5 days ago
Responsibilities
- Integrate SAST, DAST, and SCA security testing into CI/CD deployment pipelines.
- Secure AWS/GCP cloud infrastructure and Kubernetes environments while conducting code reviews and architectural risk assessments.
- Manage vulnerability detection, dependency scanning, prioritization, tracking, reporting, triage, and remediation.
- Build automated security workflows and scalable security guardrails using Python, Go, Bash, or similar automation.
- Monitor technical security controls for regulatory exams, SOC-2 audits, and PCI audits.
- Participate in security incident investigation and mitigation.
- Collaborate with product, data engineering, front-end engineering, tech operations, compliance, and legal teams.
- Travel periodically for team offsites.
Requirements
- Bachelor's degree in Computer Science or a related field, or equivalent professional experience.
- Deep experience in both Infrastructure Security and Application Security.
- Hands-on experience building security guardrails in GitHub Actions, GitLab CI, Jenkins, or similar CI/CD tools.
- Experience with cloud and Kubernetes security, OWASP Top 10, and Secure SDLC practices.
- Experience with enterprise vulnerability management platforms and automated dependency scanning solutions.
- Proficiency writing automation in Python, Go, or Bash.
- Experience using AI-driven automation or agentic tools to streamline security workflows.
- Understanding of regulated environments and the ability to translate compliance requirements into technical controls.
- Clear communication of technical trade-offs to non-technical stakeholders and a history of cross-functional collaboration.
- CISSP certification and startup or fintech experience are preferred but not required.
Benefits
- Some travel is required for periodic team offsites.
