4 months ago
Remote, EMEASenior
Responsibilities
- Integrate security best practices throughout the software development lifecycle to protect products, infrastructure, and customer data.
- Design and maintain automation for patch management, vulnerability management, compliance evidence collection, and other security workflows.
- Embed security controls and guardrails into the developer platform and define reusable secure development standards and Terraform/Docker modules.
- Harden ECS, EKS, and other containerized workloads through secure isolation, networking, access control, image signing, provenance, admission control, least-privilege IAM, and runtime anomaly detection.
- Deploy and manage cloud security platforms such as Wiz and drive remediation workflows.
- Automate audit-ready evidence collection for PCI DSS, ISO 27001, SOC 2, and DORA.
- Support vulnerability management, including triage, service-level agreements, root-cause analysis, and remediation.
- Lead incident response and post-mortems, conduct threat modeling and architecture reviews, and advise on secure design and cryptography.
- Perform application security reviews, code review, threat modeling, static and dynamic analysis, attack surface analysis, and penetration testing.
- Build security documentation, internal tooling, and feedback loops while serving as a security subject-matter expert across application, cloud, and compliance domains.
Requirements
- At least 5 years of experience in a technical security role, preferably in a cloud-native or fintech/SaaS environment.
- Strong proficiency with AWS services and security, including IAM, KMS, CloudTrail, S3, GuardDuty, and SCPs.
- Solid understanding of DevSecOps and integrating security into CI/CD workflows.
- Proficiency with Terraform and other infrastructure-as-code tooling, including writing secure reusable modules and enforcing guardrails.
- Proficiency in Python, Bash, or TypeScript for scripting and automation-tool development.
- Experience securing containers using Docker, ECS, EKS, or Kubernetes and implementing hardened images.
- Expert understanding of the OWASP Top 10, secure coding, and software supply-chain risks.
- Experience managing and integrating cloud security platforms such as Wiz, Orca, Lacework, or Prisma Cloud.
- Experience with vulnerability management and remediation workflows at scale.
- Experience with application security practices, including code review, threat modeling, SAST, DAST, and attack surface analysis.
- Experience with application penetration testing or vulnerability research/bug bounty hunting, including identifying and fixing SQL injection, XSS, CSRF, SSRF, authentication, and authorization vulnerabilities.
- Understanding of threat modeling or security reviews and the ability to explain security concepts to audiences with different levels of experience.
- Preferred qualifications include exposure to PCI DSS, ISO 27001, and SOC 2; familiarity with detection engineering or lightweight SIEM tooling; and contributions to open-source security tools or internal security automation frameworks.
Benefits
- Remote work flexibility in the EU/UK.
- Choice of preferred operating system: Windows or Mac.
- Attractive remuneration.
- Company card with a monthly allowance for lunches, coffee, and similar expenses with coworkers.
- Opportunity to develop professionally in a growing team with transparent communication and a flat hierarchy.
