About us: We are a group of regulated fintech and cryptocurrency companies. Security isn’t a feature for us — it’s the foundation the business stands on.
About the role: You will be one of two founding security hires, working alongside a GRC Manager under the CISO: they own the compliance framework and audit calendar; you own the technical engineering and evidence that makes compliance real. This is a hands-on, high-ownership individual-contributor role in an environment governed by PCI DSS Level 1, ISO 27001, SOC 2, and CCSS. You’ll have direct access to standalone security tooling — scanners, WAF/CDN security rules, cloud security posture tools — and work through a specify → implement → verify loop with DevOps and R&D for anything embedded in infrastructure or application code they own. You define what must change and verify it changed; they implement in their systems. It’s a deliberate model that keeps change control clean in a regulated environment, and it means your requests need to be sharp — which is why we need someone with a real infrastructure background, not just a scanner operator.
What you’ll do:
In priority order: • Be the security—engineering liaison — translate security requirements and audit-driven requests from the CISO into scoped engineering tasks; implement within your own security tooling scope; route infrastructure and code changes to DevOps and R&D as tracked, well-specified requests; verify outcomes and report status proactively. • Produce technical compliance evidence — cloud config exports, access reviews, network posture, scan results, change records, CI/CD execution logs — audit-ready, on the GRC Manager’s calendar and to their specifications. • Run offensive security and validation — internal vulnerability scanning; reproduce and validate external pen test findings; verify remediation; challenge false positives with evidence; coordinate ASV scans and pen test cycles technically. • Own CI/CD security gate outcomes — triage findings from pipeline gates (SAST, dependency/container scanning, SBOM); define checks and pass/fail thresholds; manage and monitor implementation of gate changes by their owners; package outputs as compliance evidence. • Assess cloud and edge posture — research the cloud and CDN/WAF stack, find and test drift and misconfigurations, prioritize by risk, verify remediation; direct ownership of WAF security rules and posture tooling. • Run vulnerability management end to end — scanning, triage, prioritization, fix coordination, closure verification. • Co-build security monitoring — co-implement the detection layer of our agentic, Kubernetes-native monitoring platform with DevOps; contribute and execute detection logic; investigate what it surfaces. • Support incident response — technical investigation, log analysis, containment under CISO direction. What you’ll bring • Solid DevOps / infrastructure foundation: AWS, Kubernetes, CI/CD, infrastructure-as-code, Linux — the specify→verify model only works when the specifier deeply understands the systems. • Hands-on experience with offensive security tooling — penetration testing tools, red team frameworks, vulnerability scanners (e.g. Nessus, Burp Suite, Metasploit, Nmap, OpenVAS) — able to run scans, validate findings, and reproduce reported vulnerabilities. • Shell scripting and automation (Bash). • The communication muscle this role runs on: you can take “the assessor needs proof these controls exist” and come back with the right export, correctly scoped, first time. • Sound judgment with elevated access and credentials; least-privilege discipline.
Nice to have: • 2+ years in a security-titled seat (security engineering, vulnerability management, AppSec). • Offensive certifications: OSCP, eJPT, PNPT or equivalent. • Exposure to audit evidence production (PCI DSS, ISO 27001, SOC 2) — knowing what evidence looks like is a genuine differentiator. • Python for security automation and tooling. • Tooling: Trivy, SonarQube, Dependency-



