Senior Security Engineer

Posted Yesterday
Hiring Remotely in Headquarters, AZ, USA
In-Office or Remote
Senior level
Fintech • Hardware • Payments
The Role
Monitors and investigates security alerts across SIEM, endpoint, identity, cloud, email, and network environments. Conducts threat hunting, incident response, containment, remediation, vulnerability management, and post-incident reviews. Develops playbooks, automation, integrations, detections, and infrastructure-as-code deployments. Uses and tunes agentic SOC tooling while maintaining human oversight. Coordinates with technical and business teams, participates in a 24/7 on-call rotation, mentors junior engineers, and improves security operations through metrics and continuous improvement.
Summary Generated by Built In

ABOUT REPAY
REPAY (“Realtime Electronic Payments” / NASDAQ TICKER: RPAY) is an established and fast-growing publicly traded financial technology and payment processing company headquartered in Atlanta, Georgia, with offices across the country. REPAY enables its customers to accept payments anytime, anywhere, and through any channel while providing a secure, seamless, and enjoyable payment experience for the end consumers. REPAY offers a comprehensive suite of electronic payment and funding solutions, including debit and credit card processing, ACH processing, Instant Funding, and electronic bill payment systems with full IVR, text, and mobile capabilities. The scalability of its products allows merchants of all sizes to add an instant arsenal of intelligent payment technology solutions to their businesses without significant development costs or infrastructure investments.

ABOUT THE ROLE

REPAY is seeking a highly motivated, self-driven Senior Security Engineer to join our Security Operations team. This role sits at the center of our Security Operations Center (SOC) — monitoring and triaging security event queues, conducting proactive threat hunting, and driving incidents from detection through containment and remediation. You will partially own and continuously improve our response playbooks and procedures, build and maintain the automation and integrations that reduce repetitive operational work, operationalize new detections, and assist with vulnerability management as needed.

 

You will also use and train our agentic SOC platform, applying AI-driven workflows to improve triage quality and reduce time to detect and respond. This role participates in the 24/7 weekly on call rotation and partners closely with IT, cloud engineering, network, and application teams to coordinate response actions and remediations. The ideal candidate is a curious, hands-on investigator who is comfortable making decisions under pressure, communicates clearly during active incidents, and turns every incident into a lasting improvement.

 

RESPONSIBILITIES

Security Monitoring and Triage

  • Monitor and triage security event and alert queues across SIEM, EDR/XDR, identity, email, cloud, and network telemetry, ensuring timely and accurate disposition.
  • Investigate alerts to determine scope, impact, and root cause, escalating confirmed incidents according to defined severity criteria.
  • Participate in the 24/7 weekly Security Operations on call rotation, providing timely response to high priority security alerts, incidents, and escalations.
  • Document investigative findings, decisions, and evidence to a standard that supports audit, legal, and post-incident review needs.

Threat Hunting

  • Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Leverage threat intelligence, MITRE ATT&CK, and adversary tradecraft to surface activity that evades existing detections.
  • Produce hunt reports covering findings, detection gaps, and recommended improvements.

Incident Response, Playbooks, and Procedures

  • Execute incident response activities including triage, investigation, containment, eradication, and recovery.
  • Own the development, maintenance, and testing of response playbooks, runbooks, and standard operating procedures.
  • Lead or contribute to post-incident reviews, tracking corrective actions to closure and updating playbooks based on lessons learned.
  • Support tabletop exercises and purple team activities to validate detection and response readiness.

Response Actions Using Security Tooling

  • Take containment and remediation actions using enterprise security tooling, including EDR/XDR host isolation and response, SASE/SSE policy enforcement, secure email gateway (SEG) and DLP rule tuning.
  • Request, review, and implement firewall and network access rule changes to block malicious activity and reduce exposure.

Agentic SOC Enablement

  • Use the agentic SOC platform in daily operations to accelerate alert triage, enrichment, and investigation.
  • Validate AI-generated conclusions and recommended actions, ensuring appropriate human oversight and governance of automated response.
  • Train, tune, and provide structured feedback on agent workflows, prompts, and knowledge sources to improve accuracy and reduce false positives.

Security Engineering

  • Design and implement automation for repetitive operational tasks such as enrichment, ticket creation, evidence collection, triaging, and response actions (containment and remediation).
  • Build and maintain automated playbooks and integrations across security and IT platforms using APIs and scripting.
  • Track operational metrics such as time to detect, time to respond, and false positive rate, and use them to prioritize automation work.
  • Update or configure security platforms or infrastructure hosting them using IaC.
  • Operationalize new detections identified through threat hunting.
  • Design and implement security control improvements to address risks and gaps in security monitoring and defense.

Vulnerability Management Support

  • Assist with vulnerability management activities including scan review, validation, risk-based prioritization, and remediation tracking.
  • Correlate vulnerability data with threat intelligence and evidence of active exploitation to inform remediation urgency.
  • Partner with IT, infrastructure, and development teams to drive remediation and verify closure.

