Afli în 5 zile de ce nu primești răspuns la aplicații. Vezi cum →
← Înapoi la joburi
Yellow Card

Security Operations Engineer

Full-timeMidWorldwideaziAdmin & Operations
Salariu
Nedivulgat
Aplică la angajator →
Te trimitem direct pe site-ul angajatorului. Gratuit, fără cont.

Rol remote operational sau administrativ pentru companie internationala

Despre rol

Who We Are

Yellow Card is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment infrastructure to fiat settlement rails, wallet services, and custom local Stablecoin issuance, Yellow Card provides the complete infrastructure businesses need to manage Stablecoins, payments, and operations across 50 emerging markets.

Yellow Card operates with a substantial global team spanning 24 countries. This workforce is characterized by its linguistic diversity, with collective speaking of over 25 languages, underscoring the company’s extensive international reach.

The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC). It is a fully remote, hands-on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting.

Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions. The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection-as-code and SOAR automation.

This is not a perimeter-security or scan-and-report role. The right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end-to-end vulnerability remediation cycles in containerised environments.

What You'll Do

1. Security Operations

The engineer owns the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment. This is the primary domain of the role.

Alert design and coverage

Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature-based and behavioural logic
Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface
Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs
Maintain a detection backlog, prioritised by risk, with defined review cadences

Alert triage

Daily SIEM alert triage following defined response timing standard
Classify, investigate, and resolve security signals;
Reduce false-positive rates through structured tuning cycles, with documented rationale for rule changes
Maintain triage runbooks for key production detection rules

Automated response workflows (SOAR)

Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time-to-context
Document automation logic and maintain version control for all playbooks
Measure and report automation coverage rate as a standing KRI

2. Cloud Security Posture Management

Cloud posture management is the infrastructure-facing domain of the role, covering vulnerability management, identity governance, and configuration and change control. AWS EKS and Serverless resources are the primary environments.

Vulnerability management

Own the end-to-end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context
Manage EKS-specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence
Coordinate remediation with engineering teams by opening well-scoped tickets, tracking progress, and escalating SLA breaches
Maintain MTTR and SLA compliance data by severity tier
Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows

Identity and access governance

Review and approve IAM policy changes, enforcing least-privilege and flagging over-permissioned roles or service accounts
Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross-account trust boundaries
Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required
Support the secrets rotation program and enforce zero hardcoded credentials across the estate

Configuration and change management

Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates
Own container image security: base image update cadence, scanning results review, and image ownership classification
Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows
Maintain a configuration baseline for critical cloud resources and flag drift

3. Posture Tracking and Reporting

The engineer is the primary data owner for security posture metrics across both SOC and cloud domains. Reporting outputs feed executive dashboards, GRC compliance evidence, and quarterly risk reviews.

KRI data collection

Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences
SOC KRIs: MTTA (Mean Time to Acknowledge), MTTR, false-positive rate, automation coverage rate, detection coverage score
VM KRIs: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count
Posture KRIs: CSPM score, under-protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage

Recurring control reviews

Listat via Himalayas

CV-ul tău trece de ATS-ul lor?94% din cursanți primesc interviuri în 2 săptămâni.
Kit AI · €24 →
Challenge nou

Aplici și nu primești niciun răspuns?

Challenge-ul de 5 Zile îți arată exact ce te oprește — CV, LinkedIn, scrisoare de intenție și interviu, cu scoruri reale, nu păreri.

Vezi Challenge-ul de 5 Zile →