Job description
Applying to Paxos? Our only careers site is paxos.com/careers, and we only recruit via @paxos.com email. Details below.
___
About Paxos
Today’s financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in. So we’re rebuilding it.
We’re on a mission to open the world’s financial system to everyone by enabling the instant movement of any asset, any time, in a trustworthy way. For over a decade, we’ve built blockchain infrastructure that tokenizes, custodies, trades and settles assets for the world's leading financial institutions, like PayPal, Venmo, Mastercard, Interactive Brokers and Charles Schwab.
The Opportunity
As a Detection and Response Engineer, you will build the detections, hunts, and automations that protect our cloud infrastructure, our crypto systems, endpoints, and network. You will act as a “Builder” by writing detections as code and automating response, and as a “purple teamer” by emulating attacks with our Product Security teams to confirm our detections work. Our 24x7 SOC handles first-line triage, and you focus on the detection engineering, threat hunting, and validation that make our coverage effective. Strong hands-on investigation skills are expected, and they support this work rather than define it.
What You'll Do
Detection Coverage & Quality: Ship production-grade detections as code with measurable signal improvements—reducing false positives and closing gaps identified in purple team exercises.
Validated Defenses: Run purple team exercises with other teams to confirm detection effectiveness and identify blind spots.
Threat Hunting Program: Execute proactive hunts based on threat intelligence and convert findings into new detections and documented IOCs/TTPs.
Operational Efficiency: Build automations to accelerate investigation and triage; create and maintain runbooks and incident write-ups that make response consistent and repeatable across the team.
Detection Stack: Identify gaps and integrate best-in-class tools that increase team effectiveness and visibility across endpoints, cloud, network, and signing systems.
About You
You bring 3+ years of experience in security operations, detection engineering, offensive security testing, or a related security engineering role, and you're comfortable owning tickets and incidents end-to-end within established runbooks, escalating clearly when you hit the edge of your knowledge.
You have hands-on experience investigating and responding to security threats across endpoints, cloud environments, and network telemetry, using existing tooling (SIEM, EDR, ticketing systems) effectively rather than needing to build it from scratch.
You bring strong analytical judgment and a calm, methodical approach to triaging alerts and driving incidents through resolution, and you flag gaps in process or coverage as you find them.
You have hands-on experience tuning detections in SIEM and EDR platforms to improve signal quality and reduce false positives, and can write or adapt detection rules from an existing template or pattern.
You have used adversary-emulation or purple-team tooling to validate that your detections actually fire, and you understand common attack paths well enough to know what a given detection should — and shouldn't — catch.
You are a builder who looks for opportunities to automate repetitive work, including using AI and scripting (Python/Bash) to speed up investigations.
You communicate clearly within your immediate team, contribute meaningfully to post-incident write-ups, and act on feedback that sharpens your investigative and detection work.
You are prepared to participate in an on-call rotation and document incidents clearly and effectively to support continuous improvement.
Important Notice for Paxos Applicants
Fraudulent accounts sometimes pose as Paxos recruiters on LinkedIn and other platforms, and fake websites sometimes impersonate our careers site. These scammers attempt to deceive applicants into paying for job opportunities or providing personal financial information.
To verify a legitimate Paxos opportunity:
Our only official careers site is paxos.com/careers
We only use @paxos.com email addresses
We never ask for payment or financial details to apply, interview, or work here
For technical roles, we do not perform a coding interview without prior screening by our engineering team
Thanks for your interest in Paxos!
Requirements
- Languages
- English
- Work mode
- Remote
- Seniority
- Mid-level
- Eligibility
- United States