Security Operations Engineer

The Security Operations Engineer is the operational backbone of the Security Operations Centre. This fully remote, hands-on role owns security alert design, triage and automated response, cloud security posture management across AWS and EKS, and security posture tracking and reporting. The role partners with Application Security, DevOps, Engineering, and Security GRC teams, driving detection-as-code, SOAR automation, vulnerability remediation, IAM governance, compliance reporting, and infrastructure security.

Responsibilities

  • Design and maintain SIEM detection rules across cloud, container, identity, and application layers.
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps across AWS and EKS.
  • Integrate threat intelligence feeds and maintain a risk-prioritized detection backlog.
  • Perform daily alert triage, investigation, tuning, and runbook maintenance.
  • Build and maintain SOAR playbooks and automate enrichment and response workflows.
  • Own vulnerability triage and remediation across cloud and container environments.
  • Oversee CSPM posture targets and critical finding remediation.
  • Review IAM policies, workload identity, secrets management, and cloud network security changes.
  • Track SOC and cloud security KRIs, MTTR, SLA compliance, posture scores, and automation coverage.
  • Produce structured findings, posture reports, audit evidence, and due diligence materials.

Requirements

  • 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering.
  • Hands-on AWS security experience including IAM, networking, CloudTrail, GuardDuty, and cloud-native security services.
  • Kubernetes and EKS security experience including pod security, network policies, workload identity, and image scanning.
  • SIEM operations, alert triage, detection rule authoring, log analysis, and correlation experience.
  • Vulnerability management experience with CSPM, CVSS prioritization, and SLA frameworks.
  • Ability to review Terraform or CloudFormation for security misconfigurations.
  • Incident response experience covering investigation, containment, and reporting.
  • Experience in a regulated environment such as FinTech, payments, banking, or crypto.
  • Experience with Datadog, Wiz, Orca Security, AWS Secrets Manager, and SOAR platforms.
  • Python or Bash scripting ability.
  • Familiarity with SOC 2, ISO 27001, GDPR, and DORA.
  • Understanding of cryptocurrency or blockchain security considerations.
  • Strong written communication and cross-functional coordination skills.
  • Experience in a startup or scale-up environment.
  • AI tooling familiarity and interest in applying AI to operational workflows.
  • AWS Security Specialty certification is valued.

Benefits

  • Ownership of the SOC and cloud security posture function from day one.
  • Broad exposure to detection engineering, cloud security, container security, incident response, and compliance.
  • Collaborative team culture with a mature Application Security function and strong leadership support.
  • Remote-first, fully remote work environment.
  • Learning and development resources, support, and professional autonomy.
  • Mental health support services.
  • Stock option plan for full-time employees.
  • Competitive compensation and meaningful health coverage.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available