Application Security Engineer / Architect (DevSecOps) (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer / Architect (DevSecOps) (Fintech): Building and managing security controls within CI/CD pipelines and cloud infrastructure for a capital markets platform with an accent on DevSecOps automation and vulnerability management. Focus on scaling security operations through AI-based tools, enforcing IaC standards, and remediation of application source code vulnerabilities.
Location: New York, NY. Must be in the office 4 days per week.
Salary: $175,000 - $210,000
Company
A cloud-native end-to-end capital markets platform providing sophisticated investors access to every asset in every market through a unified, high-scale infrastructure.
What you will do
- Own security controls within CI/CD pipelines including SAST, DAST, SCA, and secrets detection.
- Lead cloud security efforts by enforcing best practices for IAM, network controls, and workload protection.
- Manage the end-to-end vulnerability lifecycle: triage, risk prioritization, tracking, and reporting.
- Build automation and AI-based tools to scale DevSecOps operations.
- Define and enforce secure infrastructure-as-code (IaC) standards via policy-as-code in partnership with Infra Engineering.
- Perform threat modeling and security design reviews for new features and services.
Requirements
- 7+ years of experience in DevSecOps, application security, or cloud security engineering.
- Proficiency with at least one major cloud provider (AWS, Azure, or GCP) and CI/CD platforms like GitHub Actions, GitLab CI, or Jenkins.
- Hands-on experience with SAST/SCA tools (e.g., Semgrep, Snyk, Checkmarx) and Kubernetes security (RBAC, network policies).
- Strong scripting skills in Python or Bash for automation.
- Experience with IaC tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov).
- Must be based in New York, NY and available to work in-office 4 days per week.
Culture & Benefits
- Competitive compensation package including company equity and 401k matching.
- Full medical, dental, and vision insurance.
- Gender-neutral parental leave.
- In-office perks: lunch stipends and fully stocked kitchens in a prime location.
- A collaborative, high-performance culture that values diversity in ideas and experiences.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →