远程工作雷达

信息安全工程师(CISO路径)

Information Security Engineer (CISO track)

开发工程限定地区(需当地身份)日间重叠仅 1 小时,需熬夜配合
公司Tangible
薪资未公开
工作地点United Kingdom
地域资格限定地区(需当地身份)
时区要求日间重叠仅 1 小时,需熬夜配合
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United Kingdom 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠仅 1 小时,需熬夜配合。

全职远程 · 时区为CET或相近 - 全职 · 向CTO汇报
职位简介
你将是我们的首位专职信息安全人员。目前,安全工作由工程领导和外部供应商兼职负责;我们希望这成为你的全职工作。工作内容是实际操作:AWS、基础设施即代码、检测与响应、审计。随着公司发展,该职位将成长为首席信息安全官(CISO)。
我们向金融机构销售产品,他们的安全团队会质疑我们所做的每一件事,因此你需要是能给出合理答案的人。
职责
你将负责的工作

  • 负责我们AWS环境中的安全:IAM和最小权限原则、网络分段、加密、日志和检测(GuardDuty、Security Hub、CloudTrail),修复发现的问题。
  • 将安全融入开发流程:密钥管理、依赖项和容器扫描、对高风险变更进行代码审查、与工程师一起进行威胁建模。
  • 自动化:检测规则、警报、合规性证据、IaC防护措施。如果一个控制措施可以用代码实现而不是开会讨论,就用代码实现。
  • 运行漏洞管理和事件响应。编写操作手册,进行演练。
  • 制定AI和LLM使用的规则:哪些数据发送给哪些供应商,哪些模型被批准,如何处理和记录提示词和输出。评估如提示注入和数据泄露等风险,设计让员工继续工作的控制措施。
  • 负责SOC 2:控制设计、自动化证据收集、与审计师的关系。
  • 处理面向金融机构客户的合规事务:隐私方面的GDPR和CCPA,欧盟的DORA和EBA外包指南,美国的GLBA和SEC/FINRA要求。
  • 领导客户安全审查:尽职调查问卷、RFP、合同安全条款、与银行安全团队的电话会议。
  • 进行供应商审查和第三方风险评估。
  • 通过建立意识培训、防钓鱼能力以及适用于销售和商务人员而非仅工程师的设备和身份卫生来保障人员安全。
  • 长期来看:制定安全战略,以业务术语向管理层报告风险,选择工具,制定预算,招聘。

要求
我们寻找的人选

  • 5年以上安全工程或安全密集型基础设施工作经验,具备AWS安全方面的深度(IAM、SCP、日志、检测、加密)。认证可以接受,但实际交付的项目更重要。
  • 精通Python和Terraform,或类似工具。你通过自动化收集证据,而不是维护电子表格。
  • 有SOC 2经验,最好是多次经验。
查看英文原文

Fully remote · CET timezone or close - Full-time · Reports to the CTO
About the role
You'll be our first dedicated information security hire. Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one. The work is hands-on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO.
We sell to financial institutions, and their security teams question everything we do, so you'll be the person with good answers.
Tasks
What you'll do

  • Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
  • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
  • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code.
  • Run vulnerability management and incident response. Write the runbooks, run the drills.
  • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working.
  • Own SOC 2: control design, automated evidence collection, the auditor relationship.
  • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
  • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams.
  • Run vendor reviews and third-party risk.
  • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
  • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

Requirements
What we're looking for

  • 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation.
  • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn't theater.
  • Clear writing. Remote means async, and async means your policies and risk memos do the talking.
  • The ambition to grow into an executive role and the people skills to survive it.

Nice to have

  • Fintech or another regulated B2B environment with large financial-institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You've been the first security hire somewhere before.

Benefits
What we offer

  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.

How we hire

  • Intro call (30 min).
  • Technical deep dive (60–90 min): AWS security scenarios, plus a walk-through of a program you built.
  • Practical exercise: review a sanitized architecture or a due diligence questionnaire and tell us what you'd fix first.
  • Leadership conversation: the CISO path, and working with the non-technical half of the company.
  • References and offer.

We're an equal opportunity employer. If you don't tick every box, apply anyway.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位