Summary
A hands-on security engineering role for an experienced professional who will build and operate security capabilities across cloud infrastructure, applications, CI/CD pipelines, and compliance processes. The position requires strong infrastructure knowledge, offensive security skills, automation abilities, and close collaboration with engineering teams.
Highlights
High-impact security role with ownership across cloud security, vulnerability management, compliance evidence, incident response, and modern security automation. Offers direct influence on security strategy and broad technical scope.
Description
Security Engineer (DevSecOps)
Full-time · Hybrid / Remote-friendly
About us
We are a group of regulated fintech and cryptocurrency companies.
Security isn’t a feature for us — it’s the foundation the business stands on.
About the role
You will be one of two founding security hires, working alongside a GRC Manager under the CISO: they own the compliance framework and audit calendar; you own the technical engineering and evidence that makes compliance real.
This is a hands-on, high-ownership individual-contributor role in an environment governed by PCI DSS Level 1, ISO 27001, SOC 2, and CCSS.
You’ll have direct access to standalone security tooling — scanners, WAF/CDN security rules, cloud security posture tools — and work through a specify → implement → verify loop with DevOps and R&D for anything embedded in infrastructure or application code they own.
You define what must change and verify it changed; they implement in their systems.
It’s a deliberate model that keeps change control clean in a regulated environment, and it means your requests need to be sharp — which is why we need someone with a real infrastructure background, not just a scanner operator.
What you’ll do
In priority order:
• Be the security–engineering liaison — translate security requirements and audit-driven requests from the CISO into scoped engineering tasks; implement within your own security tooling scope; route infrastructure and code changes to DevOps and R&D as tracked, well-specified requests; verify outcomes and report status proactively.
• Produce technical compliance evidence — cloud config exports, access reviews, network posture, scan results, change records, CI/CD execution logs — audit-ready, on the GRC Manager’s calendar and to their specifications.
• Run offensive security and validation — internal vulnerability scanning; reproduce and validate external pen test findings; verify remediation; challenge false positives with evidence; coordinate ASV scans and pen test cycles technically.
• Own CI/CD security gate outcomes — triage findings from pipeline gates (SAST, dependency/container scanning, SBOM); define checks and pass/fail thresholds; manage and monitor implementation of gate changes by their owners; package outputs as compliance evidence.
• Assess cloud and edge posture — research the cloud and CDN/WAF stack, find and test drift and misconfigurations, prioritize by risk, verify remediation; direct ownership of WAF security rules and posture tooling.
• Run vulnerability management end to end — scanning, triage, prioritization, fix coordination, closure verification.
• Co-build security monitoring — co-implement the detection layer of our agentic, Kubernetes-native monitoring platform with DevOps; contribute and execute detection logic; investigate what it surfaces.
• Support incident response — technical investigation, log analysis, containment under CISO direction.
What you’ll bring
• Solid DevOps / infrastructure foundation: AWS, Kubernetes, CI/CD, infrastructure-as-code, Linux — the specify→verify model only works when the specifier deeply understands the systems.
• Hands-on experience with offensive security tooling — penetration testing tools, red team frameworks, vulnerability scanners (e.g.
Nessus, Burp Suite, Metasploit, Nmap, OpenVAS) — able to run scans, validate findings, and reproduce reported vulnerabilities.
• Shell scripting and automation (Bash).
• The communication muscle this role runs on: you can take “the assessor needs proof these controls exist” and come back with the right export, correctly scoped, first time.
• Sound judgment with elevated access and credentials; least-privilege discipline.
Nice to have
• 2+ years in a security-titled seat (security engineering, vulnerability management, AppSec).
• Offensive certifications: OSCP, eJPT, PNPT or equivalent.
• Exposure to audit evidence production (PCI DSS, ISO 27001, SOC 2) — knowing what evidence looks like is a genuine differentiator.
• Python for security automation and tooling.
• Tooling: Trivy, SonarQube, Dependency-Track, GuardDuty, Defender, Cloudflare security.
• SIEM / detection engineering (Microsoft Sentinel).
• Interest in LLM/AI systems and their security.
• Fintech, payments, or crypto background.
Why join
• Founding hire: direct line to the CISO and real influence over the security roadmap — you’re not ticket #4 in a queue.
• Full breadth: offensive work, evidence, cloud posture, detection, incident response — not a narrow slice.
• A modern AI-assisted security stack whose detection layer you’ll co-build from close to the ground up.
• A GRC counterpart who owns the paperwork side of compliance, so your audit involvement stays technical.