Point your AI agent at freehire and let it find you a job.

Get the CLI →
Discussion

Senior Security Engineer

NewBe an early applicant

ABOUT REPAY
REPAY (“Realtime Electronic Payments” / NASDAQ TICKER: RPAY) is an established and fast-growing publicly traded financial technology and payment processing company headquartered in Atlanta, Georgia, with offices across the country. REPAY enables its customers to accept payments anytime, anywhere, and through any channel while providing a secure, seamless, and enjoyable payment experience for the end consumers. REPAY offers a comprehensive suite of electronic payment and funding solutions, including debit and credit card processing, ACH processing, Instant Funding, and electronic bill payment systems with full IVR, text, and mobile capabilities. The scalability of its products allows merchants of all sizes to add an instant arsenal of intelligent payment technology solutions to their businesses without significant development costs or infrastructure investments.

ABOUT THE ROLE

REPAY is seeking a highly motivated, self-driven Senior Security Engineer to join our Security Operations team. This role sits at the center of our Security Operations Center (SOC) — monitoring and triaging security event queues, conducting proactive threat hunting, and driving incidents from detection through containment and remediation. You will partially own and continuously improve our response playbooks and procedures, build and maintain the automation and integrations that reduce repetitive operational work, operationalize new detections, and assist with vulnerability management as needed.

You will also use and train our agentic SOC platform, applying AI-driven workflows to improve triage quality and reduce time to detect and respond. This role participates in the 24/7 weekly on call rotation and partners closely with IT, cloud engineering, network, and application teams to coordinate response actions and remediations. The ideal candidate is a curious, hands-on investigator who is comfortable making decisions under pressure, communicates clearly during active incidents, and turns every incident into a lasting improvement.

RESPONSIBILITIES

Security Monitoring and Triage

  • Monitor and triage security event and alert queues across SIEM, EDR/XDR, identity, email, cloud, and network telemetry, ensuring timely and accurate disposition.
  • Investigate alerts to determine scope, impact, and root cause, escalating confirmed incidents according to defined severity criteria.
  • Participate in the 24/7 weekly Security Operations on call rotation, providing timely response to high priority security alerts, incidents, and escalations.
  • Document investigative findings, decisions, and evidence to a standard that supports audit, legal, and post-incident review needs.

Threat Hunting

  • Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Leverage threat intelligence, MITRE ATT&CK, and adversary tradecraft to surface activity that evades existing detections.
  • Produce hunt reports covering findings, detection gaps, and recommended improvements.

Incident Response, Playbooks, and Procedures

  • Execute incident response activities including triage, investigation, containment, eradication, and recovery.
  • Own the development, maintenance, and testing of response playbooks, runbooks, and standard operating procedures.
  • Lead or contribute to post-incident reviews, tracking corrective actions to closure and updating playbooks based on lessons learned.
  • Support tabletop exercises and purple team activities to validate detection and response readiness.

Response Actions Using Security Tooling

  • Take containment and remediation actions using enterprise security tooling, including EDR/XDR host isolation and response, SASE/SSE policy enforcement, secure email gateway (SEG) and DLP rule tuning.
  • Request, review, and implement firewall and network access rule changes to block malicious activity and reduce exposure.

Agentic SOC Enablement

  • Use the agentic SOC platform in daily operations to accelerate alert triage, enrichment, and investigation.
  • Validate AI-generated conclusions and recommended actions, ensuring appropriate human oversight and governance of automated response.
  • Train, tune, and provide structured feedback on agent workflows, prompts, and knowledge sources to improve accuracy and reduce false positives.

Security Engineering

  • Design and implement automation for repetitive operational tasks such as enrichment, ticket creation, evidence collection, triaging, and response actions (containment and remediation).
  • Build and maintain automated playbooks and integrations across security and IT platforms using APIs and scripting.
  • Track operational metrics such as time to detect, time to respond, and false positive rate, and use them to prioritize automation work.
  • Update or configure security platforms or infrastructure hosting them using IaC.
  • Operationalize new detections identified through threat hunting.
  • Design and implement security control improvements to address risks and gaps in security monitoring and defense.

Vulnerability Management Support

  • Assist with vulnerability management activities including scan review, validation, risk-based prioritization, and remediation tracking.
  • Correlate vulnerability data with threat intelligence and evidence of active exploitation to inform remediation urgency.
  • Partner with IT, infrastructure, and development teams to drive remediation and verify closure.

Cross-Team Coordination

  • Coordinate response actions and remediations with IT, cloud engineering, network, application development, and business teams.
  • Communicate incident status, impact, and required actions clearly to both technical and non-technical stakeholders.
  • Work collaboratively with end users to assist with and resolve security events or concerns they report.
  • Mentor junior engineers and strengthen shift handoff quality, documentation, and knowledge sharing across the team.

