
Real job — pulled straight from Papaya Global’s careers page · Verified August 25, 2026 · No reposts.
Job description
Papaya Global is hiring a Security Operations Engineer — a full-time, based in Herzliya, IL role. Apply directly on Papaya Global's careers page below.
SecOps Engineer
Location: Herzliya (IL)
Description
Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries.
About the job
We are looking for a SecOps Engineer to join our cybersecurity team. In this role, you will help defend the organization end-to-end across cloud, endpoints, identities, and applications while building and maturing our security operations capability.
You will work across SIEM and telemetry, detection engineering, alert investigation, threat hunting, digital forensics and incident response, threat intelligence, and response automation. You will partner closely with IT, DevOps, Application Security, R&D, and business stakeholders to turn security signals into effective action and lasting improvements.
This is a hands-on role for someone who enjoys investigating complex problems, improving controls, and building repeatable security operations in a growing environment. The role may participate in an on-call rotation and occasional after-hours incident response as required.
Responsibilities
- Operate and improve the security operations stack — SIEM, identity, endpoint, cloud, and application telemetry — including log source onboarding, health monitoring, and coverage-gap remediation.
- Investigate security alerts and threats through triage, host and artifact analysis, DFIR, and threat hunting.
- Lead incident response from detection through containment, recovery, and post-incident review.
- Build and tune detection rules, SIEM queries, and dashboards for high-risk attack paths, and convert threat intelligence into new detections, hunts, and control improvements.
- Automate response and enrichment workflows by using AI tools, scripting (Python, Bash, PowerShell), or SOAR tools to cut response time, and report incident metrics — root cause, impact, and remediation status.
- Support security reviews of vendors, SaaS platforms, and internal applications, and partner with engineering to validate whether existing controls detect and mitigate relevant threats.
- Support security monitoring and response for AI-enabled workflows and artifacts where applicable, including agentic tooling, integrations, and related operational risks.
- Use AI-assisted triage and anomaly-detection models to prioritize alerts and cut time-to-detect across SIEM and endpoint telemetry.
- Develop agentic workflows to speed up evidence correlation, RCA, timeline reconstruction, and case write-ups during investigations.
- Evaluate AI agentic investigation tools for accuracy and performance and use the results to fine-tune and further enhance the automated playbooks.
Requirements
- 3+ years of hands-on experience in security operations, incident response, detection engineering, or a similar cybersecurity role.
- Strong practical experience with IT security, endpoint protection, identity security, and security operations.
- Hands-on experience with SIEM platforms, including alert triage, investigation, query development, dashboards, and detection tuning.
- Solid understanding of cloud security and practical experience with one or more major cloud platforms, including identity, logging, network, and workload security concepts.
- Experience with incident response and DFIR workflows, including host-based and artifact analysis on Windows, Linux and macOS.
- Proficiency in Python, Bash, PowerShell, or similar scripting languages for automation and operational tooling.
- Familiarity with SOAR platforms, automated playbooks, alert enrichment, and response workflows.
- Strong written and verbal communication skills, with the ability to collaborate across DevOps, IT, R&D, security, and business teams.
- Ability and willingness to participate in occasional after-hours response when required by a material security incident.
- Strong familiarity with AI tools and experience putting them to work in security investigations.
Nice to have
- Experience building detections and incident-response capability in a growing or cloud-native organization.
- Experience with threat hunting, malware analysis, host forensics, and mapping activity to common adversary tactics, techniques, and procedures.
- Experience with containerized or cloud-native architectures, identity providers, and modern endpoint security platforms.
Get Security Operations Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Security Operations Engineer at Papaya Global?
The required skills for Security Operations Engineer at Papaya Global include: SIEM, Python, Bash, PowerShell, AI.
What is the seniority level for Security Operations Engineer at Papaya Global?
Security Operations Engineer at Papaya Global is a Mid Level level position.
How do I apply for Security Operations Engineer at Papaya Global?
You can view the full description and apply for Security Operations Engineer at Papaya Global on EchoJobs: https://echojobs.io/job/papaya-global-secops-engineer-bx5h2.