Cross-Team Coordination

  • Coordinate response actions and remediations with IT, cloud engineering, network, application development, and business teams.
  • Communicate incident status, impact, and required actions clearly to both technical and non-technical stakeholders.
  • Work collaboratively with end users to assist with and resolve security events or concerns they report.
  • Mentor junior engineers and strengthen shift handoff quality, documentation, and knowledge sharing across the team.

 

SKILLS & EXPERIENCE NEEDED

Qualifications:

  • Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 4–7+ years of experience in a SOC, incident response, threat hunting, security engineering, or security operations roles.
  • Hands-on experience investigating alerts in a SIEM (Splunk Enterprise Security preferred) and working within EDR/XDR platforms.
  • Strong understanding of attacker techniques, MITRE ATT&CK, malware behavior, phishing, identity-based attacks, and cloud abuse patterns.
  • Working knowledge of networking fundamentals, operating system internals (Windows, Linux, macOS), and cloud platforms (AWS and/or Azure).
  • Familiarity with firewall rules, proxy and SASE/SSE policies, and DLP concepts in the context of incident response.
  • Experience with Python, PowerShell, or similar scripting languages for automation and API integration.
  • Ability to write and maintain clear playbooks, procedures, and incident documentation.
  • Willingness and ability to participate in a 24/7 weekly on call rotation.
  • Sound judgment under pressure, strong written and verbal communication skills, and a bias toward continuous improvement.

Preferred Skills:

  • Experience using or tuning agentic AI or LLM-based tooling to support SOC triage, investigation, and response.
  • Experience with automation (SOAR, Agentic) platforms and detection-as-code or automation-as-code practices.
  • Experience using IaC (i.e. Terraform or CloudFormation) to manage and deploy infrastructure or security tools.
  • Exposure to vulnerability management tooling and risk-based prioritization frameworks such as CVSS, EPSS, and the CISA KEV catalog.
  • Experience in a regulated environment such as payments, financial services, or fintech, with exposure to PCI DSS, SOC 2, or similar frameworks.
  • Experience with digital forensics, log and memory analysis, or malware triage.
  • Relevant certifications (e.g., GIAC GCIH, GCIA, GCFA, GCTI, GDAT, Splunk Core/Power User, CompTIA CySA+, AWS/Azure Security).

WHY JOIN REPAY.… BECAUSE CULTURE IS EVERYTHING

GROWTH & PEOPLE-CENTERED LEADERSHIP
As the industry-leading financial technology provider in the Consumer Finance and Business to Business spaces, we continue to set the standard for application development and delivery. In 2019, REPAY became a public company listed on the Nasdaq Stock Market (RPAY). For the past three consecutive years, we have placed on the ACG® Atlanta Georgia Fast 40, a list recognizing the top 40 fastest-growing middle-market companies in Georgia. REPAY’s leadership empowers each team member to make a difference and stretch to their fullest potential. Our dedication to frequent, transparent communication is shown with companywide meetings where our leaders share company vision and encourage employees to ask questions. 

FUN WORK ENVIRONMENT & GREAT TEAMS
We offer it all: business to casual dress, great snacks & beverages, and open-air collaborative team settings. REPAY has been certified as a Great Place to Work® company for 2017, 2018, 2019, 2020, 2021, and 2022. The REPAY team is fun, smart, collaborative, and truly enjoys working together. Making a difference in our local communities – we support several philanthropic initiatives every year to give back to our local communities. We are self-driven, motivated professionals who do not require micro-management to ensure we produce high quality and timely work.

INNOVATION & EDUCATION
We create highly sophisticated payment processing applications and are always pushing the boundaries of what is possible. We are constantly revolutionizing the industry by building on new ideas from clients and employees. We provide the resources necessary to ensure new innovations can develop quickly and with quality. We encourage continuing education, including professional conferences and events.  

PUTTING OUR PEOPLE FIRST
We believe our people are the best, and we care immensely about their success. We offer a comprehensive benefits package which includes 100% coverage of employee healthcare premiums and several free benefits, including life insurance, disability insurance, and work-life balance resources. All benefits go into effect day one. Our employees’ futures are important to us, which is why we have a 401(k)-employer match and and an Employee Stock Purchase Plan. REPAY employees are eligible to participate in our Annual Bonus Program. This bonus award reflects excellent performance of individual contributions and goals achieved during the past year.

REPAY’s core values are Excellence, Passion, Innovation, Respect, and Integrity.

REPAY is an Equal Opportunity Employer and we promote a company culture where diversity, equity and inclusion are central. We are committed to build our teams and grow a company in which employees can succeed, regardless of race, color, national origin, sex, sexual orientation, gender identity or expression, transgender status, pregnancy, religion, age (40 and over), disability, service in the uniformed services, protected veteran status, genetic information, or any other classification protected by federal, state or local law. Celebrating our diverse backgrounds, views and beliefs allows us to embrace what makes us unique and continue to innovate and push the boundaries of what is possible.

