Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Engineer (Fintech): Deploying and maintaining security infrastructure across identity, endpoint, cloud, and application layers with an accent on IAM, AWS services, CSPM, and compliance tooling. Focus on building detection systems, managing vulnerability lifecycles, automating workflows, and supporting GRC for SOC 2 audits.
Location: Austin, TX
Salary: $150,000 – $175,000
Company
Well-funded fintech at the intersection of institutional finance and blockchain infrastructure, backed by $40M from top investors.
What you will do
- Deploy and maintain core security controls (SSO/MFA, MDM, EDR, CSPM, secrets management, DLP) with technical integrations for enforcement and audit evidence.
- Build detection coverage, investigate incidents, and deliver structured reporting.
- Lead vulnerability scanning, triage, remediation, and non-human identity management.
- Automate controls, alerting, evidence collection, and operational workflows.
- Align technical controls with governance, collect audit evidence, and support SOC 2 compliance.
- Own security onboarding/offboarding and maintain documentation/SOPs.
Requirements
- 3+ years hands-on security engineering in cloud-native environments.
- Strong IAM platform experience.
- Hands-on with AWS security services (IAM, CloudTrail, GuardDuty, Security Hub, Secrets Manager).
- Working knowledge of CSPM tools (Wiz, Prisma Cloud, Prowler or equivalent).
- SAST/SCA integration into CI/CD pipelines.
- Able to produce audit-quality documentation; high autonomy and accountability.
Nice to have
- SOC 2 end-to-end audit experience.
- GRC platform experience (Vanta, Drata, SecureFrame or equivalent).
- Security automation scripting.
- DLP tooling and/or AI data governance exposure.
- NIST CSF, NYDFS Part 500 or similar framework familiarity.
- Experience building security programs from scratch in startups.
- Certifications: AWS Solutions Architect – Associate, AWS Certified Security – Specialty, CISSP.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →