Senior Security Operations Engineer

Total Administrative Services Corporation US,
Remote

About The Position

Xformative Payment Systems is seeking a hands-on Senior Security Operations Engineer to help secure and scale our platform. XPS is at the cutting edge of the Fintech industry, specializing in cloud-native payment processing solutions. XPS is a late stage start up that was conceptualized, established, and owned by Total Administrative Systems Corp (TASC) a benefit TPA to offer card based and payment product capabilities associated with healthcare and benefits. The business has new leadership and is entering its growth phase and will be expanding beyond its current markets. At XPS, every member of our small, agile team can drive and create impactful work. Our flexible and fully remote work setup allows you to balance your professional and personal life seamlessly while contributing to our exciting growth journey. The Senior Security Operations Engineer will own day-to-day security operations across our cloud infrastructure and application workloads while partnering closely with our CTO and Information Security & Risk Officer. We’re looking for someone who not only identifies risks, but actively helps solve them through automation, collaboration, and implementation.

Requirements

  • Strong programming skills (Node, Typescript).
  • Expertise in system administration, networking, and operating systems (Linux/Unix).
  • Proficient in automation tools (Github Actions, Cloudformation, Terraform, Serverless, AWS SDK).
  • Knowledge of AWS monitoring and logging tools such as Cloudwatch, CloudTrail, SecurityHub, GuardDuty. etc.
  • Exceptional attention to detail with a preference for highly structured procedures.
  • Solid grasp of CI/CD security, supply-chain risks, and IaC (Terraform) security reviews.
  • Strong incident response skills across detection, investigation, containment, and recovery especially in complex cloud-native environments.
  • Bachelor’s degree in computer science, engineering, or a related field, or equivalent experience in a similar role within the technology sector.
  • Applicants must be authorized to work in the U.S.
  • 5 or more years of large-scale distributed system development.
  • Minimum of 3 years’ fintech experience, or equivalent experience with regulated environments with compliance requirements (e.g., SOC2, PCI DSS)
  • Minimum of 5 years working in Security Operations/Cloud Security/Blue Team roles, with deep, hands-on experience in AWS (IAM/GuardDuty/CloudTrail/CloudWatch).
  • Practical expertise with SIEM/log analytics, EDR, and secrets management (e.g., Vault).
  • Experience with cloud platforms (AWS preferred, GCP, Azure) and containerization technologies (Docker, ECS).
  • Experience with CI/CD pipelines and tools (Github Actions)
  • Willingness to participate in a shared on-call rotation for security incidents

Responsibilities

  • Own day-to-day security operations for AWS-based cloud and serverless workloads including threat detection, alert triage, incident response, forensics, and post-incident learning.
  • Build and tune detections and automations (SIEM rules, SOAR/runbooks, detection-as-code) to reduce MTTA/MTTR and eliminate noisy alerts.
  • Harden CI/CD and software supply chain, and drive “secure by default” patterns in our SDLC.
  • Lead cloud/serverless hardening (IaC reviews, policy-as-code, least privilege IAM design, network segmentation).
  • Partner with DevOps and Engineering teams to evolve identity & access, endpoint/EDR posture.
  • Coordinate vulnerability management end-to-end: scanning, prioritization, remediation, and reporting.
  • Contribute to security governance (policies, standards, tabletop exercises, BCP/DR inputs) and support compliance efforts (e.g., SOC 2/PCI DSS).
  • Build security tooling and integrations for engineers, acknowledging that ease of use and low friction will encourage adoption and adherence.
  • Define metrics/KPIs and regularly communicate risk & progress to engineering and leadership.
  • Mentor engineers on secure design and champion a positive, enablement-first security culture.
  • Participate in architecture and threat modeling discussions to identify security risks early in the design process.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service