
Information Security Engineer – CISO Track
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in United Kingdom.
• Take responsibility for security within the AWS environment, encompassing IAM, least privilege, network segmentation, encryption, logging, and detection.
• Integrate security measures into the development pipeline through secrets management, dependency and container scanning, risky-change code reviews, and threat modeling.
• Automate detection rules, alerting processes, compliance evidence, and infrastructure-as-code guardrails.
• Manage vulnerability assessments and incident response; create runbooks and conduct drills.
• Establish security guidelines for AI and LLM usage, including vendor data management, approved models, and prompt/output logging.
• Evaluate risks associated with prompt-injection and data leakage, and devise effective controls.
• Oversee SOC 2 control development, automated evidence gathering, and relationships with auditors.
• Address regulatory obligations for financial institution clients, including GDPR, CCPA, DORA, EBA outsourcing guidelines, GLBA, and SEC/FINRA requirements.
• Lead customer security assessments, due diligence questionnaires, RFPs, contract security terms, and discussions with bank security teams.
• Conduct vendor evaluations and manage third-party risk.
• Develop security awareness training, enhance phishing resilience, and promote device and identity hygiene.
• Define security strategy, communicate risks to leadership, select tools, create a budget, and expand the team as the role evolves.
• Progress into a CISO position and report directly to the CTO.
• A minimum of 5 years in security engineering or security-intensive infrastructure roles.
• Proficient in AWS security, including IAM, SCPs, logging, detection, and encryption.
• Knowledge of Python and Terraform, or equivalent technologies.
• Experience in automating evidence collection processes.
• Familiarity with SOC 2, preferably having managed a Type II audit.
• Understanding of privacy laws and regulations.
• Exposure to the scrutiny of financial services customers, or a desire to specialize in this area.
• A practical perspective on LLM security risks, or a strong foundational understanding and curiosity to develop one.
• Ability to prioritize significant risks effectively.
• Proficient in explaining controls to auditors and engineers.
• Excellent writing skills for asynchronous communication, policy documentation, and risk memos.
• Ambition to transition into an executive role, complemented by interpersonal skills to support this growth.
• Preferred: experience in fintech or another regulated B2B sector with large financial institution clients.
• Preferred: familiarity with DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500 regulations.
• Preferred: experience securing SSO/SCIM, SFTP feeds, and APIs.
• Preferred: experience as the initial security hire.
• Located in the CET timezone or nearby.
• Fully remote work with flexible hours.
• Competitive salary.
• Equity options.
• Learning budget available.
• Direct access to leadership and customer security teams within major financial institutions.
• Opportunity to work with a blank slate and take on real ownership.
• A dedicated path toward becoming a CISO.
Cummins Inc.
GitLab
Tevora
Delinea
Get handpicked remote jobs straight to your inbox weekly.