Operations Security Engineer – Remote-First at Epi Company | BE, DE | Rezi

Operations Security Engineer – Remote-First at Epi Company

Operations Security Engineer – Remote-First

Epi Company · BE, DE

Today

Operations Security Engineer – Remote-First

Epi Company · BE, DE

an hour ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Operations Security Engineer – Remote-First role.

Rezi rewrites your resume against Epi Company's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Operations Security Engineer – Remote-First posting at Epi Company — free, in seconds.

About the Role

Play a key role in protecting Europe’s next-generation payment infrastructure. As an Operations Security Engineer, you will be at the heart of EPI’s Security Operations capability: triaging alerts, responding to incidents, improving detection coverage and proactively hunting for threats across cloud, identity, endpoint and application environments. This is a high-impact opportunity to combine hands-on SOC expertise, threat hunting and detection engineering in a remote-first, pan-European company where security directly supports the resilience and trust of Wero.

Responsibilities

  • Act as a central point of contact for alert triage, incident identification and security event investigation across EPI environments.
  • Execute incident response activities using structured frameworks such as SANS PICERL, from preparation and identification through containment, eradication, recovery and lessons learned.
  • Conduct proactive, hypothesis-driven threat hunts based on attacker behaviour, emerging threats, threat intelligence and MITRE ATT&CK techniques.
  • Parse, analyse and correlate logs from authentication, application, system, endpoint and cloud telemetry sources, including AWS and Azure.
  • Design, tune and maintain detection rules, use cases, dashboards, custom alerts and automation workflows to identify anomalies, lateral movement and persistent threats.
  • Contribute to the development and continuous improvement of SOC playbooks, runbooks, SIEM and EDR integrations.
  • Document and communicate threat findings, incident outcomes and remediation recommendations clearly to technical and non-technical stakeholders.
  • Collaborate with engineering, SOC, IR and IT teams to improve detection coverage, response readiness and operational resilience.

Requirements

  • +5 years of experience in cybersecurity, with strong hands-on experience as a SOC analyst, incident responder, detection engineer or similar role.
  • Fluent in English (CEFR C1 or C2); French, German, Dutch or other European languages are a plus.
  • Thrive in a remote-first, multicultural and fast-paced environment.
  • Strong familiarity with the full SOC lifecycle, from Tier 1 to Tier 3, including alert triage, incident response, threat hunting and threat intelligence.
  • Proven experience in threat hunting, detection engineering or threat intelligence, with the ability to turn attacker behaviours into actionable detections.
  • Solid understanding of SIEM and EDR technologies, log parsing, detection engineering and alert tuning.
  • Hands-on experience with scripting and querying tools such as Python, PowerShell or KQL to support automation, investigations and custom alerting.
  • Ability to analyse and correlate logs from diverse sources, including authentication, application, system and cloud telemetry across AWS and Azure.
  • Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure and attack path analysis.
  • Experience creating or improving incident response playbooks, runbooks and automation workflows.
  • Strong communication skills, with the ability to explain technical findings and security risks clearly to both technical and non-technical stakeholders.
  • Willingness to participate in a 24/7 on-call rotation, approximately one week per month, to support incident response and operational continuity.
  • Experience with Rapid7 and with TaHiTI.
  • Familiarity with Microsoft Entra ID and its integration into detection and response workflows.
  • Nice-to-have certifications such as GSEC, GCIH, BTL1/2, SC-200 or AZ-500.
  • Experience in payments, banking, fintech or another highly regulated environment.

Skills

  • Rapid7
  • Microsoft Defender
  • SIEM
  • EDR technologies
  • AWS
  • Azure
  • Microsoft Entra ID
  • Okta
  • PagerDuty
  • Python
  • PowerShell
  • KQL
  • Jira
  • Confluence
  • GitHub
  • SOC analyst
  • Incident responder
  • Detection engineer
  • Threat hunting
  • Threat intelligence
  • Log parsing
  • Alert tuning
  • MITRE ATT&CK
  • SANS PICERL

Location

  • Remote-first

Work Type

  • Remote-first
  • Full-time

Experience Level

  • +5 years of experience in cybersecurity

Benefits

  • Competitive compensation package, featuring salary, performance-based bonus and a thoughtfully designed, high-quality benefits programme
  • Remote-first culture with quarterly and annual all-staff in-person meetups
  • Possibility to work from another EU country for up to 3 months per year
  • Learning & development budget: €5,000 training budget per year

About the Company

  • In today’s digital Europe, payments still feel too complicated. Random delays, confusing rules, extra apps and accounts make it harder than it should be to pay and get paid.
  • The European Payments Initiative is changing that with Wero, a proudly European digital wallet to make payments easier, clearer and more secure. Online, in store, at home and across borders, with your money and data protected under European laws and regulations.
  • Wero is live in Belgium, France, Germany and the Netherlands and launching very soon in Luxembourg and Austria. Backed by 17 major banks and the two largest European acquirers, we’re building a brand new, proudly European payment system.

Equal Opportunity

  • EPI offers the same job opportunities to all, without distinction of gender, ethnicity, religion, sexual orientation, social status, disability or age. EPI promotes the development of an inclusive work environment that mirrors the diversity of the clients our product is serving.