Lumin Digital is a FinTech company whose innovative digital solutions help financial institutions engage their customers and grow. The company has hired in the
Cyber Security Engineer
Location
United States
Posted
3 days ago
Salary
$140K - $160K / year
Seniority
Senior
Job Description
Cyber Security Engineer
Lumin Digital
• Engineer the security infrastructure the rest of the company depends on across AWS and Kubernetes: telemetry pipelines, cryptographic material lifecycle, compliance automation, and the architecture patterns that scale across hundreds of environments. • Build and maintain agentic AI workflows using tools like Claude Code, MCP-based integrations, and custom agent harnesses to automate security engineering tasks. Examples include code review for vulnerability patterns, drift detection in security controls, and automated evidence collection. • Engineer the lifecycle of cryptographic material as code, including key generation, secure storage, certificate issuance, rotation, and revocation. All steps version-controlled, automated, and recoverable without a human in the loop. • Build security telemetry pipelines that detect, enrich, and route signals with the fidelity our auto-remediation systems require. • Embed security controls into deployment pipelines so vulnerabilities are prevented or resolved at build time rather than discovered post-deployment, including policy-as-code rules and automated playbooks. • Build compliance evidence collection and continuous control monitoring as engineered systems that produce auditor-ready outputs from continuous data flows. • Develop and maintain threat models that inform security architecture decisions and prioritize where engineered controls earn their place. Promote learnings into reusable patterns the rest of engineering can adopt. • Consult, review, and approve architectural decisions by other infrastructure and product teams for security compliance and outcomes, with attention to where secrets are stored and how trust boundaries are crossed. • Provide engineering support to Security Operations during incident response: build the tooling, telemetry, and automation that aids detection, containment, and recovery, in coordination with the Sec Ops team that owns the response process. • Partner with other Risk functions, technical teams, auditors, vendors, and clients to translate security requirements into engineered systems and validate posture across all environments. • Evaluate emerging AI-assisted engineering patterns and tooling through proof-of-concept work, including agent harness designs, prompt patterns, and eval methodologies. Promote what proves itself into team standard practice. • Operate our COTS security tooling when needed, usually through IaC and automation we've built ourselves, occasionally by clicking through a vendor console. • Perform other duties as assigned.
Job Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related field, or equivalent combination of demonstrated engineering experience, shipped projects, and certifications in security engineering, cryptography, or cloud-native automation.
- 5+ years of hands-on experience in security engineering, software engineering, or a closely related technical discipline, with a strong emphasis on building engineered systems rather than operating manual processes.
- At least 1 year of production experience with at least 2 agentic coding tools, such as Claude Code, Gemini, Cursor, Codex, AMP, or OpenCode.
- Demonstrated experience building and shipping production code in Python or a similarly capable language, with infrastructure-as-code tools such as Terraform.
- Proven track record of working in cloud-native environments, with deep familiarity in AWS, Kubernetes, containerized workloads, and CI/CD pipeline integration.
- Experience with security telemetry platforms (OpenSearch or similar), PKI / certificate lifecycle management, or compliance automation preferred.
- Fluency with AI-assisted development tools like Claude Code and similar agentic coding assistants, including the ability to design, prompt-engineer, and orchestrate agents for security engineering workflows. Production experience where AI was load-bearing in the build.
- Hands-on experience shipping at the agentic tool layer: MCP integrations, custom agent harnesses, or AI tool-use pipelines.
- Strong software engineering fundamentals: version control, code review, testing, CI/CD, and API design, with the ability to write production-quality, maintainable code rather than throwaway scripts.
- Hands-on proficiency with cloud-native engineering: AWS (KMS, IAM, Lambda, EKS, and supporting services), Kubernetes, and Terraform or equivalent IaC tools.
- Technical knowledge of cybersecurity concepts, threat modeling, and secure design principles sufficient to consult on, review, and approve security-critical architectural decisions.
- Working knowledge of PKI concepts and certificate lifecycle management, with the ability to engineer cryptographic lifecycles as code.
- Experience with security telemetry pipelines and log analytics platforms (OpenSearch or similar), including data normalization, enrichment, and the structural fidelity required for downstream automation.
