Security Engineer

Lhv — Estonia · Posted ~3 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Join us! Security Engineer (Cloud & Automation) About Lhv We're building a bank the world actually needs – modern, sharp and genuinely human. We started in Estonia, growing through grit and high standards. Now we're taking on the UK and Europe. The next chapter is about doing the most ambitious work we've ever done, and changing how people experience money. We run on three values: No Bullshit, Agile, and Never Satisfied. They're not wall art. They're how we make decisions, push each other and show up every day. WHY THIS ROLE MATTERS LHV is in the middle of something big. And this is your chance to be part of it. We’ve migrated our core systems to the cloud, and we’re rapidly integrating AI across our services and software development. But with our rapid growth, and appetite for pushing boundaries, the risk landscape evolves just as fast. That’s where you come in. We aren't looking for a checklist-driven person. We need an engineer at heart who uses automation to multiply our security team's impact. You'll have the autonomy to act as your own project manager, bridging the gap between development, operations, and security. By automating threat controls, simplifying workflows, and utilizing AI-driven security testing, you will ensure our rapid pace remains incredibly secure. What You'll Do Partner with DevEx to define and continuously improve automated security controls across our development lifecycle (SAST, SCA, DAST), including requirements, rules, coverage, and exception handling, and ensure they actually work in practice.Build and automate technical safeguards in our cloud and identity environments (AWS, Kubernetes, Entra ID), analyzing access paths and configuration baselines.Act as a hands-on security partner for engineering teams right from the design phase: modeling threats for APIs, OAuth2/OIDC, MCP interfaces, AI-agent integrations, and integrations with internal systems.Develop and manage our AWS security platform, scaling our logging pipelines, SIEM, and EDR integrations.Automate the everyday work of the security team, from alert triage to evidence collection, and smart LLM-driven tooling to eliminate manual work.Take complete ownership of your projects from identifying technical risks to coordinating with stakeholders and documenting your solutions.Adapt and grow with the role; we don't believe in rigid boxes, so you'll have the freedom to shape your responsibilities as our technology and challenges evolve. What We're Looking For A strong engineering background in infrastructure, platform development, or systems-level security, ideally with a minimum of 7 years of experience.Solid capability to write clean code or scripts in Python, Go, or Bash, alongside comfort with Infrastructure-as-Code and CI/CD pipelines.Hands-on experience with AWS (IAM, networking, logging) and Kubernetes, or a rock-solid background in on-prem systems and virtualization, combined with a clear understanding of cloud-native fundamentals.A practical grasp of application security, including the OWASP Top 10 and OWASP guidance for LLM applications, authentication flows like OAuth2/OIDC, and the ability to comfortably read code in Java/Spring, Python, or TypeScript.Active use of LLMs and AI tools in daily workflows, with a realistic understanding of what agentic tools can and shouldn't do.High autonomy and the ability to run tasks like a project manager, proactively finding stakeholders, organizing meetings, and driving initiatives.A strong commitment to clear documentation, ensuring complex configurations, processes, and security exceptions are easily understood by others.A broad technical horizon and a desire to move comfortably between attack and defense, development and operations, rather than being boxed into a narrow, rigid role.You thrive in an environment where things move quickly.You already reside in Estonia as we don't offer relocation for this role. Nice-to-haves: Experience with Microsoft Defender, Sentinel, and security scanning tools like Prowler, Trivy, Nessus, or OpenVAS.An offensive security mindset, whether from professional pentesting, bug bounties, or CTF experience, or familiarity with security standards like CIS Benchmarks.Proficiency in the Estonian language is preferred. WHY YOU'LL LOVE IT HERE Own security automation.Work with ambitious colleagues who rapidly push boundaries.Enjoy the freedom to experiment and the ownership to build real impact.We value mutual respect, direct communication, and colleagues who are excited to solve complex problems.Grow professionally and personally through meaningful opportunities. THE FUTURE WE'RE BUILDING Banking has been ugly, slow and impersonal for too long. We're fixing that with design that respects people's intelligence and technology that actually works for them. If that sounds like the kind of problem worth working on, let's talk. JOB LOCATION Tallinn, Tartu