Skip to main content
Yellow Card Financial

Security Operations Engineer

RemoteNot specified
Published
Role
Security
Experience
Mid
Company size
Mid-size
Salary not disclosed
Check eligibility

The listing doesn't say where it hires from. Check the description or the employer's site before applying.

No BS summary

Security Operations Engineer, 3-5 yrs experience, must have AWS and Kubernetes security skills. Experience in FinTech or crypto is preferred. Remote work, global candidates welcome.

Core skills

SIEMAWS securityEKS security

Required skills

AWSIAMCloudTrailGuardDutyKubernetesEKSCSPMCVSSTerraform/CloudFormationPython/BashSOAR

Optional skills

AWS Secrets ManagerDatadogWizOrca SecuritySOC 2ISO 27001GDPRDORA

Required languages

English Fluent

What you'll do

  • Design and maintain SIEM detection rules for cloud, container, identity, and application layers
  • Map detection coverage against MITRE ATT&CK and identify gaps for AWS and EKS attack surfaces
  • Integrate threat intelligence feeds and maintain a risk-prioritized detection backlog
  • Perform daily SIEM alert triage, investigation, classification, and resolution
  • Reduce false positives through structured tuning cycles and maintain triage runbooks
  • Build and maintain SOAR playbooks for IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
  • Automate enrichment steps and document automation logic under version control
  • Own vulnerability triage for cloud and container environments
  • Manage EKS-specific vulnerability coverage, workload scanning, pod security standards, and node patching cadence
  • Coordinate remediation with engineering teams and track SLA compliance
  • Review and approve IAM policy changes and execute IAM hygiene reviews
  • Support secrets rotation and enforce zero hardcoded credentials
  • Review cloud network security changes and maintain configuration baselines
  • Collect and report SOC, vulnerability management, and posture KRIs
  • Execute recurring infrastructure security control reviews
  • Support external audits and due diligence with evidence artifacts
  • Co-own infrastructure vulnerability backlog with Application Security
  • Act as infrastructure and identity SME during AppSec assessments and architecture reviews
  • Own infrastructure containment during incidents spanning application and infrastructure layers
  • Collaborate with Security GRC on control evidence and compliance mapping
  • Integrate threat intelligence feeds into detection logic
  • Perform daily SIEM alert triage and investigate security signals
  • Tune detection rules to reduce false positives and maintain triage runbooks
  • Manage EKS vulnerability coverage, including image currency, workload scanning, pod security standards, and node patching cadence
  • Coordinate remediation with engineering teams and track SLA breaches
  • Review IAM policy changes and execute IAM hygiene reviews
  • Govern workload identity configurations in EKS
  • Support secrets rotation and prevent hardcoded credentials
  • Review cloud network security changes
  • Investigate and remediate CSPM misconfiguration alerts
  • Maintain security posture metrics and KRI data
  • Execute recurring infrastructure security control checks
  • Support audits and due diligence with evidence artifacts
  • Collaborate with AppSec, DevOps, Engineering, and Security GRC teams

What they require

  • Fluency in written and verbal English
  • Ability to collaborate with cross-functional teams across different time zones
  • 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
  • Hands-on AWS security experience including IAM policy design, virtual network architecture, and cloud-native security services
  • Kubernetes and EKS security experience including pod security standards, network policy enforcement, workload identity, and image scanning
  • Experience with SIEM operations, alert triage, detection rule authoring, log analysis, and correlation
  • Experience with vulnerability management, CSPM tooling, risk-based prioritisation, CVSS scoring, and SLA framework operation
  • Ability to read and review Terraform or CloudFormation for misconfigurations
  • Experience with incident response, investigation, containment, and post-incident reporting
  • Experience in a regulated environment such as FinTech, payments, banking, or crypto preferred
  • Ability to author and tune detection rules without relying on vendor defaults
  • Structured written communication for triage reports, post-incident write-ups, and stakeholder metrics
  • Ability to coordinate remediation across engineering teams without direct authority
  • Comfort operating in a lean team with broad domain boundaries
  • AWS Security Specialty certification highly valued
  • Experience with CSPM and SIEM platforms preferred
  • Experience with secrets management platforms preferred
  • Familiarity with compliance frameworks preferred
  • Experience with SOAR or workflow automation platforms preferred
  • Understanding of cryptocurrency or blockchain security considerations preferred
  • Experience in a startup or scale-up environment preferred
  • AI tooling familiarity and interest in applying AI to operational workflows preferred
  • Ability to collaborate with cross-functional teams and across different time zones
  • Hands-on AWS security experience including IAM policy design, virtual network architecture, cloud-native security services, CloudTrail, and GuardDuty
  • SIEM operations experience including alert triage, detection rule authoring, log analysis, and correlation
  • Vulnerability management experience including CSPM tooling, risk-based prioritisation, CVSS scoring, and SLA framework operation
  • Incident response experience including investigation, containment, and post-incident reporting
  • Ability to author and tune detection rules without relying on vendor-supplied defaults

Benefits

  • Competitive compensation
  • Meaningful health coverage
  • Stock option plan for full-time employees
  • Learning and development resources
  • Remote-first flexibility
  • Mental health support services
  • Ownership of the SOC and cloud security posture function
  • Broad exposure to detection engineering, cloud security, container security, incident response, and compliance
  • Collaborative team culture with a mature AppSec function and leadership support
  • Health coverage
  • Fully remote work environment
  • Ownership of SOC and cloud security posture function from day one
  • Broad domain exposure across detection engineering, cloud security, container security, incident response, and compliance
  • Collaborative team culture

Yellow Card is a licensed stablecoin-based infrastructure provider operating across over 60 countries, providing stablecoin payment infrastructure, fiat settlement rails, wallet services, and custom local stablecoin issuance for businesses across 50 emerging markets.

FintechMid-size

Details

Apply routeDom
Also posted in 1 other channel
Salary not disclosed