SKILLS & EXPERIENCE NEEDED

Qualifications:

  • Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 4–7+ years of experience in a SOC, incident response, threat hunting, security engineering, or security operations roles.
  • Hands-on experience investigating alerts in a SIEM (Splunk Enterprise Security preferred) and working within EDR/XDR platforms.
  • Strong understanding of attacker techniques, MITRE ATT&CK, malware behavior, phishing, identity-based attacks, and cloud abuse patterns.
  • Working knowledge of networking fundamentals, operating system internals (Windows, Linux, macOS), and cloud platforms (AWS and/or Azure).
  • Familiarity with firewall rules, proxy and SASE/SSE policies, and DLP concepts in the context of incident response.
  • Experience with Python, PowerShell, or similar scripting languages for automation and API integration.
  • Ability to write and maintain clear playbooks, procedures, and incident documentation.
  • Willingness and ability to participate in a 24/7 weekly on call rotation.
  • Sound judgment under pressure, strong written and verbal communication skills, and a bias toward continuous improvement.

Preferred Skills:

  • Experience using or tuning agentic AI or LLM-based tooling to support SOC triage, investigation, and response.
  • Experience with automation (SOAR, Agentic) platforms and detection-as-code or automation-as-code practices.
  • Experience using IaC (i.e. Terraform or CloudFormation) to manage and deploy infrastructure or security tools.
  • Exposure to vulnerability management tooling and risk-based prioritization frameworks such as CVSS, EPSS, and the CISA KEV catalog.
  • Experience in a regulated environment such as payments, financial services, or fintech, with exposure to PCI DSS, SOC 2, or similar frameworks.
  • Experience with digital forensics, log and memory analysis, or malware triage.
  • Relevant certifications (e.g., GIAC GCIH, GCIA, GCFA, GCTI, GDAT, Splunk Core/Power User, CompTIA CySA+, AWS/Azure Security).

WHY JOIN REPAY.… BECAUSE CULTURE IS EVERYTHING


GROWTH & PEOPLE-CENTERED LEADERSHIP
As the industry-leading financial technology provider in the Consumer Finance and Business to Business spaces, we continue to set the standard for application development and delivery. In 2019, REPAY became a public company listed on the Nasdaq Stock Market (RPAY). For the past three consecutive years, we have placed on the ACG® Atlanta Georgia Fast 40, a list recognizing the top 40 fastest-growing middle-market companies in Georgia. REPAY’s leadership empowers each team member to make a difference and stretch to their fullest potential. Our dedication to frequent, transparent communication is shown with companywide meetings where our leaders share company vision and encourage employees to ask questions.

FUN WORK ENVIRONMENT & GREAT TEAMS
We offer it all: business to casual dress, great snacks & beverages, and open-air collaborative team settings. REPAY has been certified as a Great Place to Work® company for 2017, 2018, 2019, 2020, 2021, and 2022. The REPAY team is fun, smart, collaborative, and truly enjoys working together. Making a difference in our local communities – we support several philanthropic initiatives every year to give back to our local communities. We are self-driven, motivated professionals who do not require micro-management to ensure we produce high quality and timely work.

INNOVATION & EDUCATION
We create highly sophisticated payment processing applications and are always pushing the boundaries of what is possible. We are constantly revolutionizing the industry by building on new ideas from clients and employees. We provide the resources necessary to ensure new innovations can develop quickly and with quality. We encourage continuing education, including professional conferences and events.

PUTTING OUR PEOPLE FIRST
We believe our people are the best, and we care immensely about their success. We offer a comprehensive benefits package which includes 100% coverage of employee healthcare premiums and several free benefits, including life insurance, disability insurance, and work-life balance resources. All benefits go into effect day one. Our employees’ futures are important to us, which is why we have a 401(k)-employer match and and an Employee Stock Purchase Plan. REPAY employees are eligible to participate in our Annual Bonus Program. This bonus award reflects excellent performance of individual contributions and goals achieved during the past year.

REPAY’s core values are Excellence, Passion, Innovation, Respect, and Integrity.

REPAY is an Equal Opportunity Employer and we promote a company culture where diversity, equity and inclusion are central. We are committed to build our teams and grow a company in which employees can succeed, regardless of race, color, national origin, sex, sexual orientation, gender identity or expression, transgender status, pregnancy, religion, age (40 and over), disability, service in the uniformed services, protected veteran status, genetic information, or any other classification protected by federal, state or local law. Celebrating our diverse backgrounds, views and beliefs allows us to embrace what makes us unique and continue to innovate and push the boundaries of what is possible.

We are interested in every qualified candidate who is eligible to work in the United States. This position is not eligible for hire in California. Additionally, we are not able to sponsor visas.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available