Security Operations Engineer

Stealth%20fintech

Job details

  • REMOTE
  • FULL_TIME
  • San Francisco
  • United States
  • Verified 2026-10-06
  • Salary: USD 140,000–170,000/yr
  • Source: Stealth%20fintech public ASHBY source

Original job description

About Tereina

Tereina is on a mission to revolutionize B2B payments. We're a well-funded, early-stage startup, supported by SAP, building cutting-edge solutions that will transform the way businesses move money. Our platform handles cross-border payment processing, counterparty management, bank account administration, and compliance workflows for enterprise customers worldwide.

Our Security Operations function keeps that platform — and the money and data that move through it — secure. Tereina runs on Java and Spring Boot microservices on Google Kubernetes Engine, built and shipped through automated CI/CD pipelines, and operates under the security and compliance expectations of our banking partners, enterprise customers, and SOC 2. Security Operations finds risk across our cloud, build, and runtime environments and drives it to resolution —through automation — and owns our security audit program, from SOC 2 and ISO 27001 through internal audits and partner and customer assessments.

About the Role

Reporting to our head of Technology Operations, the Security Operations Engineer will be part of the team that owns Tereina's daily security operations and help lead our security audit and compliance program. You will help harden our cloud and CI/CD infrastructure and work with engineering teams to maintain secure environments. You will be a point person for security operations; you will identify potential issues before they become actual issues.

You will continue to automate our pipeline from finding identification through to resolution, and you will guide our security practice as we increase our scale and scope. You will also lead audits, including SOC 2 and ISO 27001 and our internal audit program, and serve as the primary point of contact for external auditors, banking partners, and enterprise customers on security and compliance. You will partner closely with Engineering, DevOps, and Compliance to turn findings into clear, prioritized remediation work and to keep our controls continuously audit-ready.

Key Responsibilities

· Cloud Security Posture: Assess, triage, and resolve Security Command Center findings across our GCP environments, hardening cloud infrastructure and configuration.

· Vulnerability Management: Review CVEs and drive remediation efforts throughout the build and runtime environments — from application dependencies and container images to the infrastructure they run on.

· Pinpointed Remediation: Turn automated scanner findings into precise code, library, and configuration change requirements that engineering teams can act on quickly.

· Security Automation: Automate the tools, services, and code build and inspection steps that take a finding from identification to resolution, reducing manual effort and time to remediate.

· CI/CD Hardening: Strengthen the security of our build pipelines and the artifacts they produce, embedding scanning and checks directly into how we ship software.

· Proactive Risk Identification: Act as the point person for security operations, spotting emerging risks early and raising them before they become incidents.

· Security Practice Leadership: Guide and evolve our security practices, standards, and tooling as Tereina grows in scale and scope.

· External Audit Leadership: Lead audits as required, including SOC 2 Type II and ISO 27001 audits end to end — scoping, readiness, evidence collection, auditor walkthroughs, and remediation of exceptions — and manage the relationship with our audit firms and coordinate internal resources.

· Internal Audit Program: Plan and run regular internal audits and control testing against SOC 2, ISO 27001, and our own policies, tracking findings through to closure.

· Auditor & Partner Point of Contact: Serve as the primary point of contact for auditors, and support security reviews, questionnaires, and due diligence from banking partners and enterprise customers.

· Controls & Evidence Automation: Own our security control framework, policies, and risk register, and automate evidence collection so we stay continuously audit-ready rather than preparing once a year.

· Cross-team Collaboration: Work with Engineering, DevOps, Compliance, and leadership across time zones to keep environments secure and embed control requirements into how we build and operate.

Qualifications

· Experience: 5+ years in security operations, security engineering, or DevSecOps, including hands-on ownership of cloud and application security in a production environment.

· Audit Leadership: Proven experience leading SOC 2 Type II and/or ISO 27001 audits and acting as the primary point of contact for external auditors, plus experience planning and running internal audits.

· Controls & Frameworks: Strong working knowledge of security control frameworks (SOC 2 Trust Services Criteria, ISO 27001 Annex A), including designing controls, writing policies, and preparing audit evidence.

· Java & Gradle: Hands-on experience with Java and Gradle, with the ability to turn automated fault findings into pinpointed code and library change requirements.

· Vulnerability Scanning: Experience with vulnerability and code scanning tools such as SonarQube, GitHub Dependabot, or Amazon Inspector.

· Tooling & Automation: Ability to write and maintain security tooling and automation in Node.js or Python.

· Systems Fundamentals: Strong working knowledge of shell scripting, Unix/Linux, and networking.

· AI Tooling Proficiency: Fluent use of modern AI assistants (e.g., Claude Code or similar) to build and maintain tooling and automation.

· Ownership & Judgment: Self-directed and proactive, with the judgment to prioritize risk and drive remediation to completion.

· Communication & Influence: Able to explain security findings, control gaps, and their impact clearly to engineers, leadership, auditors, and external partners — and to drive remediation across teams you don't manage.

Preferred Qualifications

· Experience with GCP Security Command Center.

· Experience with Jenkins, GCP Cloud Build, GitHub Actions, or similar build pipelines.

· Experience in payments, banking, fintech, or another regulated financial environment, including partner and customer security due diligence.

· Experience with compliance automation platforms (e.g., Vanta, Drata, or similar).

· Relevant certifications such as CISSP, CISA, ISO 27001 Lead Auditor or Lead Implementer, or Google Professional Cloud Security Engineer.

· Experience working with global development and operations teams.

Why Join?

  • Growth: Own the platform and the operations function end-to-end, and expand your scope across new products, rails, partners, and markets as we scale.

  • Impact: Shape how payments operations scale at a fast-moving B2B payments company.

  • Innovation: Work at the intersection of payments operations and AI-enabled automation.

  • Culture: Join a collaborative team that values curiosity, inclusion, and sustainable work.

We are looking for curious, driven builders who want to create secure, scalable, user-friendly payments products. If you do not meet every qualification but bring initiative and a growth mindset, we encourage you to apply.

We embrace AI as a powerful tool for innovation and welcome team members eager to leverage it in their work. As an equal opportunity employer, we're committed to diversity, inclusion, and creating an environment where everyone can thrive.

Related jobs

Apply at company