Security Operations Engineer
Remote
RemoteFull TimeMid LevelMedium
Full TimeMid LevelMedium
Job Summary
Security Operations Engineer is the operational backbone of the SOC, responsible for end-to-end security detection and response in the SOC, including SIEM rule design and alerting, triage, and automated response via SOAR; responsible for cloud security posture management across AWS EKS, vulnerability triage and remediation cycles, incident response, and collaboration with AppSec, DevOps, and GRC; remote-first FinTech environment with emphasis on detection engineering, cloud security, container security, incident response, and compliance.
Required Qualifications
- 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
- Hands-on AWS security experience
- Kubernetes and EKS security experience
- SIEM operations: alert triage, detection rule authoring (signature-based and behavioural)
- Vulnerability management: CSPM tooling, risk-based prioritisation, CVSS scoring, SLA framework operation
- IaC security: ability to read and review Terraform or CloudFormation for misconfigurations
- Incident response: investigation, containment, and post-incident reporting
- Professional certifications: AWS Security Specialty (highly valued)
- Experience with CSPM and SIEM platforms: Datadog, Wiz, Orca Security
- Experience with secrets management platforms: AWS Secrets Manager
- Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, DORA
- Scripting ability in Python or Bash for detection-as-code and operational automation
- Experience with SOAR or workflow automation platforms
- Understanding of cryptocurrency or blockchain security considerations
- Experience in a startup or scale-up environment
- AI tooling familiarity and interest in applying AI to operational workflows
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.