrike, Defender, or SentinelOne)
- Experience writing security rules (such as Sigma, YARA, or SIEM-specific query languages) to detect malicious activity
- Ability to work clearly and effectively with non-technical teams, specifically when coordinating on fraud and insider threat investigations
Nice to Haves
- Familiarity with brand protection or anti-phishing vendor platforms to find and report malicious domains