Security Operations Engineer

Yellow Card supplies licensed stablecoin payment rails covering treasury, cross-border payments and liquidity for businesses across African markets.

United States
About Yellow Card

Yellow Card helps businesses expand across Africa through stablecoin-powered payment infrastructure. Users can buy, sell, and store digital assets using local currencies, manage treasury operations, and access cross-border payment solutions. Yellow Card serves as both an on/off ramp and payments API provider across emerging markets.

View jobs by Yellow Card

Skills

About the Role

The Security Operations Engineer is the operational backbone of the Security Operations Centre. This fully remote, hands-on role owns security alert design, triage and automated response, cloud security posture management across AWS and EKS, and security posture tracking and reporting. The role partners with Application Security, DevOps, Engineering, and Security GRC teams, driving detection-as-code, SOAR automation, vulnerability remediation, IAM governance, compliance reporting, and infrastructure security.

Requirements

  • 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering.
  • Hands-on AWS security experience including IAM, networking, CloudTrail, GuardDuty, and cloud-native security services.
  • Kubernetes and EKS security experience including pod security, network policies, workload identity, and image scanning.
  • SIEM operations, alert triage, detection rule authoring, log analysis, and correlation experience.
  • Vulnerability management experience with CSPM, CVSS prioritization, and SLA frameworks.
  • Ability to review Terraform or CloudFormation for security misconfigurations.
  • Incident response experience covering investigation, containment, and reporting.
  • Experience in a regulated environment such as FinTech, payments, banking, or crypto.
  • Experience with Datadog, Wiz, Orca Security, AWS Secrets Manager, and SOAR platforms.
  • Python or Bash scripting ability.
  • Familiarity with SOC 2, ISO 27001, GDPR, and DORA.
  • Understanding of cryptocurrency or blockchain security considerations.
  • Strong written communication and cross-functional coordination skills.
  • Experience in a startup or scale-up environment.
  • AI tooling familiarity and interest in applying AI to operational workflows.
  • AWS Security Specialty certification is valued.

Responsibilities

  • Design and maintain SIEM detection rules across cloud, container, identity, and application layers.
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps across AWS and EKS.
  • Integrate threat intelligence feeds and maintain a risk-prioritized detection backlog.
  • Perform daily alert triage, investigation, tuning, and runbook maintenance.
  • Build and maintain SOAR playbooks and automate enrichment and response workflows.
  • Own vulnerability triage and remediation across cloud and container environments.
  • Oversee CSPM posture targets and critical finding remediation.
  • Review IAM policies, workload identity, secrets management, and cloud network security changes.
  • Track SOC and cloud security KRIs, MTTR, SLA compliance, posture scores, and automation coverage.
  • Produce structured findings, posture reports, audit evidence, and due diligence materials.

Benefits

  • Ownership of the SOC and cloud security posture function from day one.
  • Broad exposure to detection engineering, cloud security, container security, incident response, and compliance.
  • Collaborative team culture with a mature Application Security function and strong leadership support.
  • Remote-first, fully remote work environment.
  • Learning and development resources, support, and professional autonomy.
  • Mental health support services.
  • Stock option plan for full-time employees.
  • Competitive compensation and meaningful health coverage.