Mesh is hiring a Security Operations Engineer in IT/Security — EU (Remote). The overview below is synthesized from the employer posting on job-boards.greenhouse.io: factual requirements and scope are preserved, but prose is rewritten with editorial context. Verify details and apply via the employer link.
About Mesh
Company context from the listing:
At Mesh, our mission is to enable consumers to pay and be paid with any asset. Today, trillions of dollars in tokenized assets exist but remain largely unusable for everyday commerce.
Overview
Company context from the listing:
As a Security Ops Engineer, you will be a hands-on technical builder and responder responsible for designing, implementing, and operating security controls across our infrastructure, systems, and operational workflows. This role spans building robust security architecture, conducting threat modeling, analyzing attack vectors from an analyst's perspective, and driving active incident response.
What You'll Do
Day-to-day scope for the Security Operations Engineer as described in the posting:
- Implement Security Controls and Architecture by designing, deploying, and maintaining core defensive systems, security integrations, and infrastructure guardrails.
- Perform Threat Analysis and Modeling by evaluating system architectures from an attacker's perspective, identifying key attack surfaces, and building practical defensive mitigations.
- Conduct Practical Code and System Reviews by evaluating new features and integration architectures for security risks, leveraging code comprehension to improve overall security posture.
- Manage Vulnerability Remediation by tracking findings from scans, pentests, and bug reports, prioritizing by risk, and driving fixes to closure with engineering owners.
- Own Security Operations Platform Management by administering, configuring, and maintaining SIEM/SOAR platforms for threat detection and incident response.
- Engineer Detection Rules and Alerts by writing, tuning, and optimizing detection queries to identify real threats while minimizing false positives.
- Conduct Security Investigations and Incident Response by analyzing alerts, performing forensic analysis, and managing escalation and communication during active incidents.
- Document Findings by producing clear reports for security reviews, threat models, and incident investigations that support institutional knowledge and audits.
- Support Compliance and Evidence Collection by ensuring security events, review findings, and remediation work are properly logged and available for audit and regulatory requirements.
- Maintain Operational Readiness by staying current on emerging threats, attack techniques, and security engineering practices relevant to our infrastructure and threat model.
Who You Are
Experience and skills the team lists as required:
- Bachelor's degree in Computer Science, Cybersecurity, or a related field.
- 5–7+ years of hands-on experience building defensive security systems, implementing security controls, or operating in security response environments.
- Strong technical background in understanding attack techniques, performing threat analysis, and leading incident response efforts.
- Experience managing vulnerability findings from identification through remediation.
- Working knowledge of SIEM/SOAR platforms and writing detection rules (e.g. SPL, KQL, or similar).
- Deep understanding of network, host, application, and cloud security concepts.
- Strong written and verbal communication skills, with the ability to clearly document findings and escalate issues.
- Ability to work independently with minimal supervision in a fast-paced environment.
- Experience collaborating with small, international teams across multiple time zones.
- Willingness to work outside normal business hours when needed for incident response.
Nice to have
- Familiarity with threat modeling frameworks (e.g. STRIDE, MITRE ATT&CK).
- Experience implementing automated security controls and infrastructure security tooling.
- Hands-on experience with SIEM platforms at scale (Sumo Logic, Splunk, Azure Sentinel, Datadog, or similar).
- Experience with cloud security monitoring (AWS, Azure, GCP) and native security services.
- Exposure to containerized environments (Docker, Kubernetes) and securing cloud-native workloads.
- Familiarity with security and compliance frameworks (ISO 27001/2, NIST, SOC2, GDPR, DORA).
- Experience with at least one object-oriented programming language; Python preferred.
- Experience with at least one query language such as KQL or similar.
Why You’ll Love It Here
At Mesh, you're not stepping into a typical role—you're joining a rocket ship in mid-liftoff. You'll tackle complex, meaningful problems that actually move an industry forward, working alongside a sharp, motivated team that moves quickly, collaborates deeply, and expects everyone to operate with ownership.
In-Office Expectations
Employees based in our San Francisco, New York, and Bangalore hubs are expected to work from the office at least 40% of the time (approximately two days per week). This expectation may vary slightly depending on role, team, and business needs.
How We Care For Our Team
We believe great work happens when people feel valued and supported. That starts with competitive salary and equity that grows as you and the company grow, plus comprehensive health coverage for you and your family.
We're invested in your growth with a dedicated budget for courses, conferences, and certifications. Work from wherever you're most productive with our remote-friendly approach, and count on having the top-tier tools and equipment you need to do exceptional work.
Mesh Pay is committed to equal employment opportunities regardless of race, color, genetic information, creed, religion, sex, sexual orientation, gender identity, lawful alien status, national origin, age, marital status, and non-job related physical or mental disability, or protected veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
