Security Operations Engineer
Yellow Card Financial
Security Operations Engineer
Yellow Card is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment infrastructure to fiat settlement rails, wallet services, and custom local Stablecoin issuance, Yellow Card provides the complete infrastructure businesses need to manage Stablecoins, payments, and operations across 50 emerging markets.
Yellow Card operates with a substantial global team spanning 24 countries. This workforce is characterized by its linguistic diversity, with collective speaking of over 25 languages, underscoring the company's extensive international reach.
The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC). It is a fully remote, hands-on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting.
Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions. The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection-as-code and SOAR automation.
This is not a perimeter-security or scan-and-report role. The right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end-to-end vulnerability remediation cycles in containerised environments.
What You'll Do
1. Security Operations
The engineer owns the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment. This is the primary domain of the role.
Alert design and coverage
- Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature-based and behavioural logic
- Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface
- Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs
- Maintain a detection backlog, prioritised by risk, with defined review cadences
Alert triage
- Daily SIEM alert triage following defined response timing standard
- Classify, investigate, and resolve security signals;
- Reduce false-positive rates through structured tuning cycles, with documented rationale for rule changes
- Maintain triage runbooks for key production detection rules
Automated response workflows (SOAR)
- Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
- Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time-to-context
- Document automation logic and maintain version control for all playbooks
- Measure and report automation coverage rate as a standing KRI
2. Cloud Security Posture Management
Cloud posture management is the infrastructure-facing domain of the role, covering vulnerability management, identity governance, and configuration and change control. AWS EKS and Serverless resources are the primary environments.
Vulnerability management
- Own the end-to-end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context
- Manage EKS-specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence
- Coordinate remediation with engineering teams by opening well-scoped tickets, tracking progress, and escalating SLA breaches
- Maintain MTTR and SLA compliance data by severity tier
- Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows
Identity and access governance
- Review and approve IAM policy changes, enforcing least-privilege and flagging over-permissioned roles or service accounts
- Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross-account trust boundaries
- Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required
- Support the secrets rotation program and enforce zero hardcoded credentials across the estate
Configuration and change management
- Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates
- Own container image security: base image update cadence, scanning results review, and image ownership classification
- Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows
- Maintain a configuration baseline for critical cloud resources and flag drift
3. Posture Tracking and Reporting
The engineer is the primary data owner for security posture metrics across both SOC and cloud domains. Reporting outputs feed executive dashboards, GRC compliance evidence, and quarterly risk reviews.
KRI data collection
- Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences
- SOC KRIs: MTTA (Mean Time to Acknowledge), MTTR, false-positive rate, automation coverage rate, detection coverage score
- VM KRIs: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count
- Posture KRIs: CSPM score, under-protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage
Recurring control reviews
- Execute infrastructure security control checks on weekly (CSPM critical findings), monthly (IAM hygiene, secrets rotation status), and quarterly (posture benchmark, detection coverage review) cadences
- Produce structured findings reports for each review cycle, flagging control failures for escalation
Reporting
- Provide SOC and cloud posture metrics, including trends, at the required reporting cycles
- Support external audit and due diligence processes by providing evidence artefacts
4. Others
- Co-own the shared vulnerability backlog (infrastructure side) with the Application Security team, ensuring consistent prioritisation methodology across domains
- Serve as the infrastructure and identity SME for the AppSec team during application security assessments and architecture reviews
- Own infrastructure containment during incidents that span application and infrastructure layers, working alongside AppSec for root cause analysis
- Provide infrastructure, identity, and network security review for new third-party integrations prior to deployment
- Collaborate with the Security GRC function on control evidence and compliance mapping, particularly for SOC 2, ISO 27001, and GDPR requirements
What You'll Bring
- Fluency in English, both written and verbal
