4 дня назад
Senior Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Cloud and Application Security): Designing, operating, and automating security controls across cloud, application, API, and software-development environments with an accent on AWS security, vulnerability remediation, identity and access management. Focus on reviewing complex architectures, integrating controls into CI/CD workflows, and translating technical findings into practical remediation for Engineering teams.
Location: Luxembourg; hybrid work
Company
provides regulated, wallet-based payment infrastructure for organisations with complex, multi-party fund flows, enabling platforms and fintechs to collect, split, hold, and distribute funds.
What you will do
- Partner with Engineering and Platform teams on security guidance for applications, APIs, infrastructure, and major technical changes.
- Perform risk-based security reviews and integrate security throughout the software development life cycle.
- Review cloud, identity, network, application, and cloud-native security architectures and recommend proportionate controls.
- Assess vulnerabilities and CVEs, determine impact and exploitability, support remediation decisions, and validate fixes.
- Own, operate, automate, and continuously improve the Security Engineering toolset and technical controls.
- Work with the SOC and Engineering teams on remediation, audits, regulatory requirements, and security assessments.
Requirements
- Strong hands-on experience in Security Engineering, Cloud Security, Application Security, Product Security, or a similar role.
- Practical knowledge of cloud security and cloud-native architectures, ideally in AWS environments.
- Understanding of application and API security, including authentication, authorisation, access control, and common vulnerabilities.
- Experience with CI/CD environments, vulnerability management, cloud security, and infrastructure security technologies.
- Knowledge of identity and access management, network security, encryption, secrets management, and cloud security principles.
- Ability to review technical architectures, identify risks, solve problems, and communicate practical solutions to engineers and architects.
Nice to have
- Experience in fintech, payments, financial services, or another regulated environment.
- Experience securing large-scale API-based platforms.
- Experience with infrastructure-as-code, containers, Kubernetes, threat modelling, and secure design reviews.
- Knowledge of PCI DSS, SOC 2, DORA, or similar frameworks.
- Relevant cloud or security certifications.
Culture & Benefits
- Full-time position within the Technology department.
- Hands-on collaboration with Engineering, Platform, SOC, and Security leadership.
- Opportunity to support secure delivery at scale across a regulated payment platform.
Hiring process
- HR call.
- Interview with a senior member.
- Interview with the Head of Information Security.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →