LI.FI logo
LI.FI

The multi-chain liquidity gateway. A DeFi middleware to build crypto-enabled businesses.

Lead Security Architect

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

Germany

Posted

56 days ago

Salary

€120K - €150K / year

Seniority

Senior

Bachelor DegreeEnglishCloudSDLCWeb3

Job Description

Lead Security Architect

LI.FI

• Own and strengthen company-wide security and compliance • Lead security efforts across infrastructure, applications, internal systems, and employee devices • Identify risks and vulnerabilities across the organisation and ensure they are addressed • Establish scalable security processes and best practices across teams • Own the organisation's compliance posture - define target frameworks, drive progress against them, and ensure requirements are reflected in day-to-day operations • Coordinate audits and external security work • Own relationships with external security firms and auditors • Lead the organisation through compliance framework certifications end-to-end • Plan and run security reviews and external audits, ensuring findings are tracked and resolved • Act as the internal authority on external security requirements and regulatory expectations • Build security awareness across the company • Define and own the company's security awareness and training programme • Drive application security • Own the Secure Software Development Lifecycle (Secure SDLC) across the engineering organisation • Work closely with engineering teams to ensure secure design and implementation of products — getting into the detail where needed • Personally review tools, frameworks, and architectures for security risks and ensure findings drive action • Own Web3 security • Bring a solid understanding of Web3-specific security risks — smart contract vulnerabilities, protocol exploits, wallet and key management, and on-chain threat vectors • Own AI Security • Identify and mitigate security risks related to AI-driven tooling, agents, and automation • Implement security tooling and automation • Own the security tooling strategy — defining requirements, evaluating solutions, and driving implementation • Establish monitoring standards, incident response processes, and security workflows • Ensure security is consistently embedded in engineering pipelines and tooling

Job Requirements

  • Proven experience owning or leading a security function — not just executing within one
  • Background in security engineering or architecture — you understand how systems are built and where they break
  • Experience building or maturing security programmes in fast-moving engineering organisations
  • Experience in a Web3 or payments fintech environment
  • Solid knowledge of key compliance frameworks including SOC 2, ISO 27001, DORA, MiCA, the EU AI Act, NIS2, and related standards
  • Experience guiding organisations through certification and audit processes end-to-end — not just familiarity with the frameworks, but having done the work
  • Strong understanding of modern application security practices
  • Experience with security reviews, threat modelling, and vulnerability management
  • Familiarity with cloud infrastructure security and developer tooling
  • Understanding of AI security risks and emerging attack vectors is a strong plus
  • Experience managing or mentoring security teams is a plus
  • Strategic thinker who can translate risk into priorities and communicate them clearly to leadership
  • Comfortable operating with autonomy in a fast-moving, ambiguous environment
  • Able to influence without authority across engineering and leadership
  • Proactive by default - you identify problems before they're escalated to you

Benefits

  • 30 days of PTO
  • Flexible remote days
  • Flexible working hours
  • Equity participation from day 1
  • Entitlement to work computer (choice of equipment)
  • An annual 1,000€ personal development budget once you have worked 6+ months (pro-rated the first year)
  • A one-time 1,000€ remote budget to use on coworking, office setup, etc.

Related Categories

Related Job Pages

More Security Engineer Jobs

FRICE Consulting logo

Consultor Especializado en Cumplimiento PCI DSS y Ciberseguridad

FRICE Consulting

En FRICE Consulting valoramos la diversidad e inclusión, fomentando un entorno donde el talento trasciende cualquier diferencia. ¡Únete a nuestra Comunidad FRICE! No dudes en postular por el portal.

