Job description

Applying to Paxos? Our only careers site is paxos.com/careers, and we only recruit via @paxos.com email. Details below.
___

About Paxos

Today’s financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in. So we’re rebuilding it.

We’re on a mission to open the world’s financial system to everyone by enabling the instant movement of any asset, any time, in a trustworthy way. For over a decade, we’ve built blockchain infrastructure that tokenizes, custodies, trades and settles assets for the world's leading financial institutions, like PayPal, Venmo, Mastercard, Interactive Brokers and Charles Schwab.

The Opportunity

As a Senior Detection and Response Engineer, you will build the detections, hunts, and automations that protect our cloud infrastructure, our crypto systems, endpoints, and network. You will act as a “Builder” by writing detections as code and automating response, and as a “purple teamer” by emulating attacks with our Product Security teams to confirm our detections work. Our 24x7 SOC handles first-line triage, and you focus on the detection engineering, threat hunting, and validation that make our coverage effective. Strong hands-on investigation skills are expected, and they support this work rather than define it.

 

What You'll Do

  • Detection Coverage & Quality: Ship production-grade detections as code with measurable signal improvements—reducing false positives and closing gaps identified in purple team exercises.

  • Validated Defenses: Run purple team exercises with other teams to confirm detection effectiveness and identify blind spots.

  • Threat Hunting Program: Execute proactive hunts based on threat intelligence and convert findings into new detections and documented IOCs/TTPs.

  • Operational Efficiency: Build automations to accelerate investigation and triage; create and maintain runbooks and incident write-ups that make response consistent and repeatable across the team.

  • Detection Stack: Identify gaps and integrate best-in-class tools that increase team effectiveness and visibility across endpoints, cloud, network, and signing systems.

 

About You

  • You bring 5-8+ years of experience in security operations, detection engineering, offensive security testing, or a related security engineering role — with a track record of scope growth, not just years.

  • You independently own complex, ambiguous, or multi-stage incidents from initial triage through containment, eradication, and recovery — making the call in the moment and building or improving the runbook afterward, rather than waiting for one to exist.

  • You bring deep, hands-on expertise in SIEM and EDR platforms, can design new detections from scratch, own detection strategy for a significant surface area, and meaningfully reduce false-positive rates across a rule set you own.

  • You can design and run purple-team exercises in partnership with other engineering teams, emulating real attacker techniques and using the findings to reshape the detection roadmap rather than just confirm what already works.

  • You have a strong point of view on what tools and architecture the team should invest in, not just how to use what's already there, and you make credible build-vs-buy calls.

  • You think like a builder and continuously find ways to automate repetitive security workflows, applying AI thoughtfully to improve the speed, consistency, and scale of investigation and response across the team.

  • You produce original threat intelligence assessments and run proactive threat hunts based on hypotheses, translating findings directly into new detections and a stronger detection roadmap.

  • You communicate fluently with engineering leadership and cross-functional stakeholders during major incidents, and your docs and retros shape team direction, not just record what happened.

  • You actively mentor junior members of the team, serve as a trusted technical escalation point, and have a track record of measurably accelerating others' growth.

  • You're comfortable participating in an on-call rotation and can act as incident commander when needed — driving structural fixes that prevent a class of incidents from recurring, not just one instance.

Important Notice for Paxos Applicants
Fraudulent accounts sometimes pose as Paxos recruiters on LinkedIn and other platforms, and fake websites sometimes impersonate our careers site. These scammers attempt to deceive applicants into paying for job opportunities or providing personal financial information.

To verify a legitimate Paxos opportunity:

  • Our only official careers site is paxos.com/careers

  • We only use @paxos.com email addresses

  • We never ask for payment or financial details to apply, interview, or work here

  • For technical roles, we do not perform a coding interview without prior screening by our engineering team

Thanks for your interest in Paxos!

Requirements

Languages
English
Work mode
Hybrid
Seniority
Senior
Eligibility
Israel

Engineering salary

Salary breakdown

16 engineering roles on Jobs Web3 publish a range, and together they span $120k to $500k/year.

Other roles at Paxos

More engineering jobs

All jobs

Related pages