Security Operations Engineer @Teamified
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago

[Hiring] Security Operations Engineer @Teamified

1mth ago - Teamified is hiring a remote Security Operations Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Worldwide

Role Description

Our client operates a cloud-hosted payment platform and validates against PCI DSS v4.0.1 as a Level 2 service provider via SAQ D for Service Providers. They are seeking an experienced security engineer on a three-month contract to run the annual compliance cycle to completion. This is a hands-on engineering role combined with programme ownership. The successful candidate will:

  • Implement technical control changes.
  • Assemble and quality-check the evidence set.
  • Complete the self-assessment questionnaire.
  • Prepare the Attestation of Compliance for executive sign-off.
  • Work alongside the client's existing engineering and operations teams.

The evidence and documentation produced should be built to a standard suitable for external assessment, as the client anticipates moving to QSA-led Level 1 validation in a future cycle.

Responsibilities

  • Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
  • Deliver the logging and monitoring requirements to the standard v4.0.1 expects.
  • Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh).
  • Define the alert triage and response routine the client team will operate day to day.
  • Complete SAQ D for Service Providers and assemble the supporting evidence set.
  • Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
  • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remediation to passing scans.
  • Scope and co-ordinate penetration testing with a qualified independent provider; manage remediation and retest.
  • Maintain third-party service provider due diligence, including partner AOC collection and shared responsibility documentation.
  • Own the delivery plan: schedule, dependencies, risk log, and weekly reporting to leadership.
  • Strengthen change management practice so that changes are raised, approved, tested and evidenced consistently.
  • Document repeatable operational routines (log review, access review, scan cadence, change approval) for the client team to run after the engagement ends.

Qualifications

  • Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
  • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
  • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
  • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
  • Hands-on experience with SIEM or centralised log platforms in a compliance context.
  • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
  • Ability to independently plan, track, report and escalate.
  • Excellent written English.
  • Willingness to record a control as not in place where that is the accurate position.

Requirements

  • Payments, fintech or regulated financial services background.
  • Understanding of the acquirer, processor and card scheme landscape.
  • Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
  • PCIP, ISA, CISSP, CISM or equivalent certification.
  • Jira administration and workflow configuration.
  • Familiarity with ISO 27001 or SOC 2.

Benefits

  • Flexibility in work hours and location, with a focus on managing energy rather than time.
  • Access to online learning platforms and a budget for professional development.
  • A collaborative, no-silos environment, encouraging learning and growth across teams.
  • A dynamic social culture with team lunches, social events, and opportunities for creative input.
  • Health insurance.
  • Leave Benefits.
  • Provident Fund.
  • Gratuity.
Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Operations Engineer @Teamified
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,963+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later