Full TimeRemoteTeam 11-50

Este es un puesto de trabajo remoto. · Desde FRICE Consulting, empresa líder en Consultoría TI y captación de Talento Digital, desde el año 2016 tenemos operaciones en distintos países de Latinoamérica. En este momento, para un importante cliente que tiene operaciones en diversos países, nos encontramos en la búsqueda de un talento para el perfil: Consultor Especializado en Cumplimiento PCI DSS y Ciberseguridad - País: Residentes en Brasil / Colombia / Chile / Argentina - Modalidad: Remoto (con presencialidad ocasional) - Tiempo de asignación: A convenir - Jornada Laboral: Full Time, Lunes a viernes Objetivo del puesto: - Realizar una evaluación integral del flujo de pagos de la compañía, abarcando tanto los puntos de venta (POS) como el canal web. - Identificar riesgos, brechas de cumplimiento y procesos operativos asociados a los componentes tecnológicos del flujo de pagos. - Verificar el cumplimiento de los lineamientos de ciberseguridad y las normativas internacionales aplicables, con especial énfasis en PCI DSS (versión 4.0 preferente). - Elaborar informes técnicos y ejecutivos que presenten hallazgos, evidencias y recomendaciones concretas y aplicables, priorizando un enfoque práctico y no teórico. Requisitos: - Formación en Ingeniería en Informática, Sistemas, Ciberseguridad o carrera afín. - 3 a 5 años de experiencia comprobable en proyectos de cumplimiento PCI DSS (idealmente versión 4.0). - Experiencia práctica en evaluaciones de cumplimiento, levantamiento de procesos y revisión de controles técnicos. - Conocimiento técnico sólido del ecosistema de pagos retail: POS, pinpads, gateways, adquirentes, tokens, cifrado y arquitectura de red. - Capacidad para comunicar riesgos técnicos a audiencias no técnicas y coordinar equipos multidisciplinarios. Principales funciones: - Elevar y documentar el flujo completo de pagos en entornos POS y web, incluyendo actores, procesos, aplicaciones y componentes tecnológicos. - Evaluar el grado de cumplimiento con PCI DSS (v4.0 preferente) y otros estándares internacionales relevantes. - Identificar riesgos de seguridad y brechas de cumplimiento operativas y tecnológicas. - Revisar la configuración y segmentación de red, controles de acceso, cifrado y almacenamiento seguro de datos de tarjeta. - Analizar procesos operativos y controles de ciberseguridad aplicados a la infraestructura de pagos. - Preparar y presentar informes técnicos y ejecutivos, con hallazgos claros, evidencias y recomendaciones prácticas. - Asesorar a los equipos internos en la definición de planes de remediación. - Verificar el cumplimiento de lineamientos de seguridad en proveedores y terceros. - Promover buenas prácticas de ciberseguridad y cumplimiento normativo dentro del equipo de trabajo. Conocimientos requeridos: - Seguridad en entornos Cloud (AWS, Azure o GCP). - Desarrollo seguro (DevSecOps): revisión de código, pruebas de seguridad. - Segregación de funciones y control de accesos (RBAC, IAM). - Seguridad en integraciones (API Security, autenticación y cifrado). - Uso de herramientas de seguridad (SIEM, escáneres de vulnerabilidades, etc.). Conocimientos deseables: - Experiencia en normativas y marcos complementarios: ISO 27001, NIST, CIS, OWASP. - Certificaciones o formación adicional en seguridad de la información o cumplimiento normativo. En FRICE Consulting valoramos la diversidad e inclusión, fomentando un entorno donde el talento trasciende cualquier diferencia. ¡Únete a nuestra Comunidad FRICE! No dudes en postular por el portal.

Argentina
Job Closed
Blue Pearl logo

Mainframe Security Specialist

Blue Pearl

We craft CLOUD solutions that fit your business requirements and budget.

ContractRemoteTeam 11-50Since 2013H1B No Sponsor

• Lead remediation of MQ security vulnerabilities within a mainframe environment • Design and implement secure access control frameworks using Broadcom Top Secret • Define and document security patterns and controls across: Batch processing environments, CICS transactions, User access and permissions, Third-party integrations • Collaborate with mainframe and MQ engineers/SMEs to ensure best-practice security implementation • Provide expert input on mainframe security architecture and governance • Ensure all remediation activities are completed within audit timelines (before September deadline) • Produce clear documentation of security configurations, standards, and patterns

South Africa
Solera, Inc. logo

Cyber Security Engineer

Solera, Inc.

The global leader in vehicle lifecycle management.

Full TimeRemoteTeam 5,001-10,000Since 2005H1B No Sponsor

• SOC Analyst, serve as first line of defense in protecting information systems from internal and external threats • Conduct analysis of security events to include validation, escalation and reporting of events of interest • Responsible for all events of interest and ensure they are continuously monitored and reviewed • Monitoring and analysis of cyber security events • Recognize potential, successful, and unsuccessful intrusion attempts • Working with the Incident Response team to help create RCAs for events escalated to incident levels • Development and execution of Standard Operating Procedures, Event Handlers and Job Aids required for successful task completion • Actively participate in incident resolution, even after they have escalated • Keep the ticket queue assigned.

Mexico
Job Closed
Full TimeRemoteTeam 10,001+Since 2020H1B No Sponsor

• Provide day-to-day legal support to the Raytheon organization on all aspects of Cybersecurity law and data protection • Lead and manage data incident response investigations and reporting under legal privilege, ensuring compliance with applicable regulatory requirements • Collaborate with cybersecurity subject matter expert (SME) on NIST 800-171, and Cybersecurity Maturity Model Certification 2.0 (CMMC) • Review redlines including purchase orders and subcontract terms and conditions to ensure compliance with company policies, procedures, internal guidance, and legal requirements, including the FAR and DFARS • Assist with the development, implementation, and maintenance of policies, standard work, playbooks, guidance, templates, and other documentation related to cybersecurity compliance including interpretation of Controlled Unclassified Information (CUI) determination • Develop and deliver training on cybersecurity law related to defense industry for legal professionals within the organization, as well as assist with the development and delivery of general awareness training for employees, contractors, and third parties • Travel up to 10% of the time

Massachusetts
$157.2K - $298.8K / year
Job Closed