Security Operations Engineer
Yellow Card
WorldwideremotePosted 2 days ago
Skill Required
Security-Operations-EngineerSOC-AnalystCloud-Security-EngineerDetection-EngineerSecurity-EngineerCybersecurity-Operations-EngineerSecurity-Operations-EngineeringCyber-Operations-EngineerSecurity-Engineering-and-OperationsSecOps-EngineerSecurity EngineersecurityCloud SecurityEngineeringServerlessautomationdesignDevOpsRailsCloudSIEMNode.jsAWSIAMandFulltime
Key highlights
- Salary/compensation: Competitive compensation; stock option plan for all full-time employees
- Level Required: 3 to 5 years in security operations, cloud security, or infrastructure security engineering
- Key benefit: Fully remote work environment
- Notable requirement: Hands-on AWS security experience (IAM, VPC, CloudTrail, GuardDuty) plus Kubernetes/EKS security experience
- Nice-to-have certification: AWS Security Specialty (highly valued)
- Nice-to-have: Experience in a regulated environment (FinTech, payments, banking, or crypto)
Role overview
The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC) at Yellow Card, the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. This is a fully remote, hands-on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting. Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions, sitting within the First Line of Defense.
Responsibilities
- Own the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment
- Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature-based and behavioural logic
- Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface
- Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs
- Maintain a detection backlog, prioritised by risk, with defined review cadences
- Perform daily SIEM alert triage following defined response timing standard
- Classify, investigate, and resolve security signals; reduce false-positive rates through structured tuning cycles with documented rationale for rule changes
- Maintain triage runbooks for key production detection rules
- Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
- Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time-to-context
- Document automation logic and maintain version control for all playbooks
- Measure and report automation coverage rate as a standing KRI
- Own the end-to-end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context
- Manage EKS-specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence
- Coordinate remediation with engineering teams by opening well-scoped tickets, tracking progress, and escalating SLA breaches
- Maintain MTTR and SLA compliance data by severity tier
- Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows
- Review and approve IAM policy changes, enforcing least-privilege and flagging over-permissioned roles or service accounts
- Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross-account trust boundaries
- Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required
- Support the secrets rotation program and enforce zero hardcoded credentials across the estate
- Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates
- Own container image security: base image update cadence, scanning results review, and image ownership classification
- Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows
- Maintain a configuration baseline for critical cloud resources and flag drift
- Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences
- Execute infrastructure security control checks on weekly (CSPM critical findings), monthly (IAM hygiene, secrets rotation status), and quarterly (posture benchmark, detection coverage review) cadences
- Produce structured findings reports for each review cycle, flagging control failures for escalation
- Provide SOC and cloud posture metrics, including trends, at the required reporting cycles
- Support external audit and due diligence processes by providing evidence artefacts
- Co-own the shared vulnerability backlog (infrastructure side) with the Application Security team, ensuring consistent prioritisation methodology across domains
- Serve as the infrastructure and identity SME for the AppSec team during application security assessments and architecture reviews
- Own infrastructure containment during incidents that span application and infrastructure layers, working alongside AppSec for root cause analysis
- Provide infrastructure, identity, and network security review for new third-party integrations prior to deployment
- Collaborate with the Security GRC function on control evidence and compliance mapping, particularly for SOC 2, ISO 27001, and GDPR requirements
Requirements
- Fluency in English, both written and verbal
- Ability to collaborate with cross-functional teams and across different time zones
- 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
- Hands-on AWS security experience: IAM policy design, virtual network architecture, cloud-native security services, CloudTrail, GuardDuty
- Kubernetes and EKS security experience: pod security standards, network policy enforcement, workload identity, image scanning
- SIEM operations: alert triage, detection rule authoring (signature-based and behavioural), log analysis and correlation
- Vulnerability management: CSPM tooling, risk-based prioritisation, CVSS scoring, SLA framework operation
- IaC security: ability to read and review Terraform or CloudFormation for misconfigurations
- Incident response: investigation, containment, and post-incident reporting
- Ability to author and tune detection rules without relying on vendor-supplied defaults
- Structured written communication for triage reports, post-incident write-ups, and stakeholder metrics
- Ability to coordinate remediation across engineering teams without direct authority
- Comfort operating in a lean team where domain boundaries are broader than in large enterprise security functions
Nice to have
- Experience in a regulated environment (FinTech, payments, banking, or crypto preferred)
- Professional certifications: AWS Security Specialty (highly valued)
- Experience with CSPM and SIEM platforms: Datadog, Wiz, Orca Security
- Experience with secrets management platforms: AWS Secrets Manager
- Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, DORA
- Scripting ability in Python or Bash for detection-as-code and operational automation
- Experience with SOAR or workflow automation platforms
- Understanding of cryptocurrency or blockchain security considerations
- Experience in a startup or scale-up environment
- AI tooling familiarity and interest in applying AI to operational workflows
Benefits
- Competitive compensation and meaningful health coverage
- Stock option plan for all full-time employees
- Access to learning and development resources, support, and autonomy to grow professionally
- Fully remote work environment
- Mental health support services
- Ownership of the SOC and cloud security posture function from day one, in a high-growth FinTech environment
- Broad domain exposure: detection engineering, cloud security, container security, incident response, and compliance
- Collaborative team culture with a mature AppSec function and strong leadership support
- Regulated, multi-geography environment with real-world impact on financial inclusion
Additional details
- Yellow Card is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries
- Yellow Card operates with a substantial global team spanning 24 countries with collective speaking of over 25 languages
- The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection-as-code and SOAR automation
- This is not a perimeter-security or scan-and-report role; the right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end-to-end vulnerability remediation cycles in containerised environments
- SOC KRIs tracked: MTTA, MTTR, false-positive rate, automation coverage rate, detection coverage score
- VM KRIs tracked: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count
- Posture KRIs tracked: CSPM score, under-protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage