Primer logo
Primer

Powerful no-code automation for payments and commerce.

Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200H1B SponsorCompany SiteLinkedIn

Location

Poland

Posted

9 days ago

Salary

0

Seniority

Senior

EnglishCloud

Job Description

Security Engineer

Primer

• Running security reviews and threat modelling on features and systems across Primer's product, and turning findings into clear, actionable guidance for the teams shipping them • Independently planning and delivering your own security projects, from initial design through to rollout • Building tooling and automation that makes future reviews faster and cheaper to run • Coordinating penetration testing and tracking remediation through to closure • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

Job Requirements

  • Working experience in product or application security: you've done security reviews or threat modelling and can spot the risks that matter
  • The ability to read and write code, not just review it. You're comfortable building small tools and automation rather than only filing findings
  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly
  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer
  • Clear communication with engineers who aren't security specialists, since most of your impact lands through their work
  • Nice to have: Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them
  • Nice to have: Background in payments, fintech, or another regulated, high-stakes domain
  • Nice to have: Interest in areas like supply chain security, detection engineering, or AI security

Benefits

  • Competitive share options
  • Uncapped holiday, with 25 days minimum to be taken
  • Co-working space access
  • Workations & Company Retreat
  • The best equipment for your role
  • £500 towards your home office setup
  • Generous learning budget
  • Private Medical Insurance
  • A broad set of additional perks and benefits (*depending on location)

Related Categories

Related Job Pages

More Security Engineer Jobs

ZoomInfo logo

Senior Director, Security Governance

ZoomInfo

It’s Our Business to Grow Yours

Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Define and execute a GRC roadmap, leading governance, risk, and compliance programs. • Design and maintain the enterprise risk register, partnering with business leaders to identify, quantify, and mitigate risks. • Manage compliance with frameworks (ISO 42001, ISO 27001, ISO 27701, ISO 27017, and SOC2, and CIS Controls) and drive continuous compliance rather than just annual audits. • Build and manage a right-sized vendor risk program, assessing vendor maturity and reviewing security contracts. • Enable ZoomInfo transaction velocity and ensure customer service by building customer trust and rapidly responding to inquiries. • Leverage Agentic AI and GRC platforms (ServiceNow GRC, Vanta, and others) to automate processes, generate metrics, and deliver executive dashboards. • Act as the key liaison between Security, Legal, Product, and executive leadership to align risk posture with business objectives.

Ireland
Full TimeRemoteTeam 10,001+H1B Sponsor

• Establish the vision, strategy and success metrics for the Customer Support and Integrity Security function. • Lead the technical direction and roadmap execution for Customer Support and Integrity Security. • Work directly with Customer Support and Integrity, Merchant Experience, Enterprise Security, Engineering, Product, GRC and related teams. • Design and Operationalize security controls. • Establish clear, measurable metrics to demonstrate and track the performance of the Customer Support and Integrity security programs. • Perform security testing and validation of support teams, processes and systems to identify security gaps and remediation plans. • Drive alignment across multiple organizations, build durable operating mechanisms.

United States
$193.8K - $285K / year
Full TimeRemoteTeam 11-50Since 2023H1B Sponsor

Role Description You'll be our first dedicated information security hire. Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one. The work is hands-on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO. Tasks - Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find. - Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers. - Automate: detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code. - Run vulnerability management and incident response: write the runbooks, run the drills. - Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working. - Own SOC 2: control design, automated evidence collection, the auditor relationship. - Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US. - Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams. - Run vendor reviews and third-party risk. - Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers. - Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire. Qualifications - 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). - Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets. - SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation. - Exposure to financial-services customer scrutiny, or the appetite to make it your specialty. - A working view on LLM security risks, or strong fundamentals and the curiosity to build one. - Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn't theater. - Clear writing. Remote means async, and async means your policies and risk memos do the talking. - The ambition to grow into an executive role and the people skills to survive it. Requirements - Nice to have: Fintech or another regulated B2B environment with large financial-institution customers. - DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500. - Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs. - You've been the first security hire somewhere before. Benefits - A blank slate with real ownership. - A committed path to CISO. - Fully remote, flexible hours. - Direct access to leadership and to customer security teams at major financial institutions. - Competitive pay, equity, learning budget. How we hire - Intro call (30 min). - Technical deep dive (60–90 min): AWS security scenarios, plus a walk-through of a program you built. - Practical exercise: review a sanitized architecture or a due diligence questionnaire and tell us what you'd fix first. - Leadership conversation: the CISO path, and working with the non-technical half of the company. - References and offer. Company Description Tangible is transforming the way secondary markets work for LPs, GPs and wealth managers. We combine technology and deep private markets expertise to bring transparency, efficiency and simplicity to secondary transactions. Our products enable more LPs to sell on the secondary market and empower GPs and wealth managers to create scalable liquidity solutions for their investors.

CET + + 1 moreAll locations: CET + | 3 HOURS
Cloud Bridge logo

Network Security Engineer

Cloud Bridge

Harness the full potential of AWS with award-winning Premier Partner, Cloud Bridge

ContractRemoteTeam 51-200Since 2018H1B Sponsor

• Conduct detailed network traffic analysis to identify risks and vulnerabilities • Assess current network security posture and recommend improvements • Design and support implementation of network security controls • Provide independent assessment of security capabilities and gaps • Support development of bespoke solutions based on organisational exposure • Work across network architecture to ensure secure design principles • Contribute to improving detection and response capabilities (e.g. deception techniques)

United Kingdom
£600 / day