Fully remote 路 CET timezone or close - Full-time 路 Reports to the CTO.
Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one.
The work is hands-on: AWS, infrastructure as code, detection and response, auditors.
As the company grows, the role grows into CISO.
We sell to financial institutions, and their security teams question everything we do, so you'll be the person with good answers.
Tasks What you'll do Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
Detection rules, alerting, compliance evidence, IaC guardrails.
If a control can be code instead of a meeting, make it code.
Run vulnerability management and incident response.
Write the runbooks, run the drills.
Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged.
Assess risks like prompt injection and data leakage, design controls that let people keep working.
Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
Run vendor reviews and third-party risk.
Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
Over time: set the security strategy.