- Ability to collaborate with cross-functional teams and across different time zones
- 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
- Hands-on AWS security experience: IAM policy design, virtual network architecture, cloud-native security services, CloudTrail, GuardDuty
- Kubernetes and EKS security experience: pod security standards, network policy enforcement, workload identity, image scanning
- SIEM operations: alert triage, detection rule authoring (signature-based and behavioural), log analysis and correlation
- Vulnerability management: CSPM tooling, risk-based prioritisation, CVSS scoring, SLA framework operation
- IaC security: ability to read and review Terraform or CloudFormation for misconfigurations
- Incident response: investigation, containment, and post-incident reporting
- Experience in a regulated environment (FinTech, payments, banking, or crypto preferred)
- Ability to author and tune detection rules without relying on vendor-supplied defaults
- Structured written communication for triage reports, post-incident write-ups, and stakeholder metrics
- Ability to coordinate remediation across engineering teams without direct authority <
$192k - $240k
...founders and finance teams to accelerate operations, gain real-time visibility, and control... ...support you need to grow your career.Engineering at BrexEngineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy...SuggestedWork at officeRemote workWork from home$145k - $175k
Job DescriptionWe are seeking an experienced Security Operations Engineer to help advance the next generation of security capabilities across our enterprise. This role is a technical leader responsible for designing, implementing, and continuously improving enterprise...SuggestedTemporary workWork at officeRemote work$90k - $157.5k
Network Security Operation Engineer will be responsible for implementing and maintaining systems to protect State Street’s network infrastructure. This includes managing security policy, conducting security audits, and analyzing security & network traffic. Additionally,...SuggestedFull timeTemporary workFlexible hoursWeekend work- ...change. Constantly grow as you work hard for a mission that matters at a company where you matter.Your Impact As a Senior Security Operations Engineer II, you will play a key role in building secure, reliable, and developer-friendly infrastructure that enables teams to...SuggestedWork at officeRemote work
- Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge... .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate... ...and Paris. Join us!As a Senior Security Operations Engineer you will:Serve as trusted...SuggestedFull timeWork at officeLocal areaRemote workHome officeFlexible hours
$86.8k - $198k
Security Operations Center EngineerThe Opportunity: As a Security Operations Center Engineer, you’ll build and improve the systems that enable security teams to detect, investigate, and respond to cyber threats. We need an engineer who can combine cybersecurity knowledge...Full timeContract workPart timeWork at officeLocal areaRemote workShift work$120k - $180k
...industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.THE ROLEAs a Security Operations Engineer in the Global Information Security Office (GISO), you will lead the mission to reduce our global attack surface across...Work at officeFlexible hoursShift work$168.75k - $270k
...matters at a company where you matter.Job Description - Principal Security Operations EngineerOur mission is to protect lifeWe’re out to make the... ...single day.Your ImpactAs a PrincipalSecurity Operations Engineer, you will play a key role in building secure, reliable, and...Work experience placementWork at office- ...monitoring and analyzing our organization's security infrastructure, detecting and... ...internal technology teams-including Cloud Engineering, Network Security, IAM, DevOps, and Governance... ...the continuous maturation of the SOC's operational processes. Participate in tabletop...Full timeWork at officeRemote workFlexible hours
- ...highest-priority goals faster. And because Tines is secure and private by design, it's popular with security, IT, engineering, finance, and other security-focused teams.... .... We are looking for a Senior Security Operations Engineer passionate about security and automation...Remote work
- ...Security Operations Engineer Capco is a fully independent, global management and technology consultancy. For 25 years we have combined innovative thinking with deep industry knowledge to deliver business consulting, digital transformation and technology services to...Contract workRemote workFlexible hours
- ...Security Operations Engineer Patrick SFB, FL or Arlington, VA 540 is seeking a Security Operations Engineer to support our partnership with Google and the Department of Defense in advancing mission-critical capabilities for a global data processing platform. This...Temporary workWork at officeLocal areaFlexible hours
- ...humble and looking to make a lasting impact in healthcare, we'd like to meet you. ABOUT THE ROLE As the Security Operations Engineer at Hopscotch, you will lead and manage core security and compliance controls for the business using modern methods and...Live inWork at office
- ...Job Description Role Summary We are seeking a Security Operations Engineer to serve as a key contributor within a mature cybersecurity program. This individual will lead initiatives focused on data protection, Zero Trust security, threat detection, incident...
