Information Security Engineer – CISO Track

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Tangible

Tangible

11 - 50 employees

Founded 2023

💸 Finance

🏪 Marketplace

💳 Fintech

Finance • Marketplace • Fintech

Tangible is a London-based financial technology company and secondary markets platform that provides liquidity solutions and advisory for institutional investors. It operates auction and liquidity hub products for closed-end and semi-liquid funds, serving limited partners (LPs), general partners (GPs), wealth managers and secondary liquidity providers. Tangible offers a tech suite and strategic/financial advisory for secondary transactions and works with regulated broker partners to facilitate securities offers.

📋 Description

• Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find. • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers. • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code. • Run vulnerability management and incident response. • Write the runbooks, run the drills. • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. • Assess risks like prompt injection and data leakage, design controls that let people keep working. • Own SOC 2: control design, automated evidence collection, the auditor relationship. • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US. • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams. • Run vendor reviews and third-party risk. • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers. • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

🎯 Requirements

• 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). • Certifications are fine, but shipped work is better. • Python and Terraform, or close equivalents. • You automate evidence collection instead of maintaining spreadsheets. • SOC 2 experience, ideally owning a Type II audit. • Working knowledge of privacy legislation. • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty. • A working view on LLM security risks, or strong fundamentals and the curiosity to build one. • Judgment about which risks matter. • Clear writing. • The ambition to grow into an executive role and the people skills to survive it. • Nice to have Fintech or another regulated B2B environment with large financial-institution customers. • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500. • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs. • You've been the first security hire somewhere before.

🏖️ Benefits

• A blank slate with real ownership • A committed path to CISO. • Fully remote, flexible hours. • Direct access to leadership and to customer security teams at major financial institutions. • Competitive pay, equity, learning budget.

Apply Now

Similar Jobs

🕒 June 12

Work Life Group

11 - 50

🎯 Recruiter

👥 HR Tech

Senior Atlassian Consultant supporting NATO's Cyber Operations Management System. Responsible for building environments and documenting requirements.

🕒 June 11

Cloud Bridge

51 - 200

🎯 Recruiter

🤝 B2B

Network Security Engineer handling assessment, design, and improvement of network security controls. Collaborating on traffic analysis and bespoke security solutions for enterprise risk exposure.

🕒 April 8

TryHackMe

51 - 200

🔒 Cybersecurity

📚 Education

☁️ SaaS

Senior AI Security Content Engineer developing cutting-edge cybersecurity training content at TryHackMe. Transforming AI security concepts into engaging labs for learners worldwide.