
Information Security Engineer – CISO Track
Posted Jul 22

Posted Jul 22
This is a fully remote position, open to applicants in United Kingdom.
• Take charge of security within our AWS ecosystem: focusing on IAM and least privilege, network segmentation, encryption, logging, and detection (GuardDuty, Security Hub, CloudTrail), while addressing any issues discovered.
• Integrate security into the development pipeline: implement secrets management, conduct dependency and container scanning, review code for potential risks, and collaborate with engineers on threat modeling.
• Automate processes: establish detection rules, alerting, compliance evidence, and IaC guardrails. If a control can be implemented through code rather than meetings, prioritize coding it.
• Manage vulnerability assessments and incident response initiatives.
• Create documentation for operational procedures and conduct drills to ensure readiness.
• Establish guidelines for our AI and LLM usage: determine which data is shared with vendors, approve models, and define how prompts and outputs are managed and logged.
• Evaluate risks such as prompt injection and data leakage, and design controls that enable continued workflow.
• Oversee SOC 2 compliance: design controls, automate evidence gathering, and maintain relationships with auditors.
• Address regulatory requirements for our financial institution clients: ensure compliance with GDPR and CCPA for privacy, DORA and EBA outsourcing standards in the EU, as well as GLBA and SEC/FINRA expectations in the US.
• Lead security reviews for customers: handle due diligence questionnaires, RFPs, contract security negotiations, and discussions with bank security teams.
• Conduct vendor evaluations and manage third-party risk assessments.
• Enhance human security by developing awareness training, phishing resilience programs, and promoting device and identity hygiene that caters to both sales and engineering teams.
• Over time, establish the security strategy, communicate risks in business language to leadership, select tools, develop a budget, and expand the team.
• Minimum of 5 years experience in security engineering or security-focused infrastructure roles, with significant expertise in AWS security (IAM, SCPs, logging, detection, encryption).
• While certifications are valuable, hands-on experience is preferred.
• Proficiency in Python and Terraform, or similar technologies.
• You prioritize automating evidence collection over maintaining spreadsheets.
• Experience with SOC 2, ideally having led a Type II audit.
• Familiarity with privacy regulations is essential.
• Experience dealing with scrutiny from financial services customers, or a strong desire to specialize in this area.
• A foundational understanding of LLM security risks, or a keen interest in developing this expertise.
• Ability to assess which risks are most significant.
• Strong written communication skills.
• Aspirations to advance into an executive position, complemented by the interpersonal skills necessary for success.
• Preferable experience in Fintech or another regulated B2B sector dealing with large financial institutions.
• Knowledge of DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
• Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
• History of being the first security hire in an organization.
• A unique opportunity to shape and own your role.
• A dedicated pathway to CISO.
• Fully remote work with flexible hours.
• Direct access to leadership and customer security teams at prominent financial institutions.
• Competitive compensation, equity, and a budget for learning and development.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.