Tangible logo
Tangible

Liquidity made simple

Information Security Engineer – CISO Track

Security EngineerSecurity EngineerContractRemoteSeniorTeam 11-50Since 2023H1B SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

12 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSPythonTerraform

Job Description

Information Security Engineer – CISO Track

Tangible

• Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find. • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers. • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code. • Run vulnerability management and incident response. • Write the runbooks, run the drills. • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. • Assess risks like prompt injection and data leakage, design controls that let people keep working. • Own SOC 2: control design, automated evidence collection, the auditor relationship. • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US. • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams. • Run vendor reviews and third-party risk. • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers. • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

Job Requirements

  • 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption).
  • Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents.
  • You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit.
  • Working knowledge of privacy legislation.
  • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter.
  • Clear writing.
  • The ambition to grow into an executive role and the people skills to survive it.
  • Nice to have Fintech or another regulated B2B environment with large financial-institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You've been the first security hire somewhere before.

Benefits

  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.

Related Categories

Related Job Pages

More Security Engineer Jobs

Cloudflare logo

Senior Security Compliance Specialist

Cloudflare

Cloudflare, Inc. protects online applications without installing software, adding hardware, or changing lines of code. The company’s internet properties help

Full TimeRemoteTeam 4,400Since 2010

Role Description As a Senior Security Compliance Specialist at Cloudflare, you will: - Lead Cloudflare through the CCCS CSP ITS Assessment process - Update and maintain CCCS requirements within Cloudflare’s Common Control Framework - Work cross-functionally with Engineering, Legal, Product, and operational teams to drive security control implementation for the organization - Improve the maturity of Cloudflare’s Security Compliance program - Help guide our overall security policy and governance architecture - Have input into the overall security compliance strategy Qualifications - 5+ years of experience working in Security Compliance - Led the pursuit of, or maintained a CCCS Medium / PBMM certification - Deep understanding of the CCCS CSP ITS assessment processes - Deep understanding of CCCS requirements - Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, HITRUST, FedRAMP - Ability to work cross-functionally with internal stakeholders and strong communications skills - Ability to work closely with auditors and articulate technical concepts - Ability to work efficiently and independently in a fast-paced, high-volume environment - Willingness to travel occasionally to engage with regulators and auditors Benefits - Opportunity to join a world-class security organization within a billion-dollar business - Engagement in meaningful projects that protect the free and open Internet Company Description At Cloudflare, we are on a mission to help build a better Internet. We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. - Project Galileo: Equipping journalism and civil society organizations with tools to defend against attacks since 2014. - Athenian Project: Providing state and local governments with protection and reliability for election information since 2017. - 1.1.1.1: A public DNS resolver focused on speed, security, and privacy.

Canada
Action1 logo

Product Security Engineer

Action1

Patch Management That Just Works | Real-time discovery and remediation of third-party and OS vulnerabilities

Full TimeRemoteTeam 51-200Since 2018H1B No Sponsor

• Support Product Security Incident Response Team (PSIRT) and vulnerability-handling activities • Validate, triage, track, and coordinate security reports • Provide practical remediation guidance to engineering teams • Help validate security fixes and reduce product security risks • Review code, APIs, and system architecture to identify security issues early • Conduct threat modeling and security design reviews • Improve security automation within engineering workflows • Support SAST, SCA, secrets scanning, and other security controls • Maintain software bills of materials (SBOMs), dependency visibility, and remediation follow-up • Support security assessments, vulnerability assessments, and penetration testing • Maintain vulnerability-handling playbooks, product security procedures, and incident response runbooks

Serbia
BlackStone eIT logo

Cybersecurity Specialist – IAM, Vulnerability Management

BlackStone eIT

A global team who's passionate about transformative enterprise solutions & intelligent design

Full TimeRemoteTeam 201-500H1B No Sponsor

• Provide secured remote operational support across identity and access management and vulnerability management. The role performs approved technical activities and tracking; access approvals, security policy, risk acceptance and regulatory accountability. • Support user, privileged and service-account administration through approved requests and access workflows. • Assist with periodic access reviews, joiner/mover/leaver controls and evidence preparation. • Operate approved vulnerability scanning and reporting tools and validate findings with system owners. • Maintain vulnerability, exception and remediation trackers and coordinate technical follow-up. • Support IAM, MFA, privileged-access and directory-service incidents within authorised access boundaries. • Provide metrics, evidence and trend analysis for security reporting and governance reviews. • Escalate overdue, critical or policy-related matters to the onsite Security Engineer. • Maintain operational procedures, access-control records and vulnerability-management documentation.

India
PartnerOne logo

Security Lead

PartnerOne

We are the leaders in Big Data management through hyper-automation, virtualized cloud tiering, metadata and AI

Full TimeRemoteTeam 201-500H1B No Sponsor

**Position Overview**Mortgage Cadence is seeking an experienced Security Lead to own and mature core security programs while working collaboratively with engineering, compliance, and product teams. This role offers hands-on technical leadership with a focus on execution and program maturity. The Security Lead will translate risk management priorities into actionable plans, guide a small team of security professionals, and serve as a trusted advisor on security posture and incident response. You will balance strategic program development with operational delivery, ensuring security is embedded into the organization's development and operational processes. Why This Role ExistsAs Mortgage Cadence scales its product and client base, security program maturity has become a competitive necessity and a material business requirement. This role was created to provide experienced security leadership that can own and execute across multiple security disciplines, develop junior staff, and represent security effectively with engineering leadership, audit partners, and key clients. Core ResponsibilitiesTeam Leadership & Development - Coach junior staff on security fundamentals, investigations, and technical execution; actively invest in team capability growth. - Collaborate with HR and leadership on hiring plans to grow team capacity as the business scales. Vulnerability Management & Security Posture - Own Mortgage Cadence's vulnerability management program, including setting remediation standards, SLAs, and accountability structures. - Build and maintain executive-level security posture dashboards that surface risk status, remediation trends, and key metrics to leadership. - Oversee triage, assignment, and resolution of security findings, ensuring risks are tracked and formally accepted with appropriate business context. - Drive measurable improvements to security posture over time through governance and cross-team accountability. Security Incident Response - Establish and continuously mature Mortgage Cadence's incident response capability, including detection, triage, escalation, containment, and post-incident review. - Lead incident response during security events, providing clear communication to internal stakeholders and, when necessary, to affected clients. - Conduct or oversee tabletop exercises and simulations to test readiness and identify gaps in incident response processes. Application Security & Security Testing - Oversee vulnerability scanning, code review practices, and penetration testing activities; integrate security requirements into the development lifecycle. - Collaborate with engineering leads to establish secure development standards and hold teams accountable for timely remediation of identified vulnerabilities. - Manage relationships with internal and external security testing partners, prioritizing assessments based on risk and business needs. Compliance, Audit & Client Security - Lead Mortgage Cadence's audit and compliance programs (SOC 1/SOC 2, PCI, and other applicable frameworks), working closely with external auditors and internal stakeholders. - Serve as the primary security authority for client-facing security reviews, questionnaires, and due diligence engagements. - Work with sales and client success to support RFP processes and security-related contract discussions. - Ensure audit readiness is a continuous organizational state through evidence collection, control testing, and documentation. Security Strategy & Governance - Own Mortgage Cadence's information security policy framework, ensuring policies remain current, enforceable, and business-aligned. - Represent information security on governance bodies (e.g., Change Advisory Board), providing risk-based input on significant organizational and technology changes. - Develop and communicate security best practices and risk guidance to the business; translate threat intelligence into actionable priorities. - Report on security program health, risk metrics, and strategic recommendations to senior leadership on a regular cadence.

Colombia