Liquidity made simple
Information Security Engineer
Location
CET + + 1 moreAll locations: CET + | 3 HOURS
Posted
9 days ago
Salary
0
Seniority
Mid Level
Job Description
Information Security Engineer
Tangible
Role Description You'll be our first dedicated information security hire. Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one. The work is hands-on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO. Tasks - Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find. - Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers. - Automate: detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code. - Run vulnerability management and incident response: write the runbooks, run the drills. - Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working. - Own SOC 2: control design, automated evidence collection, the auditor relationship. - Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US. - Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams. - Run vendor reviews and third-party risk. - Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers. - Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire. Qualifications - 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). - Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets. - SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation. - Exposure to financial-services customer scrutiny, or the appetite to make it your specialty. - A working view on LLM security risks, or strong fundamentals and the curiosity to build one. - Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn't theater. - Clear writing. Remote means async, and async means your policies and risk memos do the talking. - The ambition to grow into an executive role and the people skills to survive it. Requirements - Nice to have: Fintech or another regulated B2B environment with large financial-institution customers. - DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500. - Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs. - You've been the first security hire somewhere before. Benefits - A blank slate with real ownership. - A committed path to CISO. - Fully remote, flexible hours. - Direct access to leadership and to customer security teams at major financial institutions. - Competitive pay, equity, learning budget. How we hire - Intro call (30 min). - Technical deep dive (60–90 min): AWS security scenarios, plus a walk-through of a program you built. - Practical exercise: review a sanitized architecture or a due diligence questionnaire and tell us what you'd fix first. - Leadership conversation: the CISO path, and working with the non-technical half of the company. - References and offer. Company Description Tangible is transforming the way secondary markets work for LPs, GPs and wealth managers. We combine technology and deep private markets expertise to bring transparency, efficiency and simplicity to secondary transactions. Our products enable more LPs to sell on the secondary market and empower GPs and wealth managers to create scalable liquidity solutions for their investors.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Network Security Engineer
Cloud BridgeHarness the full potential of AWS with award-winning Premier Partner, Cloud Bridge
• Conduct detailed network traffic analysis to identify risks and vulnerabilities • Assess current network security posture and recommend improvements • Design and support implementation of network security controls • Provide independent assessment of security capabilities and gaps • Support development of bespoke solutions based on organisational exposure • Work across network architecture to ensure secure design principles • Contribute to improving detection and response capabilities (e.g. deception techniques)
Senior Identity Security Architect – IGA
SaviyntThe #1 Converged Identity Platform with Intelligent Access Governance for Employees, Third Parties & Machines.
• Serve as the technical authority for the Saviynt IGA platform. • Provide deep product expertise and architectural leadership across design, implementation, and operational phases. • Partner closely with the System Owner, security leadership, cloud teams, and implementation partners. • Ensure scalable, secure, and high-quality delivery of identity services. • Act as the primary technical decision-maker for Saviynt configurations, integrations, and troubleshooting. • Provide leadership to implementation and configuration teams.
M365 Security Consultant
Cloud BridgeHarness the full potential of AWS with award-winning Premier Partner, Cloud Bridge
• Lead deployment and optimisation of Microsoft Defender for Endpoint • Support security architecture across M365 E5 security stack • Align endpoint security strategy across laptops, servers, and VDI environments • Has in-depth knowledge/ skill of deploying designing M365 e5 security stack • Provide guidance on licensing utilisation and maximisation of E5 capabilities • Support integration across multiple security domains and tools • Work with engineering teams to implement and improve security controls
Staff Software Engineer, Cloud Security
Included HealthAccess. Answers. Advocacy. We're raising the standard of healthcare for everyone.
• Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams. • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions. • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response. • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools. • Implement and champion Infrastructure as Code (IaC) principles, **specifically using Terraform,** for programmatic definition, enforcement, and auditing of security configurations. • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering. • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks. • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools. • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams. • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls. • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data. • Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines. • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices. • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows. • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response. • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.



