Responsibilities
- Act as the primary Security Engineering partner for the Treasury business unit, managing security posture from assessment to remediation and continuous enhancement.
- Conduct threat modeling and security architecture evaluations for Treasury products and services.
- Oversee the secure software development lifecycle, establishing security guardrails, CI/CD integrations, and developer guidance to enable secure-by-default practices.
- Lead cloud security architecture on Azure and AWS, covering IAM, network segmentation, encryption, zero trust controls, Kubernetes policies, and DDoS/WAF strategies, aligning with infrastructure standards.
- Collaborate with GRC to ensure Treasury meets compliance requirements for SOC 2, ISO 27001, and financial regulations as it integrates into governance programs.
- Manage vulnerability discovery via security assessments, penetration testing, and bug bounty programs, automating triage, prioritization, remediation, and validation processes.
- Develop and expand a Security Champions program within Treasury Engineering to embed security advocates and extend team influence.
- Influence senior-level engineering architecture decisions through design reviews and assessments, with authority to address security concerns.
- Mentor and develop Security Engineers through threat model walkthroughs, design discussions, and structured knowledge sharing to elevate technical standards.
- Monitor emerging threats in FinTech, crypto, and enterprise treasury systems, translating new attack techniques into defensive improvements across platforms.
Requirements
- 10+ years of Security Engineering experience with hands-on work in Product Security and Infrastructure Security.
- Expert-level skills in threat modeling using STRIDE or similar, security architecture review, OWASP Top 10, API security, authentication/authorization design, and secure SDLC.
- Deep expertise in securing cloud environments on Azure, AWS, or GCP, including IAM architecture, network security, secrets management, container/Kubernetes security, and infrastructure as code.
- Hands-on experience building and operating DevSecOps tools like static analysis, dynamic analysis, software composition analysis, secrets scanning, container scanning, and CI/CD security integration.
- Strong software engineering skills in Python, Go, or equivalent, with ability to build security tooling, automate controls, and integrate security into engineering workflows.
- Experience with cryptographic principles and key management, including HSMs, MPC, PKI, and key rotation, understanding financial infrastructure implications of key management failures.
- A hands-on approach, effective when engaged in writing threat models, reviewing architecture documents, reading code, and building tooling.
Nice to Have
- Background in FinTech, crypto, blockchain, or high-stakes financial environments, especially where security failures directly impact customers or financial systems.