Назад
Company hidden
2 часа назад

Security Engineering Lead (Fintech)

Формат работы
remote (только Europe)/hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK/Germany/Estonia
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security Engineering Lead (Cybersecurity/Fintech): Setting the multi-quarter strategy for application and cloud security across an Investment API platform with an accent on embedding security into the SDLC and hardening cloud infrastructure. Focus on automating security tooling (SAST/DAST/SCA), implementing DORA regulatory frameworks, and scaling security engineering practices in a highly regulated environment.

Location: Hybrid in Berlin, London, or Tallinn, or remotely across Europe

Company

hirify.global provides an Investment API that enables businesses to offer capital market investment and retirement planning services.

What you will do

  • Define and execute the multi-quarter strategy for application and cloud security across the platform.
  • Lead, mentor, and scale the Security Engineering team while fostering a security-first culture.
  • Build secure "paved roads" by integrating security into CI/CD, encryption, and network surfaces.
  • Own end-to-end application security, including threat modeling, secure code review, and vulnerability management.
  • Optimize cloud security posture in GCP using IAM, VPC Service Controls, and Kubernetes hardening.
  • Translate DORA and other regulatory requirements (MaRisk, BAIT) into actionable technical engineering programs.

Requirements

  • 6–10 years in security engineering, with 4+ years focused on product or cloud security.
  • Deep technical expertise in GCP, Terraform, and Kubernetes hardening.
  • Strong knowledge of OWASP Top 10, ASVS, and supply-chain security (SLSA).
  • Proven experience leading and growing technical teams.
  • Experience working in highly regulated environments with familiarity with DORA, ISO 27001, or similar.
  • Must be based in or work remotely from Europe.

Nice to have

  • Proficiency in Go, Python, or other modern backend languages.
  • Hands-on experience with AI/LLM security and agentic identities.
  • Experience managing Bug Bounty or VDP programs.
  • Background in offensive security or incident response (EDR, SIEM).
  • German language skills for client interactions.

Culture & Benefits

  • Competitive salary and participation in an employee equity program.
  • 30 days of annual leave and a one-month fully paid sabbatical every 4 years.
  • Flexibility to work remotely abroad for up to 183 days per year.
  • Personal development budget and sports benefits.
  • Inclusive environment with active Employee Resource Groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →