Lead Security Engineer
You will establish and mature security practices across application security, security operations, and governance, risk, and compliance. You will define application, cloud, AI, detection, incident-response, and vendor-security approaches; conduct assessments; handle complex reviews; and mentor engineers without formal people-management responsibility.
Responsibilities
- Drive the application security roadmap, including threat modelling, secure code review, API security testing, and security pipeline architecture
- Define security guardrails for AI and agentic workflows, including prompts, destructive actions, and data exposure
- Set technical direction for detection engineering, alert pipelines, and automated response across the security stack
- Own incident response readiness by designing playbooks, leading tabletop exercises, and acting as technical lead during major incidents
- Set standards for cloud security assessments across AWS and Kubernetes
- Own and improve the vendor security assessment and third-party due diligence framework
- Mentor mid-level and senior engineers by reviewing detection logic, assessments, and playbooks
Requirements
- 7+ years of information security experience, including building or substantially maturing a security function or program
- 2+ years of experience at a regulated fintech, bank, or payment company
- Hands-on cloud infrastructure security expertise in AWS and Kubernetes
- Experience driving application security programs, including threat modelling, secure code review, CI/CD hardening, and API security testing
- Ability to define security guardrails for AI and agentic tooling, including LLM integrations, MCP servers, and automated workflows
- Detection engineering experience, including designing detection strategy and mentoring others in rule writing
- Experience with endpoint security tooling, identity and access management architecture, Google Workspace, Okta, Cloudflare Access, SSO, and SCIM
- Experience designing or significantly evolving vendor security assessment or third-party due diligence programs
- Written and verbal communication skills for representing security decisions to leadership and cross-functional stakeholders
- Business-fluent English
Benefits
- Stock options
- Discretionary performance bonus