$126.3k - $243.1k
...Security Operations Engineer At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential...- ...that we provide a great place to come to work each day to pursue your passions. THE CHALLENGE We are looking for a Security Operations Engineer to support, maintain, and contribute to our Security Orchestration, Automation, and Response (SOAR) platform. In this...Casual workFlexible hours
$45 - $60 per hour
...Security Operations Engineer Want to work for a company that is changing the future of transportation? Our cutting-edge self-driving vehicle company has developed a revolutionary platform that powers our fleet of passenger vehicles. We are looking for an entry-level...Contract workTemporary work$35 - $45 per hour
...Security Operations Engineer in the Autonomous Vehicles Industry We are seeking a Security Operations Engineer who will be responsible for monitoring, triaging, and investigating security threats across our systems and networks. This role will involve continuously...Temporary workWork at officeRemote work- ...Senior Security Operations Engineer Job Title: Senior Security Operations Engineer Location: Washington, DC Note: This is an onsite position Place at NIGC Headquarters located at 550 12th Street SW, Washington, DC 20024 Work Authorization: Only US Citizen or Green...
- ...Cybersecurity Excellence Awards. We deliver zero trust secure remote access and real-time data streaming for operational technology (OT) and industrial control systems (... ...Manage Google SecOps RBAC Detection Engineering Build and deploy production detection rules...Permanent employmentRemote workFlexible hours
- ...ManpowerGroup Global, Inc. is seeking an IT Admin. II (Security Operations) to join the security and IT teams in Fond du Lac area. The role focuses on implementing and maintaining enterprise infrastructure with a strong emphasis on security and risk management. The candidate...
- ...Security Operations (SecOps) Engineer Duration: 12+ months (possible extension) Location: New York, NY 10286 Onsite role (4 days a week) Responsibilities Seeking a hands-on Security Operations (SecOps) Engineer to build, operate, and continuously improve the security...
- ...Description Island is the ideal environment for enterprise work - security is everywhere without ever getting in the way. The Island... ...Cloud 100 The Role We're looking for a Security Operations Engineer who will own the day-to-day operation and continuous...InternshipWork at officeMonday to Friday
- ...Senior Security Engineer (Security Operations) Sword Health is shifting healthcare from human-first to AI-first through its AI Care platform, making world-class healthcare available anytime, anywhere, while significantly reducing costs for payers, self-insured employers...Full timeRemote workFlexible hoursShift work
- ...Senior Security Engineer At Cetera, our Information Security organization is responsible for protecting sensitive client, advisor, and... ...classification, and protection to lead the implementation and operation of modern data security posture management (DSPM) and data...Full timeFlexible hours
- ...Security Operations Engineer Today's financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in. So we're rebuilding it. We're on a mission to open the world's financial system to everyone...Remote work
- ...DPP is seeking a Security Operations Engineer for an opportunity with our client in the healthcare insurance industry. Work location : Partial onsite (Tues., Wed., Thur. onsite) and as needed Hours: 40 hours per week Mon. - Fri. Overtime and weekend work...Contract workWork experience placement
- ...Seeking a hands-on and detail-oriented Security Operations Engineer, the full-time hybrid position will operate, tune, and improve key security tools across endpoint and cloud security, while collaborating closely with DevOps and infrastructure teams to enhance security...Full timeRemote work
$143.91k
Agency: Health Resources and Services AdministrationDepartment: Department of Health and Human ServicesSub agency: Division of Cyber Security to Office of the Chief Information Office (OCIO)Salary: Starting at $143,913 Per year (GS 14)Dates: Open 08/07/2026 to 08/17/2026...Work at office$106k - $170k
...developing excellence. We collaborate to find the best answers for our customers and for Position Overview:The Blackstone Security Operations - Engineering team is growing to support new cross-functional security needs. The Associate Security Engineer is responsible for...Full timeWork at officeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Engineer. Be the first to apply!
- information technology security engineer United States
- security project engineer United States
- application security engineer United States
- senior cloud security engineer United States
- security software engineer United States
- security solutions engineer United States
- sr security engineer United States
- security infrastructure engineer United States
- entry level security engineer United States
- security engineer United States

