At a Glance
- Tasks: Drive cloud security enhancements and automate security processes in a collaborative environment.
- Company: Thredd is a leading payments partner, modernising payment solutions for fintechs globally.
- Benefits: Enjoy remote work flexibility and a supportive, innovative culture.
- Why this job: Join a dynamic team to enhance cybersecurity and make a real impact in the financial sector.
- Qualifications: Experience in cloud security, scripting, and compliance frameworks is essential.
- Other info: Candidates will undergo credit and background checks; only direct applications accepted.
The predicted salary is between 43200 - 72000 £ per year.
Are you a Staff Security Engineer who can drive the continuous enhancement and safeguarding of our cloud security landscape?
Thredd is looking for a Staff Security Engineer to join our team! As our Staff Security Engineer, you will collaborate with Thredd Platform Delivery and InfoSec teams to design secure environments for core production services. You will integrate DevSecOps principles, automate security processes like secret and container scanning, and enhance vulnerability management and threat modeling. Serving as both a subject matter expert and hands-on engineer, you will improve Thredd's security posture, maintain security pipelines, and increase cybersecurity awareness by sharing insights and implementing effective controls.
Responsibilities:
- Leads technical projects by incorporating client requirements, aligning designs with client needs, and ensuring feedback integration for a client-first approach.
- Develops and maintains security documentation, including architecture diagrams, enhances engineering workflows with data solutions, and establishes robust reporting mechanisms to track performance and outcomes.
- Stay updated on the latest engineering trends and best practices, leveraging insights to influence projects and enhance organizational capabilities through engagement with industry professionals.
- Recommends and implements cloud security best practices, such as CIS Benchmarks, manages security monitoring and incident handling, mentors team members in adopting new technologies and methodologies, and designs scalable engineering solutions that meet both technical and client requirements.
- Prioritises security tool outputs, develops tactical plans for engineering projects, manages resource allocation, and ensures timely delivery by aligning project timelines with broader engineering objectives.
- Demonstrates advanced technical expertise in multiple domains, leads technical initiatives, contributes to product strategy discussions, and drives the adoption of best practices across engineering teams.
- Implement secure cloud architectures for AWS environments, drives cybersecurity practices like vulnerability management and threat modeling, ensures compliance with regulatory requirements (e.g., PCI-DSS, SOX), and fosters a culture of quality within the engineering team.
- Automate security tasks using modern tools and scripting to improve security posture, streamlines cloud security operations with Cloud SecOps practices, and protects revenue through robust cloud security measures.
- Automate security validation within CI pipelines, including secret scanning and compliance checks, supports multi-cloud design (IaaS, PaaS, SaaS) and hybrid approaches for secure access across co-located and cloud workloads, and contributes to the technical vision by evaluating engineering strategies that align with organizational goals and market demand.
What you bring:
- Prior experience as cloud security engineer or equivalent within the financial services industry.
- In-depth knowledge of cloud security architecture, best practices, and frameworks (e.g., NIST, CSA, CIS).
- Experience with security automation, orchestration, and DevSecOps practices.
- Must have in-depth exposure to EKS.
- Proficiency in scripting and programming languages (e.g., Python, PowerShell, Bash) for security automation.
- Strong understanding of encryption technologies, identity and access management (IAM), and network security in cloud environments.
- Familiarity with compliance frameworks applicable to the financial services industry (e.g., PCI-DSS, SOX).
This role is a remote role. Thredd operates in a secure environment and all candidates will be Credit and Background checked to the extent permitted by law. Only direct applicants will be considered for this role; we do not accept applications from recruitment agencies.
Staff Security Engineer employer: Thredd
Contact Detail:
Thredd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Staff Security Engineer
✨Tip Number 1
Familiarise yourself with the latest cloud security frameworks and best practices, especially those relevant to the financial services industry like NIST and CIS. This knowledge will not only help you in interviews but also demonstrate your commitment to staying updated in a rapidly evolving field.
✨Tip Number 2
Engage with online communities and forums focused on cloud security and DevSecOps. Networking with professionals in these spaces can provide insights into current trends and challenges, which you can leverage during discussions with our team.
✨Tip Number 3
Showcase your hands-on experience with security automation tools and scripting languages like Python or Bash. Be prepared to discuss specific projects where you've implemented these skills, as practical examples can set you apart from other candidates.
✨Tip Number 4
Research Thredd's approach to client-centric solutions and be ready to discuss how your background aligns with our mission. Understanding our unique offerings and how you can contribute will demonstrate your genuine interest in joining our team.
We think you need these skills to ace Staff Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cloud security, particularly within the financial services industry. Emphasise your knowledge of cloud security architecture and any specific frameworks you've worked with, such as NIST or CIS.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cloud security and how your skills align with Thredd's mission. Mention specific projects where you've integrated DevSecOps principles or automated security processes, showcasing your hands-on experience.
Showcase Technical Expertise: Detail your proficiency in scripting and programming languages like Python or PowerShell. Provide examples of how you've used these skills to automate security tasks or enhance vulnerability management in previous roles.
Highlight Compliance Knowledge: Since compliance is crucial in the financial services sector, make sure to mention your familiarity with relevant frameworks like PCI-DSS and SOX. Discuss any experience you have in ensuring compliance within cloud environments.
How to prepare for a job interview at Thredd
✨Showcase Your Cloud Security Expertise
Make sure to highlight your in-depth knowledge of cloud security architecture and best practices during the interview. Be prepared to discuss specific frameworks like NIST, CSA, and CIS, and how you've applied them in previous roles.
✨Demonstrate Your Automation Skills
Since the role involves security automation and DevSecOps practices, be ready to share examples of how you've automated security processes in the past. Discuss the tools and scripting languages you've used, such as Python or PowerShell, to enhance security measures.
✨Prepare for Technical Questions
Expect technical questions related to vulnerability management, threat modelling, and incident handling. Brush up on your knowledge of encryption technologies and identity and access management (IAM) to confidently answer these queries.
✨Emphasise Your Client-Centric Approach
Thredd values a client-first approach, so be sure to illustrate how you've incorporated client requirements into your projects. Share experiences where you aligned designs with client needs and integrated feedback effectively.