waypointjobs

Yellow Card

Security Operations Engineer

Remote — Worldwide (see timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Who We Are

Yellow Card is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment infrastructure to fiat settlement rails, wallet services, and custom local Stablecoin issuance, Yellow Card provides the complete infrastructure businesses need to manage Stablecoins, payments, and operations across 50 emerging markets.

Yellow Card operates with a substantial global team spanning 24 countries. This workforce is characterized by its linguistic diversity, with collective speaking of over 25 languages, underscoring the company’s extensive international reach.

The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC). It is a fully remote, hands-on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting.

Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions. The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection-as-code and SOAR automation.

This is not a perimeter-security or scan-and-report role. The right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end-to-end vulnerability remediation cycles in containerised environments.

What You'll Do

1. Security Operations

The engineer owns the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment. This is the primary domain of the role.

Alert design and coverage

Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature-based and behavioural logic

Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface

Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs

Maintain a detection backlog, prioritised by risk, with defined review cadences

Alert triage

Daily SIEM alert triage following defined response timing standard

Classify, investigate, and resolve security signals;

Reduce false-positive rates through structured tuning cycles, with documented rationale for rule changes

Maintain triage runbooks for key production detection rules

Automated response workflows (SOAR)

Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events

Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time-to-context

Document automation logic and maintain version control for all playbooks

Measure and report automation coverage rate as a standing KRI

2. Cloud Security Posture Management

Cloud posture management is the infrastructure-facing domain of the role, covering vulnerability management, identity governance, and configuration and change control. AWS EKS and Serverless resources are the primary environments.

Vulnerability management

Own the end-to-end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context

Manage EKS-specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence

Coordinate remediation with engineering teams by opening well-scoped tickets, tracking progress, and escalating SLA breaches

Maintain MTTR and SLA compliance data by severity tier

Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows

Identity and access governance

Review and approve IAM policy changes, enforcing least-privilege and flagging over-permissioned roles or service accounts

Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross-account trust boundaries

Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required

Support the secrets rotation program and enforce zero hardcoded credentials across the estate

Configuration and change management

Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates

Own container image security: base image update cadence, scanning results review, and image ownership classification

Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows

Maintain a configuration baseline for critical cloud resources and flag drift

3. Posture Tracking and Reporting

The engineer is the primary data owner for security posture metrics across both SOC and cloud domains. Reporting outputs feed executive dashboards, GRC compliance evidence, and quarterly risk reviews.

KRI data collection

Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences

SOC KRIs: MTTA (Mean Time to Acknowledge), MTTR, false-positive rate, automation coverage rate, detection coverage score

VM KRIs: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count

Posture KRIs: CSPM score, under-protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage

Recurring control reviews

Execute infrastructure security control checks on weekly (CSPM critical findings), monthly (IAM hygiene, secrets rotation status), and quarterly (posture benchmark, detection coverage review) cadences

Produce structured findings reports for each review cycle, flagging control failures for escalation

Reporting

Provide SOC and cloud posture metrics, including trends, at the required reporting cycles

Support external audit and due diligence processes by providing evidence artefacts

4. Others

Co-own the shared vulnerability backlog (infrastructure side) with the Application Security team, ensuring consistent prioritisation methodology across domains

Serve as the infrastructure and identity SME for the AppSec team during application security assessments and architecture reviews

Own infrastructure containment during incidents that span application and infrastructure layers, working alongside AppSec for root cause analysis

Provide infrastructure, identity, and network security review for new third-party integrations prior to deployment

Collaborate with the Security GRC function on control evidence and compliance mapping, particularly for SOC 2, ISO 27001, and GDPR requirements

What You'll Bring

Fluency in English, both written and verbal

Ability to collaborate with cross-functional teams and across different time zones

3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering

Hands-on AWS security experience: IAM policy design, virtual network architecture, cloud-native security services, CloudTrail, GuardDuty

Kubernetes and EKS security experience: pod security standards, network policy enforcement, workload identity, image scanning

SIEM operations: alert triage, detection rule authoring (signature-based and behavioural), log analysis and correlation

Vulnerability management: CSPM tooling, risk-based prioritisation, CVSS scoring, SLA framework operation

IaC security: ability to read and review Terraform or CloudFormation for misconfigurations

Incident response: investigation, containment, and post-incident reporting

Experience in a regulated environment (FinTech, payments, banking, or crypto preferred)

Ability to author and tune detection rules without relying on vendor-supplied defaults

Structured written communication for triage reports, post-incident write-ups, and stakeholder metrics

Ability to coordinate remediation across engineering teams without direct authority

Comfort operating in a lean team where domain boundaries are broader than in large enterprise security functions

Professional certifications: AWS Security Specialty (highly valued)

Experience with CSPM and SIEM platforms: Datadog, Wiz, Orca Security

Experience with secrets management platforms: AWS Secrets Manager

Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, DORA

Scripting ability in Python or Bash for detection-as-code and operational automation

Experience with SOAR or workflow automation platforms

Understanding of cryptocurrency or blockchain security considerations

Experience in a startup or scale-up environment

AI tooling familiarity and interest in applying AI to operational workflows

What We Offer

Compensation & Benefits: We offer competitive compensation and meaningful health coverage, and all full-time employees are participants in our stock option plan.

Learning & Development: Access to resources, support, and autonomy to grow professionally.

Remote-First Flexibility: We embrace a fully remote work environment.

Regulated, multi-geography environment with real-world impact on financial inclusion

Mental Health Support Services: Your mental well-being matters to us.

Ownership of the SOC and cloud security posture function from day one, in a high-growth FinTech environment

Broad domain exposure: detection engineering, cloud security, container security, incident response, and compliance

Collaborative team culture with a mature AppSec function and strong leadership support

Ready to Join Us?

Are you up for the challenge? Apply today and be part of shaping the future of FinTech. Let's innovate, disrupt, and lead together!

Originally posted on Himalayas

Who can apply

The source lists worldwide eligibility. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job