Security Engineer

Tuumplatform — Estonia · Posted ~2 hours ago

Skills

cloud security CI/CD security application security vulnerability assessment security engineering threat identification cloud infrastructure CI/CD application code security tooling

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A security engineer is sought to help protect a modern financial-services platform and the sensitive data behind it. Working closely with security leadership, you will investigate cloud infrastructure, CI/CD pipelines, and application code to identify weaknesses before they can be exploited.

Highlights

Flexible opportunity suitable for candidates ranging from early-career security professionals to experienced engineers. The role offers direct exposure to cloud infrastructure, CI/CD, application code, and proactive vulnerability discovery.

Description

Tuum is a next-generation banking platform. We enable fintech and banks to rapidly offer seamless and tailored financial services to their customers. Our core banking platform is revolutionising the financial services industry. The platform is API-based, consisting of flexible and independent modules covering all retail and business banking capabilities for quick and easy integration. Launched in 2019, Tuum is headquartered in Tallinn and is backed by investors including Citibank, BlackFin Capital Partners, Karma Ventures, Portage Ventures, SpeedInvest, and CommerzVentures. We're looking for a Security Engineer to help keep that platform safe, along with the money and data our customers trust us with. This role works well whether you're early in your security career or have years of experience — what matters most is how you think. Working directly with the Head of Security, you’ll dig into our cloud infrastructure, CI/CD pipeline, and product code to find weaknesses before attackers do and build guardrails that stop whole classes of bugs. This is a hands-on, build-oriented role: more code, automation, and root-cause fixes than tickets. What you'll be doing Threat model new services with product engineers, review code and infrastructure-as-code, and build tooling that catches recurring problems automatically.Harden our cloud environment (mainly AWS, some GCP): IAM, network boundaries, secrets/key management, logging, Kubernetes workloads, and Okta identity engineering.Own the vulnerability cycle end to end: the CI/CD gates (SAST, SCA, ECR image scanning), quarterly internal/external scanning, remediation to policy timeframes, and our penetration testing programme.Build and maintain detections on native cloud services and our own code, not a SIEM appliance - each one a query, a function and a runbook you own - and act as a first responder on incidents.Support the Head of Security on PCI DSS, SOC 2 and ISO 27001: you'd own the testing and much of the recurring calendar.Support the IT Lead on the corporate environment — automation, complex investigations, absence cover — while end-user support and device management stay with them.Help other engineers decide well without asking: reusable patterns, secure defaults, and a standing slot for security questions. Our expectations Security engineering experience, or software/infrastructure engineering with substantial security ownership — deep working knowledge matters more to us than job titles.Strong cloud security experience with a focus on AWS: IAM, networking, key management, logging. You can read and write Terraform without help.Strong skills in at least one general-purpose language, plus confidence in reading others. Our platform is mostly Java and TypeScript, so you'd review both and write code a colleague can maintain.Practical experience securing containerised workloads, plus identity and access fundamentals: OAuth/OIDC, SAML, least privilege.Working knowledge of common vulnerability classes (OWASP Top 10 and beyond) and how to prevent them structurally, plus experience operating a security control you inherited rather than designed.Clear written English and the judgment to prioritise real risk over checklist findings - auditors and our customers' banks read what you write.A collaborative approach: you can say no when it matters, and offer a workable alternative when it doesn't. Bonus points for University degree in cybersecurity or a related field.Detection engineering or incident response experience: log pipelines, EDR, cloud audit trails.Experience in a regulated or high-trust environment: fintech, payments, banking.Payments or card-issuing domain knowledge: PAN flows, scheme or issuer integration.Having stood up or run a vulnerability disclosure programme.Certifications such as AWS Certified Security Specialty, CKS, OSCP, or a hands-on GIAC track like GCSA or GCIH. What we offer Competitive salaryTuum stock optionsHybrid working (3 days a week in the office)4-day work week during the summer months (June, July, August)Private health insurance or generous wellness compensationCareer opportunities to grow both professionally and personally as we scaleBright and warm-hearted team of professionals delivering great things togetherAll-hands-on-deck approach (meaning that everyone delivers value regardless of responsibilities)