Senior Security Engineer

SeniorRemote
CompanyREPAY Management Services
LocationRemote - US, Atlanta Headquarters
CategorySecurity
SenioritySenior
WorkplaceRemote
Posted2026-09-02
Estimated salary$7K - $18K (a market estimate, not the employer's figure)
Viaworkday

Description

ABOUT REPAY
REPAY (“Realtime Electronic Payments” / NASDAQ TICKER: RPAY) is an established and fast-growing publicly traded financial technology and payment processing company headquartered in Atlanta, Georgia, with offices across the country. REPAY enables its customers to accept payments anytime, anywhere, and through any channel while providing a secure, seamless, and enjoyable payment experience for the end consumers. REPAY offers a comprehensive suite of electronic payment and funding solutions, including debit and credit card processing, ACH processing, Instant Funding, and electronic bill payment systems with full IVR, text, and mobile capabilities. The scalability of its products allows merchants of all sizes to add an instant arsenal of intelligent payment technology solutions to their businesses without significant development costs or infrastructure investments.

ABOUT THE ROLE

REPAY is seeking a highly motivated, self-driven Senior Security Engineer to join our Security Operations team. This role sits at the center of our Security Operations Center (SOC) — monitoring and triaging security event queues, conducting proactive threat hunting, and driving incidents from detection through containment and remediation. You will partially own and continuously improve our response playbooks and procedures, build and maintain the automation and integrations that reduce repetitive operational work, operationalize new detections, and assist with vulnerability management as needed.

You will also use and train our agentic SOC platform, applying AI-driven workflows to improve triage quality and reduce time to detect and respond. This role participates in the 24/7 weekly on call rotation and partners closely with IT, cloud engineering, network, and application teams to coordinate response actions and remediations. The ideal candidate is a curious, hands-on investigator who is comfortable making decisions under pressure, communicates clearly during active incidents, and turns every incident into a lasting improvement.

RESPONSIBILITIES

Security Monitoring and Triage

  • Monitor and triage security event and alert queues across SIEM, EDR/XDR, identity, email, cloud, and network telemetry, ensuring timely and accurate disposition.
  • Investigate alerts to determine scope, impact, and root cause, escalating confirmed incidents according to defined severity criteria.
  • Participate in the 24/7 weekly Security Operations on call rotation, providing timely response to high priority security alerts, incidents, and escalations.
  • Document investigative findings, decisions, and evidence to a standard that supports audit, legal, and post-incident review needs.

Threat Hunting

  • Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Leverage threat intelligence, MITRE ATT&CK, and adversary tradecraft to surface activity that evades existing detections.
  • Produce hunt reports covering findings, detection gaps, and recommended improvements.

Incident Response, Playbooks, and Procedures

  • Execute incident response activities including triage, investigation, containment, eradication, and recovery.
  • Own the development, maintenance, and testing of response playbooks, runbooks, and standard operating procedures.
  • Lead or contribute to post-incident reviews, tracking corrective actions to closure and updating playbooks based on lessons learned.
  • Support tabletop exercises and purple team activities to validate detection and response readiness.

Response Actions Using Security Tooling

  • Take containment and remediation actions using enterprise security tooling, including EDR/XDR host isolation and response, SASE/SSE policy enforcement, secure email gateway (SEG) and DLP rule tuning.
  • Request, review, and implement firewall and network access rule changes to block malicious activity and reduce exposure.

Agentic SOC Enablement

  • Use the agentic SOC platform in daily operations to accelerate alert triage, enrichment, and investigation.
  • Validate AI-generated conclusions and recommended actions, ensuring appropriate human oversight and governance of automated response.
  • Train, tune, and provide structured feedback on agent workflows, prompts, and knowledge sources to improve accuracy and reduce false positives.

Security Engineering

  • Design and implement automation for repetitive operational tasks such as enrichment, ticket creation, evidence collection, triaging, and response actions (containment and remediation).
  • Build and maintain automated playbooks and integrations across security and IT platforms using APIs and scripting.
  • Track operational metrics such as time to detect, time to respond, and false positive rate, and use them to prioritize automation work.
  • Update or configure security platforms or infrastructure hosting them using IaC.
  • Operationalize new detections identified through threat hunting.
  • Design and implement security control improvements to address risks and gaps in security monitoring and defense.

Vulnerability Management Support

  • Assist with vulnerability management activities including scan review, validation, risk-based prioritization, and remediation tracking.
  • Correlate vulnerability data with threat intelligence and evidence of active exploitation to inform remediation urgency.
  • Partner with IT, infrastructure, and development teams to drive remediation and verify closure.

Cross-Team Coordination

  • Coordinate response actions and remediations with IT, cloud engineering, network, application development, and business teams.
  • Communicate incident status, impact, and required actions clearly to both technical and non-technical stakeholders.
  • Work collaboratively with end users to assist with and resolve security events or concerns they report.
  • Mentor junior engineers and strengthen shift handoff quality, documentation, and knowledge sharing across the team.

SKILLS & EXPERIENCE NEEDED

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 4–7+ years of experience in a SOC, incident response, threat hunting, security engineering, or security operations roles.
  • Hands-on experience investigating alerts in a SIEM (Splunk Enterprise Security preferred) and working within EDR/XDR platforms.
  • Strong understanding of attacker techniques, MITRE ATT&CK, malware behavior, phishing, identity-based attacks, and cloud abuse patterns.
  • Working knowledge of networking fundamentals, operating system internals (Windows, Linux, macOS), and cloud platforms (AWS and/or Azure).
  • Familiarity with firewall rules, proxy and SASE/SSE policies, and DLP concepts in the context of incident response.
  • Experience with Python, PowerShell, or similar scripting languages for automation and API integration.
  • Ability to write and maintain clear playbooks, procedures, and incident documentation.
  • Willingness and ability to participate in a 24/7 weekly on call rotation.
  • Sound judgment under pressure, strong written and verbal communication skills, and a bias toward continuous improvement.

Preferred Skills

  • Experience using or tuning agentic AI or LLM-based tooling to support SOC triage, investigation, and response.
  • Experience with automation (SOAR, Agentic) platforms and detection-as-code or automation-as-code practices.
  • Experience using IaC (i.e. Terraform or CloudFormation) to manage and deploy infrastructure or security tools.
  • Exposure to vulnerability management tooling and risk-based prioritization frameworks such as CVSS, EPSS, and the CISA KEV catalog.
  • Experience in a regulated environment such as payments, financial services, or fintech, with exposure to PCI DSS, SOC 2, or similar frameworks.
  • Experience with digital forensics, log and memory analysis, or malware triage.
  • Relevant certifications (e.g., GIAC GCIH, GCIA, GC