- Working knowledge of cloud security and compliance frameworks (SOC 2, PCI DSS, CIS Benchmarks, AWS Well-Architected), with the ability to translate control requirements into automated, auditable systems.
- Self-directed engineering mindset with a bias toward action, a low tolerance for manual toil, and a drive to eliminate recurring work through automation. A repeated manual process is a bug, not a task.
- Excellent written and verbal communication, including the ability to translate complex security architectures into clear documentation and to operate as a consultative security partner across technical and non-technical teams. Comfort with a fully remote, async-first culture where Slack and thorough documentation are how decisions get made.
- Nice to have: Contributions at the edge of what's possible with security and AI, including open-source projects, agent evaluation work, public writing, talks, or similar.
Benefits
- medical, dental, and vision insurance
- a 401(k) with company match
- flexible PTO plus 12 paid holidays
- paid sick leave
- paid parental and family leave
- lifestyle spending account
- tuition reimbursement
- cell phone stipend
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Infrastructure & Security Engineer
NUVIEWCreating the gold standard of elevation data using the world’s first commercial constellation of LiDAR imaging satellites #WeAreNuview
Role Description The Senior Network/Cloud/Systems Engineer is a hands-on technical leader responsible for delivering secure, compliant, and reliable IT services to NuView clients. This role operates at the Tier 3 / escalation level, supporting complex environments, mentoring engineers, and ensuring consistent execution of NuView’s technical standards. This position is delivery-focused, not managerial. The Senior Network/Cloud/Systems Engineer plays a critical role in solution execution, technical quality, client trust, and platform consistency, especially in regulated and security-sensitive environments. Key Responsibilities - Technical Delivery & Escalation Support - Serve as a Tier 3 escalation point for network, cloud, and systems issues across NuView’s client base. - Engineer and support network environments, including FortiGate firewalls, routing and switching, site-to-site and client VPN, SD-WAN, and wireless. - Engineer and support cloud and identity environments, including Microsoft 365, Azure, Entra ID, Intune, and conditional access. - Engineer and support core systems, including Windows Server, Active Directory, virtualization, and backup and recovery. - Lead remediation and recovery efforts during incidents, outages, and security events. - Own complex technical issues through resolution, ensuring root cause is identified, documented, and remediated whenever possible to prevent recurrence. - Security & Compliance Execution - Implement and maintain controls aligned with frameworks such as HIPAA, NIST 800-171, CMMC, PCI-DSS, and SOC 2 (as applicable to client environments). - Support vulnerability remediation, hardening, MFA deployment, backup validation, and incident response activities. - Work with security leadership and vCISO resources to execute compliance-driven technical requirements. - Solution Implementation & Projects - Deliver client projects including migrations, security enhancements, cloud deployments, and infrastructure upgrades. - Execute projects according to NuView standards, timelines, and documentation requirements. - Participate in pre-project technical discovery and post-project validation. - Identify technical debt, security gaps, lifecycle risks, and infrastructure improvement opportunities that can improve client outcomes while supporting recurring revenue and project growth. - HaloPSA & Operational Discipline - Maintain exemplary ticket hygiene and documentation within HaloPSA. - Accurately log time, work performed, configuration changes, and outcomes for all tickets and projects. - Adhere to “no ticket, no work” standards and support continuous process improvement. - Platform Standardization & Knowledge Sharing - Contribute to standardized configurations, runbooks, SOPs, and internal documentation. - Champion NuView platform standards by reducing unnecessary client-to-client variation and promoting approved technologies, configurations, security controls, and operational practices. - Identify recurring issues or inefficiencies and propose improvements to tooling or process. - Act as a technical mentor to Tier 1 and Tier 2 engineers by coaching troubleshooting methodology, documentation quality, client communication, and sound technical decision-making. - Client Trust & Professionalism - Act as a trusted technical advisor to clients during escalations, projects, and security-related discussions. - Communicate clearly and professionally and stay calm in high-pressure situations. - Represent NuView’s security-first mindset and commitment to excellence in every engagement. - Analytical Ability & Business Judgment - Carry a deep, intrinsic focus on client outcomes. NuView is client first, and the result the client needs matters more than anything else. - Quickly assess complex, ambiguous problems and drive to root cause rather than treating symptoms. - Find