We are interested in every qualified candidate who is eligible to work in the United States. This position is not eligible for hire in California. Additionally, we are not able to sponsor visas.

Skills Required

  • Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience
  • 4-7+ years of experience in SOC, incident response, threat hunting, security engineering, or security operations roles
  • Hands-on experience investigating alerts in a SIEM, preferably Splunk Enterprise Security, and working with EDR/XDR platforms
  • Strong understanding of attacker techniques, MITRE ATT&CK, malware behavior, phishing, identity-based attacks, and cloud abuse patterns
  • Working knowledge of networking fundamentals, Windows, Linux, macOS, and AWS and/or Azure
  • Familiarity with firewall rules, proxy and SASE/SSE policies, and DLP concepts
  • Experience with Python, PowerShell, or similar scripting languages for automation and API integration
  • Ability to write and maintain playbooks, procedures, and incident documentation
  • Willingness and ability to participate in a 24/7 weekly on-call rotation
  • Sound judgment under pressure and strong written and verbal communication skills
  • Experience tuning agentic AI or LLM-based tooling for SOC triage, investigation, and response
  • Experience with SOAR or agentic automation platforms and detection-as-code or automation-as-code practices
  • Experience using Terraform or CloudFormation for infrastructure-as-code deployments
  • Exposure to vulnerability management tools and CVSS, EPSS, and CISA KEV prioritization frameworks
  • Experience in payments, financial services, or fintech and exposure to PCI DSS, SOC 2, or similar frameworks
  • Experience with digital forensics, log and memory analysis, or malware triage
  • Relevant certifications such as GIAC GCIH, GCIA, GCFA, GCTI, GDAT, Splunk Core/Power User, CompTIA CySA+, or AWS/Azure Security

REPAY Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is described as comprehensive, with day-one eligibility and robust options including medical, dental, vision, telehealth, and mental health resources. Employee-only premiums are fully covered on at least one plan, reinforcing the depth and accessibility of care.
  • Retirement Support A 401(k) with employer match and financial planning elements are highlighted as core parts of the package. Immediate eligibility in some materials further strengthens long-term savings confidence.
  • Parental & Family Support Paid parental leave and family medical leave are called out, including coverage for adoption and same‑sex parents. Flexible work options and PTO are noted as complementary supports for work-life balance.

REPAY Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, Georgia
1,000 Employees
Year Founded: 2006

What We Do

REPAY is a full-service payment technology and processing provider that enables the expedient and secure collection of payments through any channel at any time. Our omnichannel payment platform provides direct integration with enterprise management systems and access to a suite of payment solutions, including credit/debit card processing, ACH processing, Instant Funding, IVR/phone pay, text pay, electronic bill payment and presentment (EBPP) systems, and consumer-facing payment portals, such as web portals and mobile apps. REPAY also serves the B2B space by automating accounts payable (AP) services and outbound vendor payments through virtual card, ACH, and check processing and effectively managing the full print/mail and electronic communication stream. Through our proprietary clearing and settlement platform, we also offer ISOs and Payment Facilitators more autonomy and greater flexibility than the traditional large acquirer programs. Supported by our high-touch service, powerful payments engine, and intuitive reporting tools, we can build a customized program and ensure on-time and accurate transaction processing. REPAY serves multiple verticals, including personal lending, auto lending, mortgage servicing, B2B, receivables management, healthcare, and credit unions. We recently acquired TriSource Solutions, APS Payments, Ventanex, cPayPlus, and CPS Payment Services. REPAY is a public company listed on the Nasdaq Stock Market under the ticker symbol RPAY and has been a certified Great Place to Work® since 2017. The company is headquartered in Atlanta, GA, and has offices in Bettendorf, IA; Chattanooga, TN; Chicago, IL; Dallas, TX; East Moline, IL; Fort Worth, TX; Mesa, AZ; Phoenix, AZ; Salt Lake City, UT; and Sarasota, FL. For more information, visit www.repay.com.

REPAY Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Most jobs are hybrid requiring 3 days per week onsite. Technology, Product, and Sales roles often have the ability to be fully remote.

Typical time on-site: Flexible
HQAtlanta Headquarters
Tempe Office
Fort Worth Office
Salt Lake City Office
Learn more

Similar Jobs

REPAY Logo REPAY

Product Owner

Fintech • Hardware • Payments
In-Office or Remote
Headquarters, AZ, USA
1000 Employees

REPAY Logo REPAY

Partner Relationship Manager

Fintech • Hardware • Payments
In-Office or Remote
Headquarters, AZ, USA
1000 Employees

REPAY Logo REPAY

Data Scientist

Fintech • Hardware • Payments
In-Office or Remote
Headquarters, AZ, USA
1000 Employees

REPAY Logo REPAY

Senior Relationship Manager

Fintech • Hardware • Payments
In-Office or Remote
Headquarters, AZ, USA
1000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account