Senior Security Engineer (Cloud)

Btseofficial — Taiwan · Posted ~2 weeks ago

Senior

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a specialized provider delivering front‑office and back‑office support to global fintech firms, focusing on cloud security engineering. The role involves designing secure architectures, implementing advanced protection mechanisms, and ensuring high‑availability services in a fast‑moving digital finance environment.

Highlights

Opportunity to work on cutting‑edge cloud security solutions for a leading global fintech and blockchain company, contributing to innovative trading technologies and robust security infrastructure.

Description

About BTSE 彼特思方舟 is a specialized service provider dedicated to delivering a full spectrum of front-office and back-office support solutions, each of which are tailored to the unique needs of global financial technology firms. 彼特思方舟 is engaged by BTSE Group to offer several key positions, enabling the delivery of cutting-edge technology and tailored solutions that meet the evolving demands of the fintech industry in a competitive global market. BTSE Group is a leading global fintech and blockchain company that is committed to building innovative technology and infrastructure. BTSE empowers businesses and corporate clients with the advanced tools they need to excel in a rapidly evolving and competitive market. BTSE has pioneered numerous trading technologies that have been widely adopted across the industry, setting new benchmarks for innovation, performance, and security in fintech. BTSE’s diverse business lines serve both retail (B2C) customers and institutional (B2B) clients, enabling them to launch, operate, and scale fintech businesses. BTSE is seeking ambitious, motivated professionals to join our B2C and B2B teams. About The Opportunity We are looking for an Enterprise Security Engineer to manage and secure our cloud infrastructure, IDC infrastructure, and all server-related environments. This role focuses on protecting cloud environments, cloud security posture management (CSPM), AWS IAM Identity Centre, and server vulnerability management across both cloud and on-premise environments. Responsibilities Own and manage AWS-native security services including GuardDuty, Security Hub, Inspector, Macie, Config, and CloudTrailOwn and manage AWS IAM Identity Center (formerly AWS SSO) for centralized access management across all AWS accountsDesign and enforce permission sets, session policies, and access boundaries following least-privilege principlesManage AWS Organizations SCPs (Service Control Policies) to enforce account-level guardrailsDesign and enforce encryption policies for data at rest (KMS, EBS, S3, RDS) and data in transit (TLS, ACM)Conduct periodic access reviews and recertification for AWS resources, eliminating excessive or unused permissionsOwn the end-to-end server vulnerability management lifecycle: scanning, identification, prioritization, remediation coordination, verification, and reportingDefine and enforce server hardening standards and security baselines (CIS Benchmarks) for all server operating systems (Linux, Windows)Secure container environments (EKS/ECS) including image vulnerability scanning, runtime security, and network policiesConduct regular access reviews and certification campaignsDevelop and maintain automation scripts, tools, and frameworks to streamline security processesParticipate in incident response activities, investigate security incidents, and conduct root cause analysis Requirements 5+ years of experience in Cloud securityExperience with Infrastructure & Cloud (architecture, development, support, and troubleshooting)Proven experience with CSPM tools and cloud security posture assessment (AWS Security Hub, Prisma Cloud, Wiz, or equivalent)Understanding of compliance frameworks (ISO 27001, SOC 2, PCI-DSS) in cloud and server contextsSolid understanding of server operating systems (Linux, Windows) including hardening, patching, and CIS Benchmark implementationUnderstanding of IAM frameworks and identity governanceStrong analytical and problem-solving skillsExcellent communication and collaboration skills for cross-functional teamworkAble to effectively listen, speak, read and write in English, with Chinese as a plus Nice To Haves Experience with multi-cloud environments (Azure, GCP) in addition to AWSFamiliarity with Kubernetes security (network policies, RBAC, admission controllers, Falco, OPA/Gatekeeper)Proficiency in scripting and automation languages (Bash, PowerShell, Python)Experience with secrets management (HashiCorp Vault, AWS Secrets Manager)Knowledge of Zero Trust architecture principlesExperience with conditional access policies and risk-based authenticationExperience with web3 and blockchain technologiesRelevant certifications: CISSP, CEH, AWS Certified Security Specialty, or equivalent We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.