practical solutions under real constraints, weighing the right fix against time, budget, and client impact. - Translate technical decisions into business terms: cost, risk, and downtime. - Recognize when a recurring issue signals a process or design problem instead of a one-off. - Understand the relationship between technical decisions and business outcomes, balancing risk, security, client experience, operational efficiency, and profitability. Success in the Role - Serve as a trusted Tier 3 escalation resource across the NuView platform. - Drive root-cause analysis and reduce repeat incidents through permanent remediation. - Improve documentation quality, technical consistency, and operational discipline. - Contribute to platform standardization initiatives and security-first best practices. - Mentor and elevate the technical capabilities of other engineers. - Identify opportunities to reduce technical debt and improve client outcomes. - Consistently deliver projects and escalations that strengthen client trust and satisfaction in every engagement. Qualifications - 5+ years in IT infrastructure, systems engineering, or MSP/MSSP environments. - Proven experience supporting security-conscious or regulated clients. - Network: FortiGate, routing and switching, VPN, SD-WAN, wireless, with Cloudflare Zero Trust a plus. - Cloud and identity: Microsoft 365, Azure, Entra ID, Intune, conditional access. - Systems: Windows Server, Active Directory, virtualization, endpoint management, backup and recovery. - Security tooling exposure across an MSSP stack such as CrowdStrike, ThreatLocker, and Cisco Duo. - Experience in a PSA-driven service organization; HaloPSA strongly preferred. - Ability to balance speed, security, and quality in client-facing work. - Demonstrated ability to independently manage complex technical workstreams with minimal supervision while maintaining strong communication and accountability. Education and/or Certifications - Bachelor’s degree in information technology or related field (or equivalent experience). - Relevant certifications such as: - Microsoft Azure and M365 (for example AZ-104, AZ-305, MS-102). - Networking (for example Fortinet NSE, CCNA). - Security+ or equivalent foundational security certification. - Vendor certifications relevant to NuView’s stack. Benefits - Excellent Benefits (including medical, dental, vision, life insurance, HSA/FSA). - 401(k) plan with matching company contribution. - Vacation/ Paid Time Off / Company Holidays/Sick Leave / Floating Holiday. - Professional Development Programs. - Employee Referral Programs. - Corporate-Branded Swag & MORE.
Cybersecurity Engineer – EDR, CNAPP Specialist
Interval GroupHigh quality consulting. On demand. Delivered by top professionals.
• Provide expert technical support to system administration teams to deploy and maintain EDR and CNAPP agents across on-premises and public cloud environments. • Manage security coverage across diverse client and server endpoints, including physical hosts, VMs, VDIs, and containers. • Support multiple operating systems, specifically ensuring seamless protection across Windows, Linux, and MacOS. • Test, maintain, optimize, and document custom security policies and procedures for EDR and CNAPP tools. • Define and enforce tailored security policies for containers, hosts, and orchestrators like Kubernetes. • Liaise closely with internal infrastructure teams and external vendors to ensure maximum uptime and operational maintenance of security tools. • Integrate endpoint and cloud-native security tools with wider security platforms to enhance overall enterprise resilience and operations. • Monitor tool performance, optimising configurations to ensure minimal impact on system resources without compromising cybersecurity coverage.
• Working independently and collaboratively with a team to both lead and support • Perform penetration testing on applications with complex technology stacks from both a blackbox and whitebox perspective. • Dynamically flex your skills when assessing emerging or custom technologies. • Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors. • Manage priorities and tasks to achieve utilization targets. • Operate with professionalism both internally and with clients. • Ensure quality reports and services are delivered efficiently and on time. • Maintains strong depth of knowledge in the practice area. • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
Senior Consultant, Mobile Application Security
CoalfireCyber solutions that move you forward, faster.
• Working independently and collaboratively with a team to both lead and support • Perform penetration testing on applications with complex technology stacks from both a: • Blackbox perspective • Whitebox perspective • Dynamically flex your skills when assessing emerging or custom technologies. • Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors. • Manage priorities and tasks to achieve utilization targets. • Operate with professionalism both internally and with clients. • Ensure quality reports and services are delivered efficiently and on time. • Maintains strong depth of knowledge in the practice area. • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.


