Summary
ExpanseFT is a payment-processing company with a cloud-native platform operating a hybrid environment and a mature security program under PCI DSS requirements. The Security Engineer will own day-to-day security operations, including alert investigation, vulnerability management, endpoint protection, access reviews, incident response, detection engineering, and PCI DSS evidence management.
Responsibilities
- Own the daily security operations queue — triage and investigate alerts and findings across our cloud SIEM, XDR, EDR, and cloud-security-posture tooling. Drive each to closure with documented evidence
- Operate the vulnerability management lifecycle — quarterly external scans (ASV), internal authenticated scans, container and Lambda scanning, dependency alerts, and penetration-test follow-through. Track remediation against SLA
- Administer endpoint protection across our endpoint fleet — agent deployment, policy tuning, detection quality, and threat response
- Run the access-review program — periodic user, privileged, service-account, and third-party access reviews across our identity providers; terminated-user revocation verification; provisioning and deprovisioning execution
- Lead incident response as the primary responder for security events — containment, forensics, communications, and post-incident review — with executive escalation where warranted
- Own the PCI DSS evidence program — collect, label, and retain audit evidence for our annual QSA assessment. Be the QSA's primary operational point-of-contact during fieldwork
- Contribute to detection engineering — write and tune SIEM analytics rules, improve signal-to-noise on high-volume detections, and propose automation improvements
- Participate in on-call support for security alerts, including out-of-hours escalation
- Deliver annual security-awareness training and support the quarterly personnel review process
- Support physical security at our data center facility (visitor logs, device inspections, media destruction, rogue-wireless detection) on a periodic on-site basis
Skills
- * **4+ years** in Security Operations (L2/L3), Security Engineering, or a closely related role, in a regulated environment (payments, finance, healthcare, or equivalent)
- * Hands-on experience operating **AWS security services** (e.g., Security Hub, GuardDuty, Inspector, IAM) in a multi-account setup
- * Hands-on experience with a **cloud SIEM**, including **KQL** (Kusto Query Language) or equivalent query fluency; comfortable writing and tuning analytics rules, not just consuming them
- * Experience administering an **EDR platform** (SentinelOne, Defender for Endpoint, CrowdStrike, or equivalent)
- * Demonstrable experience running a **vulnerability management lifecycle** under SLA — scan, triage, evidence, remediation tracking
- * Working knowledge of **PCI DSS v4.0** (requirements 5, 7, 8, 9, 10, 11, and 12 in particular), or substantively equivalent experience with SOC 2, ISO 27001, HITRUST, or NIST CSF
- * Proficient in at least one scripting language for operations automation — **Python, Bash, or PowerShell** — plus comfort with jq, AWS CLI, and az CLI
- * Strong written communication — you will be the voice of security in tickets, runbooks, and audit evidence a QSA reads a year later
- * Able to work the queue independently, prioritize under SLA pressure, and escalate proactively
- * One or more: **CISSP**, **GIAC** (GCIH, GCED, GMON, GCDA, GSEC), **AWS Security Specialty**, **Azure Security Engineer Associate (AZ-500)**, **CompTIA CySA+**
- * Prior role as the evidence point-of-contact on a **PCI DSS QSA engagement**
- * Experience with open-source cloud security assessment tooling (e.g., **Prowler**, **Steampipe**, **CloudQuery**, **cfn-nag**, **checkov**, **tfsec**, **trivy**)
- * Experience reading or contributing to **AWS CDK (TypeScript)** or Terraform
- * Experience with a next-gen firewall platform (Cisco FTD/FMC, Palo Alto, Fortinet, or equivalent)
- * Experience on a formal on-call rotation (PagerDuty, Opsgenie, or equivalent)
Qualifications
Must Haves
- * **4+ years** in Security Operations (L2/L3), Security Engineering, or a closely related role, in a regulated environment (payments, finance, healthcare, or equivalent)
- * Hands-on experience operating **AWS security services** (e.g., Security Hub, GuardDuty, Inspector, IAM) in a multi-account setup
- * Hands-on experience with a **cloud SIEM**, including **KQL** (Kusto Query Language) or equivalent query fluency; comfortable writing and tuning analytics rules, not just consuming them
- * Experience administering an **EDR platform** (SentinelOne, Defender for Endpoint, CrowdStrike, or equivalent)
- * Demonstrable experience running a **vulnerability management lifecycle** under SLA — scan, triage, evidence, remediation tracking
- * Working knowledge of **PCI DSS v4.0** (requirements 5, 7, 8, 9, 10, 11, and 12 in particular), or substantively equivalent experience with SOC 2, ISO 27001, HITRUST, or NIST CSF
- * Proficient in at least one scripting language for operations automation — **Python, Bash, or PowerShell** — plus comfort with jq, AWS CLI, and az CLI
- * Strong written communication — you will be the voice of security in tickets, runbooks, and audit evidence a QSA reads a year later
- * Able to work the queue independently, prioritize under SLA pressure, and escalate proactively
Nice to Haves
- * One or more: **CISSP**, **GIAC** (GCIH, GCED, GMON, GCDA, GSEC), **AWS Security Specialty**, **Azure Security Engineer Associate (AZ-500)**, **CompTIA CySA+**
- * Prior role as the evidence point-of-contact on a **PCI DSS QSA engagement**
- * Experience with open-source cloud security assessment tooling (e.g., **Prowler**, **Steampipe**, **CloudQuery**, **cfn-nag**, **checkov**, **tfsec**, **trivy**)
- * Experience reading or contributing to **AWS CDK (TypeScript)** or Terraform
- * Experience with a next-gen firewall platform (Cisco FTD/FMC, Palo Alto, Fortinet, or equivalent)
- * Experience on a formal on-call rotation (PagerDuty, Opsgenie, or equivalent)
Benefits
- Training and certification budget — annual allocation for at least one major security certification plus a security conference each year
- Remote but NY based