About the role
From the employer’s listing · Paxos · posted 29 September 2026
Applying to Paxos? Our only careers site is paxos.com/careers , and we only recruit via @ paxos.com email. Details below. _ About Paxos Today’s financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in. So we’re rebuilding it. We’re on a mission to open the world’s financial system to everyone by enabling the instant movement of any asset, any time, in a trustworthy way. For over a decade, we’ve built blockchain infrastructure that tokenizes, custodies, trades and settles assets for the world's leading financial institutions, like PayPal, Venmo, Mastercard, Interactive Brokers and Charles Schwab. About the team The Security team at Paxos protects the cloud infrastructure, crypto systems, endpoints, and network that our regulated financial platform runs on. You'll join the Detection and Response function, working alongside our 24x7 SOC, which handles first-line triage, and partnering with Product Security teams to validate that our coverage holds up against real attacker techniques. About the role The Detection and Response Engineer at Paxos serves as a builder of the detections, hunts, and automations that protect our cloud infrastructure, crypto systems, endpoints, and network. You will write detections as code and automate response, and act as a purple teamer, emulating attacks alongside our Product Security teams to confirm our detections work. Our 24x7 SOC handles first-line triage, so your focus is the detection engineering, threat hunting, and validation that make our coverage effective. Strong hands-on investigation skills are expected, but they support this work rather than define it. What you'll do Detection Coverage & Quality: Ship production-grade detections as code with measurable signal improvements—reducing false positives and closing gaps identified in purple team exercises. Validated Defenses: Run purple team exercises with other teams to confirm detection effectiveness and identify blind spots. Threat Hunting Program: Execute proactive hunts based on threat intelligence and convert findings into new detections and documented IOCs/TTPs. Operational Efficiency: Build automations to accelerate investigation and triage; create and maintain runbooks and incident write-ups that make response consistent and repeatable across the team. Detection Stack: Identify gaps and integrate best-in-class tools that increase team effectiveness and visibility across endpoints, cloud, network, and signing systems. About you You bring 3+ years of experience in security operations, detection engineering, offensive security testing, or a related security engineering role, and you're comfortable owning tickets and incidents end-to-end within established runbooks, escalating clearly when you hit the edge of your knowledge. You have hands-on experience investigating and responding to security threats across endpoints, cloud environments, and network telemetry, using existing too
















